Procedure 18 ADMINISTRATIVE
Acceptable Use Policy — how Revique implements this rule today, and how an auditor verifies it.
Policy 18 · PCI DSS Req 12.2 · 0 of 4 policy statements fully met · AWS facts collected read-only 2026-08-13
← All 21 procedures
📘← Back to Policy 18 — Acceptable Use PolicyThe rule this procedure implements
How Revique implements this today
Acceptable use governs how people use Revique systems and is enforced primarily through access control rather than through a technical monitor. The technical backstop is that every action taken against AWS in the dev and production accounts is recorded in CloudTrail (Procedure 11) and attributable to a named identity (Procedure 07/08), so misuse is investigable after the fact. Attempting to bypass a security control — disabling GuardDuty, changing a security group, altering a trail — is an IAM-gated API call that appears in the audit record.
The rule against the current state
Each row takes a statement from Policy 18 and states what is actually configured. Meets = implemented as written. Partial = implemented, but not everywhere or not to the full standard. Gap = not implemented. N/A = not verifiable from infrastructure configuration.
| The rule | Current state | Verdict |
|---|
| Systems and data used only for authorised business purposes | Enforced by least-privilege access and made investigable by CloudTrail. Not otherwise monitored. | Partial |
| Only approved hardware and software used to access CHD/PHI | No device management or endpoint control is evidenced in the estate. | Gap |
| Personnel must not attempt to bypass security controls | Attempts are IAM-restricted and logged in dev and production; not logged in UAT (no trail). | Partial |
| Acceptable use rules acknowledged by all personnel | Administrative record collected at onboarding. | Partial |
🔍 Auditor verification — where to log in and what you will see
Actions are attributableConsole → CloudTrail → Event history → any event shows the invoking IAM identity, source IP and time.
Control-bypass attempts would be visibleCloudTrail → Event history → filter Event name for e.g. AuthorizeSecurityGroupIngress, StopLogging or DisableOrganizationAdminAccount.
The acknowledgement itselfAsk HR / the Security Officer for signed acceptable-use acknowledgements, and sample against the current IAM user list.
Team process
The Security Officer defines and communicates the acceptable use rules; all personnel acknowledge them during onboarding (Procedure 04) and at the annual training refresh (Procedure 06). Suspected misuse is handled as an incident (Procedure 03).
⚠️ Where reality does not meet the policy
- No endpoint or device management is evidenced, so the requirement that only approved hardware and software be used to access CHD/PHI cannot be enforced or verified.
- Because UAT has no CloudTrail, actions taken in an account holding CHD/PHI are not attributable after the fact — the investigative backstop this procedure relies on is missing there.
- No alerting exists on control-bypass events (Procedure 03/11), so misuse is discoverable only by retrospective search.
Evidence location. Acceptable use policy text and signed acknowledgements are HR records held outside AWS.
📘Back to the PolicyPolicy 18 — Acceptable Use Policy (PCI DSS Req 12.2)←