2.6 E-mail and web browsers
Web browsers and email clients are very common points of entry and attack because of their high technical complexity and flexibility, and their direct interaction with users and with the other systems and websites. Content can be crafted to entice or spoof users into taking actions that greatly increase risk and allow introduction of malicious code, loss of valuable data, and other attacks.
It is important that Renewi minimizes the attack surface and the opportunities for attackers to manipulate human behavior though their interaction with web browsers and email systems.
Key principles:
Updated versions
Renewi has only fully supported web browsers and email clients in its image allowed, only using the latest version of the browsers provided by the vendor in order to take advantage of the latest security functions and fixes. Since end users are however able to install their own software, Renewi actively encourages employees to keep their installed software up to date (user awareness campaigns) and software inventory monitoring.
URL filtering
Renewi maintains URL filters that limit a system's ability to connect to websites that are not approved by the organization (e.g. porn, gambling etc.)
Spoofing
To lower the chance of spoofed e-mail messages, Renewi has implemented the Sender Policy Framework (SPF) by deploying SPF records in DNS and enabling receiver-side verification in mail servers.
Attachments
Renewi scans and block all e-mail attachments entering the organization's e-mail gateway if they contain malicious code or file types that are unnecessary for the organization's business. This scanning is done before the e-mail is placed in the user's inbox. This includes e-mail content filtering and web content filtering.