Procedure 18  ADMINISTRATIVE

Acceptable Use Policy — how Revique implements this rule today, and how an auditor verifies it.
Policy 18  ·  PCI DSS Req 12.2  ·  0 of 4 policy statements fully met  ·  AWS facts collected read-only 2026-08-13
← All 21 procedures 📘← Back to Policy 18 — Acceptable Use PolicyThe rule this procedure implements

How Revique implements this today

Acceptable use governs how people use Revique systems and is enforced primarily through access control rather than through a technical monitor. The technical backstop is that every action taken against AWS in the dev and production accounts is recorded in CloudTrail (Procedure 11) and attributable to a named identity (Procedure 07/08), so misuse is investigable after the fact. Attempting to bypass a security control — disabling GuardDuty, changing a security group, altering a trail — is an IAM-gated API call that appears in the audit record.

The rule against the current state

Each row takes a statement from Policy 18 and states what is actually configured. Meets = implemented as written. Partial = implemented, but not everywhere or not to the full standard. Gap = not implemented. N/A = not verifiable from infrastructure configuration.

The ruleCurrent stateVerdict
Systems and data used only for authorised business purposesEnforced by least-privilege access and made investigable by CloudTrail. Not otherwise monitored.Partial
Only approved hardware and software used to access CHD/PHINo device management or endpoint control is evidenced in the estate.Gap
Personnel must not attempt to bypass security controlsAttempts are IAM-restricted and logged in dev and production; not logged in UAT (no trail).Partial
Acceptable use rules acknowledged by all personnelAdministrative record collected at onboarding.Partial

🔍 Auditor verification — where to log in and what you will see

Actions are attributableConsole → CloudTrail → Event history → any event shows the invoking IAM identity, source IP and time.
Control-bypass attempts would be visibleCloudTrail → Event history → filter Event name for e.g. AuthorizeSecurityGroupIngress, StopLogging or DisableOrganizationAdminAccount.
The acknowledgement itselfAsk HR / the Security Officer for signed acceptable-use acknowledgements, and sample against the current IAM user list.

Team process

The Security Officer defines and communicates the acceptable use rules; all personnel acknowledge them during onboarding (Procedure 04) and at the annual training refresh (Procedure 06). Suspected misuse is handled as an incident (Procedure 03).

⚠️ Where reality does not meet the policy

Evidence location. Acceptable use policy text and signed acknowledgements are HR records held outside AWS.
📘Back to the PolicyPolicy 18 — Acceptable Use Policy (PCI DSS Req 12.2)←
Revique security documentation  ·  generated 2026-08-13  ·  all identifiers masked  ·  AWS facts collected read-only on 2026-08-13
Policies define the rule; procedures describe the implementation and how to verify it.