1. Homepage
  2. Trust Center
  3. Security
  4. Protect
  5. Application and data protection Application and data protection

2.5 Application and data protection

All information stored in applications and underlying databases shall be protected with specific access control lists. These controls will enforce the principal that only authorized individuals should have access to the information based on their need to access the information as a part of their responsibilities. “Access to applications and data is configured through the requirements as prescribed in “2.1 Idendity management and …

Attacks often take advantage of vulnerabilities found in web-based and other application software. Vulnerabilities can be present for many reasons, including coding mistakes, logic errors, incomplete requirements, and failure to test for unusual or unexpected conditions. Examples of specific errors include the failure to check the size of user input; failure to filter out unneeded but potentially malicious character sequences from input streams; failure to initialize and clear variables; and poor memory management allowing flaws in one part of the software to affect unrelated portions. Attackers can inject specific exploits, including buffer overflows, SQL injection attacks, cross-site scripting, cross-site request forgery, and click-jacking of code to gain control over vulnerable machines.

Data resides in many places. Protection of that data is best achieved through the application of classification/labelling in combination with encryption techniques and data loss prevention solutions. Encrypting data provides a level of assurance that even if data is compromised, it is impractical to access the plaintext without significant resources.

Key principles

Development

In addition to paragraph “1.1.Personnel”, Renewi provides additional focus to information security and privacy aspects towards its in house software development personnel. In their software development process, developers have specific attention for security practices (e.g. in their coding).

Test of in-house developed software

Renewi tests in-house-developed and third-party-procured web applications for common security weaknesses using automated remote web application scanners prior to deployment, whenever updates are made to the application, and on a regular recurring basis (as prescribed in ‘5. Information Security Operations – Security assessments and scans’). In addition, Renewi will conduct periodic penentration tests on critical applications.

Data classification

Renewi’s data-, information-, or business owners are responsible for any information asset and the data that resides in it. They ensure that the business information is assigned with the appropriate classification (e.g. confidential, internal and public).

Renewi’s IT department together with the Security Officer enables the business with tooling that makes it possible to classify data according to the classification scheme of the business. This leads to an appropriate protection of the data in line with the importance to Renewi.

Encryption

Renewi deploys hard drive encryption software to mobile devices and systems that hold Renewi data. Also, backups are properly protected via encryption when they are stored, as well as when they are moved across the network.

Data loss prevention

Data loss prevention (DLP) refers to a system that protects data in use (e.g., endpoint actions), data in motion (e.g., network actions), and data at rest (e.g., data storage) through deep content inspection and with a centralized management framework. Renewi utilizes DLP controls from its Office365 environment, focused on sensitive information across locations, such as Exchange Online, SharePoint Online, and OneDrive for Business as well as capabilities to identify sensitive information and apply DLP policies directly in Excel 2016, PowerPoint 2016, and Word 2016.

Mobile devices

Renewi identifies and manages devices such as mobile phones and tablets that store or process Renewi data, regardless of whether they are attached to the organization’s network. When Renewi data is processed on (un)managed devices, Renewi then securely manages iOS, Android, Windows, and macOS devices from a single, unified mobile solution (keep Renewi data safe without managing the users' private devices).