1.2 Cyber Security Risk management
Renewi understands the cybersecurity risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals. The organization’s priorities, constraints, risk tolerances, and assumptions are established and used to support operational risk decisions.
Key principles
Risk management
Renewi periodically identifies threats that could potentially harm it’s information assets (information security risk analysis). Risks are identified in terms of the likelihood of a given threat-source’s exercising a particular potential vulnerability and the resulting impact of that adverse event on Renewi. Based on the risk analysis, Renewi identifies and evaluates options for the treatment of risks which may lead to updating the Information Security Strategy and Information Security Policy.
Reviews to verify compliancy level
Renewi’s approach to managing information security and its implementation (i.e. policies, procedures and controls for information security) will be reviewed internally and audited externally at planned intervals, or when significant changes to the security implementation occur. Possible recommendations based on such reviews review may lead to updating the Information Security Strategy and Information Security Policy.