1.3 Supply Chain Risk Management
The organization’s priorities, constraints, risk tolerances, and assumptions are established and used to support risk decisions associated with managing supply chain risk. The organization has established and implemented the processes to identify, assess and manage supply chain risks.
Key principles
Externals who are granted access to the Renewi network, systems and applications
Renewi applies the following requirements for externals who have access to the Renewi network, systems and applications:
- Externals are granted access to systems and applications in accordance with the regular Renewi process for assigning, mutating and revoking accounts and access rights;
- Identification and authentication is based on the access control requirements as prescribed in paragraph ‘2.1 – Identity Management and Access Control’ of this Information Security Policy.
- Externals must sign a ‘Network Access Agreement’ (NAA) before access is granted to the network. This concerns a general declaration of awareness of dealing with the provided access, in which the person declares to work on the Renewi network with due care and attention and only to perform activities that are part of the job.
- Externals need to sign a ‘Non-Disclosure Agreement’ (NDA) if access to confidential information is granted;
Requirements for externals where Renewi data is processed (cloud suppliers);
Renewi applies the following requirements to externals where Renewi data is processed (cloud providers);
- The external party may only process data if a contract or SLA has been agreed setting out the requirements with respect to information security. The external party needs to meet these requirements to guarantee the availability, integrity and confidentiality of Renewi data. These requirements must be added to the contract / SLA and include security requirements in the areas of:
- Application Security;
- Data Security;
- Threat Management;
- Infrastructure Security;
- Physical Security;
- Business Continuity;
- Security Procedures;
- Governance;
- Depending on the value and sensitivity of the information the third party comes into contact with, a specific non-disclosure paragraph needs to be inserted in the agreement;
- If the service involves the processing of personal data, a data processing agreement needs to be agreed;
- Agreements regarding the ownership of data need to be made with the external;
- Agreements regarding the auditability are made with the external party. Through a right to audit and/or certification, Renewi needs to be able to gain an insight into the quality of the measures adopted by the supplier;
Monitor and evaluate third parties
Renewi monitors and assesses the services of suppliers to guarantee that the information security conditions are complied with, and that incidents and problems are correctly handled. The following guidelines apply to suppliers:
- Suppliers communicate (using SLA reports) about the level of the provided services;
- Renewi assesses performance levels to verify compliance with the contract/SLA;
- Progress talks are regularly held to discuss contracts/SLAs as well as performance regarding the provided services.
Suppliers submit their certifications and/or audit reports to Renewi (e.g. ISAE 3402 assurance reports or ISO:27001 security certifications);