1. Homepage
  2. Trust Center
  3. Security
  4. Detect
  5. Periodic scans Periodic scans

3.3 Periodic scans

Vulnerabilities are weaknesses in information systems, security procedures, internal controls, or implementation that could be exploited by a certain threat. Examples of vulnerabilities could include the absence of a physical security mechanism upon entrance to a facility, a missing security patch or a misconfiguration in software. Renewi performs different types of assessments to timely identify and fix vulnerabilities in its environment.

Technical vulnerability scans

Renewi performs periodic technical internal vulnerability assessments, focusing on infrastructure components. In addition, external vulnerability scans are performed on web applications to identify weaknesses in the perimeter in systems that are accessible from the public internet. Resolving identified vulnerabilities will reduce the risks resulting from exploitation of these technical vulnerabilities.

Security Configuration Assessments

Renewi has established standard secure configurations of operating systems as prescribed in paragraph ‘3.1 Hardening’. Renewi validates these images on a regular basis by performing security compliance scans. Results are used to update the security configurations.

Penetration tests

Renewi performs regular external and internal penetration tests to identify vulnerabilities and attack vectors that can be used to exploit enterprise systems successfully. Penetration testing should occur from outside the network perimeter (i.e., the Internet or wireless frequencies around an organization) as well as from within its boundaries (i.e., on the internal network) to simulate both outsider and insider attacks. Penetration tests include social engineering tests to review risks related to the human element