安全
保护我们的员工和产品以及我们所信赖的数据。
安全为何如此重要
治理
我们的数据安全实践符合萨班斯-奥克斯利法案, 欧盟通用数据保护条例 (GDPR), and Greif’s Records Management and Retention Policy. Greif’s Information Technology Team, led by our manager of Global IT Security, manages data security, which includes annual audits for IT control processes, quarterly reviews of data permissions, and quarterly phishing simulations. At the center of our security operations is training. All colleagues with access to computers are required to complete quarterly cybersecurity training, receive quarterly newsletters promoting cybersecurity awareness and weekly security tips on topics ranging from password security to avoiding phishing scams, and participate in our annual Cybersecurity Month each October. Greif Executives receive updates through a cybersecurity dashboard that is shared with Greif’s Enterprise Risk Management Team and Board quarterly. The dashboard currently tracks our performance using the 美国国家标准与技术研究院 NSF 成熟度指数评分. Should Greif fall victim to a cybersecurity breach, we maintain an IT Services Cyber Incident and Response Plan and an IT Services Global Business Continuity Plan, which outlines our steps to quickly respond to and mitigate the impact of an incident. Greif received no substantiated complaints concerning breaches of customer privacy and identified no leaks, thefts, or losses of customer data in 2020.
为了管理我们建筑物的物理安全,Greif 在我们的设施中安装了标签读取器和 PIN 码锁。我们要求从我们的设施提货的每批货物都提供提货单。Greif 通过提供防篡改封盖来支持整个供应链的产品安全。
Since 2018 we have been working to implement findings from a cybersecurity maturity assessment we conducted in collaboration with a third-party partner. We introduced annual online Cybersecurity and Awareness training to help improve our colleagues’ ability to identify and respond to potential threats and minimize risk in both digital and physical spaces. After completing the training, each of our colleagues must complete a quarterly checkup, ensuring knowledge is retained and put into practice. The training is mandatory for all colleagues with access to computers, including our Executive Leadership Team. To further comply with GDPR, we have conducted GDPR training for our colleagues in EMEA and began establishing a formal data classification framework. The framework will help us better understand, and ultimately manage, the personal information we store.
Each month members of Greif’s cybersecurity and legal departments meet to discuss compliance with current and emerging data security and data privacy regulations. We monitor regulatory changes and actions required to ensure compliance.
In 2019 we established a three-year cybersecurity strategy that we began implementing in 2020. As part of this strategy, we have implemented single-sign-on (SSO) and multi-factor authentication (MFA) to Greif exposed applications. We have also implemented next-gen antivirus solutions with endpoint detection and response services. Our colleagues now have the ability to self-tag their information and emails with the proper data classification based on our new data classification framework. In 2021, we will continue to develop our cybersecurity strategy with a focus on the industrial internet of things, third-party risk management, and increasing our incident response capability.
土耳其 FPS 获得 ISO 27001 认证
自 2018 年以来,Greif 的土耳其柔性产品和服务 (FPS) 业务已获得 ISO 27001 认证,这体现了我们致力于保护 Greif 及其客户的信息资产安全的承诺。该认证表明信息安全管理系统 (ISMS) 符合国际最佳实践,并展示了 FPS 土耳其为遵守欧洲通用数据保护条例 (GDPR) 所做的重大努力。该认证以 FPS 土耳其令人印象深刻的质量资质为基础,其中包括 ISO 9001 认证的质量管理体系、符合 BRC IoP 全球包装和包装材料标准第 6 版的 AA 级产品安全管理体系和符合 ISO 14001 的环境管理体系。