 |
INFORMATION SECURITY POLICY
|
| Document No. |
IC.YS.PLTK.04 |
| Publication Date |
July 2, 2024 |
| Revision No. |
00 |
| Revision Date |
– |
| Page No. |
1/10 |
|
TABLE OF CONTENTS
- PURPOSE
- SCOPE
- DEFINITIONS
- RESPONSIBILITIES
- INTEGRATED MANAGEMENT SYSTEM OBJECTIVES
- RISK MANAGEMENT FRAMEWORK
- GENERAL PRINCIPLES OF THE INTEGRATED MANAGEMENT SYSTEM
- POLICY VIOLATIONS AND SANCTIONS
- MANAGEMENT REVIEW
- UPDATING AND REVIEWING THE INTEGRATED MANAGEMENT SYSTEM POLICY DOCUMENT
| PREPARED BY |
APPROVED BY |
| IMMS MANAGEMENT REPRESENTATIVE |
CEO |
 |
INFORMATION SECURITY POLICY
|
| Document No. |
IC.YS.PLTK.04 |
| Publication Date |
July 2, 2024 |
| Revision No. |
00 |
| Revision Date |
– |
| Page No. |
2/10 |
|
1. Purpose
The purpose of this policy is to prevent violations of legal, statutory, regulatory, or contractual obligations, as well as any security requirements, within the organization’s physical framework, to prevent violations of legal, regulatory, or contractual obligations and all security requirements under the ISO/IEC 27001 standards, and to communicate these objectives to all employees and relevant parties.
2. Scope
The protection of electronic information assets generated from commercial activities conducted within the organization and from information systems, accounting, reporting, operations, customer relations, complaints, risk management, and internal management activities; the processing, storage, and protection of personal data held within the company in accordance with the law; and the information security processes used to ensure that the confidentiality and integrity of such data are not compromised.
3. Definitions
ISMS: Information Security Management System.
Information Security Management System Manual: An informational booklet prepared to educate staff about information security and to define objectives.
Inventory: All types of information assets that are important to the company.
Know-How: The ability to perform a specific task.
| PREPARED BY |
APPROVED BY |
| ISMS MANAGEMENT REPRESENTATIVE |
CEO |
 |
INFORMATION SECURITY POLICY
|
| Document No. |
IC.YS.PLTK.04 |
| Publication Date |
July 2, 2024 |
| Revision No. |
00 |
| Revision Date |
– |
| Page No. |
3/10 |
|
Information Security: Information, like all other corporate and commercial assets, is a valuable asset for a business and must therefore be properly protected. Within the company, know-how, processes, formulas, techniques and methods, customer records, marketing and sales information, personnel information, and commercial, industrial, and technological information and secrets are considered CONFIDENTIAL INFORMATION.
Confidentiality: The restriction of access to the content of information so that it is viewable only by those authorized to access the information or data. (Example: Even if an encrypted email is intercepted, unauthorized individuals can be prevented from reading it through Registered Electronic Mail – KEP)
Integrity: The ability to detect unauthorized or accidental modification, deletion, or addition/removal of information, and ensuring that such detection is guaranteed. (Example: Storing data in a database along with its hash values—electronic signature—mobile signature)
Availability: The asset must be ready for use whenever needed. In other words, systems must remain continuously operational, and the information within them must not be lost and must remain continuously accessible.
Information Assets: These are assets owned by the company that are essential for conducting its operations without disruption. Within the scope of the processes covered by this policy, information assets include the following:
- Any type of information and data presented in paper, electronic, visual, or audio formats,
- Any software and hardware used to access or modify information,
| PREPARED BY |
APPROVED BY |
| ISMS MANAGEMENT REPRESENTATIVE |
CEO |
 |
INFORMATION SECURITY POLICY
|
| Document No. |
IC.YS.PLTK.04 |
| Publication Date |
July 2, 2024 |
| Revision No. |
00 |
| Revision Date |
– |
| Page No. |
4/10 |
|
- Networks that facilitate the transfer of information,
- Facilities and private areas,
- Departments, units, teams, and employees,
- Solution partners,
- Services, products, or offerings provided by third parties.
4. RESPONSIBILITIES
Responsibilities and authorities are defined in job descriptions based on the qualifications and competencies required for each role. The Integrated Management System Management Representative is responsible for maintaining and developing activities related to the Integrated Management System.
The Integrated Management System Management Representative is appointed by the General Manager.
4.1. Management Responsibility
- Company Management commits to complying with the defined, implemented, and active Integrated Management System; to allocating the necessary resources to ensure the system operates efficiently; and to ensuring that the system is understood by all employees.
| PREPARED BY |
APPROVED BY |
| BGYS MANAGEMENT REPRESENTATIVE |
CEO |
 |
INFORMATION SECURITY POLICY
|
| Document No. |
IC.YS.PLTK.04 |
| Publication Date |
July 2, 2024 |
| Revision No. |
00 |
| Revision Date |
– |
| Page No. |
5/10 |
|
- The Management Representative is appointed via an appointment letter during the establishment of the BGYS. When necessary, the Board of Directors revises the document and reappoints the representative.
- Managers at the management level assist by delegating responsibility for safety to lower-level staff and by setting an example. The approach established and implemented by the Board of Directors must extend all the way down to the company’s lowest-level employees. Therefore, all managers support their employees—both verbally and in writing—to ensure they comply with safety instructions and participate in safety-related activities.
- The Board of Directors establishes the budget required for comprehensive work within the integrated management system.
4.2. Responsibilities and Duties of the BGYS Management Representative
- Work in accordance with the BGYS Policy and Objectives
- Organize the creation, implementation, and maintenance of the necessary documentation for the Integrated Management System.
- Reporting to top management whenever there is a need regarding the performance and improvement of the Integrated Management System.
- Ensure that procedures are prepared, review them for compliance with the BGYS, and approve them,
| PREPARED BY |
APPROVED BY |
| BGYS MANAGEMENT REPRESENTATIVE |
CEO |
 |
INFORMATION SECURITY POLICY
|
| Document No. |
IC.YS.PLTK.04 |
| Publication Date |
July 2, 2024 |
| Revision No. |
00 |
| Revision Date |
– |
| Page No. |
6/10 |
|
- To raise awareness of the BGYS within the company by providing various training sessions at all levels,
- Ensure that awareness of customer requirements is widespread throughout the organization;
- To collaborate with external parties on matters related to the Integrated Management System.
- Ensure that all departments operate in accordance with the information technology quality objectives and policies and establish coordination.
- To prepare or review procedures, instructions, and forms and submit them to the Company Manager for approval.
- Ensure that corrective actions are initiated, carried out, and monitored through the appropriate channels.
- To plan and monitor internal audit activities to ensure that all functions within the scope of the Integrated Management System are audited at least once a year.
- Include internal audit findings on the agenda of the Management Review Meeting.
- Monitor the implementation of decisions made at the Management Review Meeting.
- Manage and maintain control over the records of the Integrated Management System.
- Comply with the general operating rules of the Information Technology department.
| PREPARED BY |
APPROVED BY |
| BGYS MANAGEMENT REPRESENTATIVE |
CEO |
 |
INFORMATION SECURITY POLICY
|
| Document No. |
IC.YS.PLTK.04 |
| Publication Date |
July 2, 2024 |
| Revision No. |
00 |
| Revision Date |
– |
| Page No. |
7/10 |
|
4.3. Duties of the Information Technology Officer
- Manage information technology operations
- To conduct budget planning
- Work in accordance with the BGYS Policy and Objectives
- Monitor the implementation of decisions made at the Management Review Meeting.
- To carry out the management and control of Integrated Management System records.
- Act in accordance with the general operating rules of Information Technology.
- Performing the duties assigned to them in policies, procedures, and instructions.
5. INTEGRATED MANAGEMENT SYSTEM OBJECTIVES
To protect all information assets within its critical systems; to operate in compliance with legislation, contracts, and international standards within the framework of the Integrated Management System; Manage risks within the Integrated Management System, implement corrective and improvement actions, and establish a sustainable system in line with the organization’s purpose. The objectives set by Management are monitored at specified intervals and reviewed during Management Review meetings.
| PREPARED BY |
APPROVED BY |
| BGYS MANAGEMENT REPRESENTATIVE |
CEO |
 |
INFORMATION SECURITY POLICY
|
| Document No. |
IC.YS.PLTK.04 |
| Publication Date |
July 2, 2024 |
| Revision No. |
00 |
| Revision Date |
– |
| Page No. |
8/10 |
|
6. RISK MANAGEMENT FRAMEWORK
The company’s risk management framework covers the identification, assessment, and treatment of information security risks. The risk analysis, statement of applicability, and risk treatment plan define how information security risks are controlled. The ISMS Management Representative is responsible for the management and implementation of the risk treatment plan. All of these activities are detailed in the asset inventory and risk assessment procedure.
7. GENERAL PRINCIPLES OF THE INTEGRATED MANAGEMENT SYSTEM
7.1. Company employees and third parties are required to be familiar with this policy and the procedures it outlines, as well as the information security requirements and rules it establishes, and to conduct their work in accordance with these rules.
7.2. Unless otherwise specified, these rules and policies must be taken into account for the use of all information—whether stored and processed in printed or electronic form—and all information systems.
7.3. The Integrated Management System is structured and operated based on the TS ISO/IEC 27001 standard.
7.4. The implementation, operation, and improvement of the ISMS are carried out with the contribution of relevant parties. The ISMS Management Representative is responsible for updating ISMS documentation as needed.
7.5. The information systems and infrastructure provided by the company to employees or third parties, as well as all types of information, documents, and products generated using these systems, belong to the company unless otherwise required by law or contract.
7.6. Confidentiality agreements are entered into with employees, consultants, service providers (security, maintenance, catering, cleaning companies, etc.), suppliers, and interns.
| PREPARED BY |
APPROVED BY |
| BGYS MANAGEMENT REPRESENTATIVE |
CEO |
 |
INFORMATION SECURITY POLICY
|
| Document No. |
IC.YS.PLTK.04 |
| Publication Date |
July 2, 2024 |
| Revision No. |
00 |
| Revision Date |
– |
| Page No. |
9/10 |
|
7.7. Information security controls to be applied during hiring, job reassignment, and termination processes are defined and implemented.
7.8. Training sessions designed to increase employees’ information security awareness and ensure their contribution to the system’s operation are regularly provided to current and new employees.
7.9. All actual or suspected information security breaches are reported; nonconformities causing breaches are identified, root causes are determined, and measures are taken to prevent recurrence.
7.10. An inventory of information assets is created in accordance with integrated management requirements, and ownership of the assets is assigned.
7.11. Corporate data is classified, and the security requirements and usage rules for each class of data are defined.
7.12. Physical security controls are implemented in accordance with the needs of assets stored in secure areas.
7.13. Necessary controls and policies are developed and implemented to protect the company’s information assets against physical threats they may face both inside and outside the organization.
7.14. Procedures and instructions related to capacity management, third-party relationships, backup, system acceptance, and other security processes are developed and implemented.
7.15. Audit log generation configurations for network devices, operating systems, servers, and applications are set in accordance with the security requirements of the relevant systems. Audit logs are protected against unauthorized access.
7.16. Access rights are assigned on a need-to-know basis. The most secure technologies and techniques available are used for access control.
7.17. Security requirements are defined during system procurement and development, and compliance with these requirements is verified during system acceptance or testing.
| PREPARED BY |
APPROVED BY |
| ISMS MANAGEMENT REPRESENTATIVE |
CEO |
 |
INFORMATION SECURITY POLICY
|
| Document No. |
IC.YS.PLTK.04 |
| Publication Date |
July 2, 2024 |
| Revision No. |
00 |
| Revision Date |
– |
| Page No. |
10/10 |
|
7.18. Continuity plans for critical infrastructure are prepared, maintained, and tested.
7.19. The necessary processes are designed to ensure compliance with laws, internal policies and procedures, and technical security standards; compliance is ensured through continuous and periodic monitoring and audit activities.
8. POLICY VIOLATIONS AND SANCTIONS
If non-compliance with the Integrated Management System Policy and Standards is detected, the sanctions specified in the Disciplinary Procedure are applied to the employees responsible for the violation.
9. MANAGEMENT REVIEW
Management review meetings are organized by the Integrated Management System Management Representative, with the participation of the Board of Directors and Department Heads. These meetings, during which the suitability and effectiveness of the Integrated Management System are evaluated, are held at least once a year.
10. UPDATE AND REVIEW OF THE INTEGRATED MANAGEMENT SYSTEM POLICY DOCUMENT
The IMS Management Representative is responsible for ensuring the continuity and review of the policy document. Policies and procedures must be reviewed at least once a year. In addition, they must be reviewed following any changes that affect the system structure or risk assessment, and if any changes are necessary, they must be approved by senior management and recorded as a new version. Each revision must be published in a manner accessible to all users.