1. Identify
The activities in the Identify function are foundational for an effective Renewi Cyber Security Organization. Understanding the business context, the resources that support critical functions, and the related cybersecurity risks enable Renewi to focus and prioritize its efforts, consistent with its business needs.
1.1 Business environment and Governance
The Renewi Cyber Security organization needs to understand the overall organizational mission, objectives, stakeholders, and activities. This enables Renewi to manage and monitor the organization’s regulatory, legal, risk, environmental, and operational requirements and inform the management of cybersecurity risk.
Key principles
Prioritization and management support
Priorities for organizational mission, objectives, and activities are established and communicated. Renewi (IT) Management actively supports information security within the organization through demonstrated commitment, explicit assignment, and acknowledgment of information security responsibilities;
Information security policy
A Renewi wide information security policy is established and communicated. The Information Security Policy:
- supports the goals and principles of the Information Security Strategy;
- documents the information security roles and responsibilities within Renewi;
- builds on best practices and specifies the key activities that must occur within the organization in the areas of 1.Identify, 2.Protect, 3. Detect, 4. Respond and 5.Recover.
- is approved by Management and is reviewed at planned intervals or if significant changes occur to ensure its continuing suitability, adequacy, and effectiveness