3.1 Security Continuous Monitoring
The information system and assets are monitored to identify cybersecurity events and verify the effectiveness of protective measures.
Key principles
The network is monitored to detect potential cybersecurity events / Intrusion Detection and Intrusion Prevention Systems (IDS/IPS)
Renewi deploys an intrusion detection and prevention systems (IDPS) to detect known bad signatures or the behaviour of potential attacks. Renewi enables the IDPS modules on its firewalls and has additional tools which include full packet capture, network-based and host-based intrusion detection systems (IDS and IPS, respectively) including analysis tools
Network Firewalls
Renewi has network and host based firewalls in place to control the flow of traffic to or from the network and to or from a specific host in the network. Network firewalls are placed in front of any critical server to verify and validate the traffic going to the server. Host based firewalls are configured directly on the host. Any unauthorized services or traffic is blocked.
Web application firewall
Renewi deploys a web application firewalls (WAF) that inspect all traffic flowing to the web application for common web application attacks, including but not limited to cross-site scripting, SQL injection, command injection, and directory traversal attacks. For applications that are not web-based, host-based firewall are be deployed as prescribed in “2.1.Boundary protection – Firewall”.