With the implementation of this policy, it aims and commits to fulfill the following basic principles required to protect, ensure the continuity, and sustainability of the Information Security Management System and information assets in terms of confidentiality, integrity, and accessibility.
· Ensuring compliance with the laws of the Republic of Türkiye, regulations, circulars, customer contracts, and requirements determined by the legal legislation required by the business,
· Guaranteeing the confidentiality of information belonging to personal, corporate, or Third Parties (produced and/or used) in all cases,
· Ensuring that information is accessible only by authorized persons in accordance with the "need-to-know" principle,
· Preventing the unauthorized use, modification, disclosure, and damage of all information assets, whether intentionally or unintentionally,
· Providing the necessary support and contribution to the activities to be carried out regarding reducing the risks on information assets to acceptable levels by conducting risk assessments,
· Providing the necessary support for the planning regarding the regular provision of awareness programs to employees and, where relevant, supplier employees, which will increase the management system awareness of the personnel and encourage them to contribute to the functioning of the system,
· Providing the necessary support for the activities aimed at detecting, reporting, closing, and preventing the recurrence of all actual or suspected breaches of information security incidents,
· Providing the necessary support and contribution to ensure that continuous access to information occurs at planned levels by ensuring business continuity,
· Providing the necessary participation and support regarding the creation, documentation, and continuous improvement of documents to fulfill the requirements of ISO 27001 and ISO 27701 standards of our management system and ensuring compliance with their requirements,
· Determining preventive approaches that will improve performance by reviewing business processes through the self-assessment process,
· Contributing to society by providing reliable services to customers and relevant parties,
· Increasing the effectiveness of our quality management systems in addition to complying with laws and regulations and meeting customer requirements,
· Preparing the personal data inventory and conducting privacy impact assessment studies within the scope of ISO 27701,
· Efforts will be made to take information security requirements into consideration at every stage by integrating the ISO 27001 and ISO 27701 Management System into the business processes of our company.
