Procedure 21 ADMINISTRATIVE
Personnel Security / Screening Policy — how Revique implements this rule today, and how an auditor verifies it.
Policy 21 · PCI DSS Req 12.7 · 0 of 3 policy statements fully met · AWS facts collected read-only 2026-08-13
← All 21 procedures
📘← Back to Policy 21 — Personnel Security / Screening PolicyThe rule this procedure implements
How Revique implements this today
Personnel screening is an HR control with no AWS footprint. Its relevance to the estate is the sequencing rule: screening must be complete before an individual is given an identity with access to CHD/PHI. The production account's 7 identities are the population this applies to most strictly, alongside the dev and UAT identities that can reach in-scope data.
The rule against the current state
Each row takes a statement from Policy 21 and states what is actually configured. Meets = implemented as written. Partial = implemented, but not everywhere or not to the full standard. Gap = not implemented. N/A = not verifiable from infrastructure configuration.
| The rule | Current state | Verdict |
|---|
| Background screening before access for sensitive roles, subject to local law | Administrative process. Not evidenced, and not correlatable to IAM identity creation dates. | Partial |
| Screening records documented and retained confidentially | HR record. | Partial |
| Re-screening considered on significant role change | Administrative process. | Partial |
🔍 Auditor verification — where to log in and what you will see
The population in scopeConsole → IAM → Users, in each account — 7 in production, 10 in UAT, 10 in dev, with creation dates in the credential report.
The screening recordsAsk HR for screening completion records for personnel with access to CHD/PHI, and compare the completion date against the IAM user_creation_time for the same individual.
Team process
HR performs and documents screening for roles with CHD/PHI access, subject to local law. The Security Officer verifies that screening is complete before authorising the access request that DevOps then provisions (Procedure 04/07). Role changes trigger a re-screening consideration.
⚠️ Where reality does not meet the policy
- Screening completion cannot be correlated to access grants from any available record, so the “prior to access” requirement is asserted rather than demonstrated.
- Long-lived machine and legacy identities in all three accounts predate the current process and have no associated personnel record (shared with Procedure 04/07).
Evidence location. Screening records are confidential HR records held outside AWS.
📘Back to the PolicyPolicy 21 — Personnel Security / Screening Policy (PCI DSS Req 12.7)←