4. Respond
The Respond Function supports the ability to contain the impact of a potential cybersecurity incident
Communications (RS.CO): Response activities are coordinated with internal and external stakeholders (e.g. external support from law enforcement agencies).
4.1 Incident Response and Management
Cyber incidents are part of our way of life as they become more frequent. When an incident occurs, it is too late to develop the right procedures, reporting, data collection, management responsibility, legal protocols, and communications strategy that will allow Renewi to successfully understand, manage, and recover. It is therefore important that Renewi has an incident response plan.
Within Renewi, an ‘information security incident’ is defined as an incident that is the result of an attack or the result of malicious or (un)intentional actions on the part of end users. Examples include:
- Any attempted network intrusion;
- Any attempted DDoS attack;
- Any detection of malicious software;
- Any incoming malicious e-mail;
- Any unauthorized access of data; (incl. e.g. stolen device)
- Any violation of security policies.
Key principles
Incident response procedure
Renewi follows up security incidents in accordance with its general incident management procedure in terms of ‘detect – response – mitigate – report – recovery – remediation – evaluation’. Detection of an incident could be the result of the violation of any key principle as described in this policy.
Third party information on security incidents/threats
As large parts of the IT infrastructure are outsourced, Renewi assembles and maintains information on third-party contact information to be used to report a security incident
Information and updates
Renewi publishes information for all personnel, including employees and contractors, regarding reporting computer anomalies and incidents to the incident handling team. Such information is included in routine employee awareness activities.