Procedure 19  HYBRID

Physical & Media Security Policy — how Revique implements this rule today, and how an auditor verifies it.
Policy 19  ·  PCI DSS Req 9  ·  1 of 4 policy statements fully met  ·  AWS facts collected read-only 2026-08-13
← All 21 procedures 📘← Back to Policy 19 — Physical & Media Security PolicyThe rule this procedure implements

How Revique implements this today

Revique operates no data centres. All physical security of the facilities housing CHD/PHI is AWS's responsibility under the shared responsibility model, and is evidenced by AWS's SOC 2 Type II report and PCI DSS Attestation of Compliance, both self-service downloads from AWS Artifact. Revique's own responsibility is the electronic media layer: the encryption state of the storage holding CHD/PHI, which is covered in detail by Procedure 09. Production is strong here — the Aurora cluster is encrypted, all 22 production buckets have default encryption, and EBS encryption-by-default is on in both production regions.

The rule against the current state

Each row takes a statement from Policy 19 and states what is actually configured. Meets = implemented as written. Partial = implemented, but not everywhere or not to the full standard. Gap = not implemented. N/A = not verifiable from infrastructure configuration.

The ruleCurrent stateVerdict
Physical security of data centres assured through the cloud provider, evidence obtained annuallyAWS SOC 2 and PCI AoC available on demand from AWS Artifact. No record of Revique having obtained and filed them.Partial
Electronic media containing CHD/PHI encrypted and access-controlledProduction: Aurora encrypted, 22/22 buckets encrypted, EBS default encryption on, zero unencrypted volumes. Exceptions exist outside production and in the legacy tier.Partial
Media securely disposed of when no longer requiredPhysical media destruction is AWS's responsibility; Revique's equivalent is cryptographic erasure (Procedure 17).Meets
Inventory of media containing CHD/PHI maintainedNo inventory document exists; AWS Config, which would generate it, is not enabled.Gap

🔍 Auditor verification — where to log in and what you will see

AWS physical controlsConsole → AWS Artifact → Reports → download the current AWS SOC 2 Type II and AWS PCI DSS Attestation of Compliance. These cover data-centre physical access, environmental controls and media destruction.
Revique's media encryptionConsole → EC2 → EBS encryption (account attribute) — Enabled in both production regions. Console → S3 → bucket Properties → Default encryption. Console → RDS → cluster Configuration → Encryption.
The exceptionsConsole → RDS → production us-e****-2 → the second MySQL instance shows encryption not enabled; EC2 → Volumes in dev us-e****-2 shows 2 of 3 unencrypted.
The media inventoryAsk the Security Officer for the inventory of media holding CHD/PHI. Not currently maintained.

Team process

The Security Officer obtains AWS's attestations annually from AWS Artifact and files them as evidence of the physical control set. DevOps is responsible for ensuring new storage is encrypted at creation, which the CDK templates and the account-level EBS default enforce for the native production estate.

⚠️ Where reality does not meet the policy

Evidence location. AWS SOC 2 and PCI AoC are downloadable from AWS Artifact. The media inventory would be a Security Officer document.
📘Back to the PolicyPolicy 19 — Physical & Media Security Policy (PCI DSS Req 9)←
Revique security documentation  ·  generated 2026-08-13  ·  all identifiers masked  ·  AWS facts collected read-only on 2026-08-13
Policies define the rule; procedures describe the implementation and how to verify it.