1. Homepage
  2. Trust Center
  3. Security
  4. Protect
  5. System protection System protection

2.4 System protection

Renewi is responsible for ensuring the confidentiality, integrity, and availability stored on its systems.  Renewi therefore has an obligation to provide appropriate protection against malware threats, such as viruses, trojans, and worms which could adversely affect the security of the system or its data entrusted on the system.

It is important that Renewi has an effective patch policy that will limit the exposure and effect of common malware threats to the systems within this scope.

Key principles:

Baselines and hardening

Renewi establishes standard secure configurations of its systems in the network, primarily clients, servers and their operating systems. Any new system deployment or existing system that becomes compromised should be imaged using one of those images or templates. These images are validated and refreshed on a regular basis to update their security configuration in light of recent vulnerabilities and attack vectors (as prescribed in ‘5. Information Security Operations – Security assessments and scans’)

Patching clients and servers

Client machines (Windows) are patched on a monthly basis. For servers, Windows machines are also patched on a monthly basis, where UNIX machines are patched on a semi-annual basis. When vulnerabilities are exposed that require immediate patching, Renewi deviates from these schemes and patches will be installed directly through an emergency change management procedure.

Patch others

All other software (e.g. Java, Adobe Reader, Apache, PHP, etc.) are patched at minimum at a yearly basis, or when vendors issue patches that need immediate installing or when vulnerability scans exposure a risk that require patching. Such vulnerability scans are performed as prescribed in “5.2.Security assessments and scans