Purpose
The purpose of this policy is to ensure that the information assets belonging to the units served by TEKİŞ ELEKTRİK and TEK TRANSFORMATÖR are protected and managed appropriately.
Scope
The Information Security Management System covers all units within TEKİŞ ELEKTRİK and TEK TRANSFORMATÖR. Implementing this policy is essential for establishing and maintaining information security in relationships with the units receiving services.
Under our Information Security Policy:
- Information assets are protected against unauthorised access.
- The confidentiality, integrity and availability of information are safeguarded.
- Information is prevented from being disclosed to unauthorised persons, whether intentionally or through negligence.
- The accuracy and currency of information are maintained.
- Information is made available to authorised users whenever required.
- Applicable legal, regulatory and contractual requirements are fulfilled.
- Information security procedures are implemented across all units.
- Regular information security training is provided to all employees.
- Identified security vulnerabilities are reported to the relevant unit manager, and necessary measures are taken.
- Vulnerabilities that cannot be resolved by the relevant unit are managed by the information security officers.
- Activities carried out with contractors and cooperating companies comply with information security procedures.
Identity information, customer information, software packages, servers and other information assets included in the asset inventory are within the scope of protection.
Applicability
All TEKİŞ ELEKTRİK and TEK TRANSFORMATÖR employees who interact with information assets covered by the Information Security Management System must comply with this policy. Senior management supports the implementation and continuity of the system by providing the necessary resources.
Objectives
- Identify the value and vulnerabilities of information assets and the threats that may put them at risk through appropriate risk assessments,
- Reduce information security risks to acceptable levels,
- Comply with applicable laws, regulations and customer requirements,
- Establish the infrastructure required to protect customer data at the highest level,
- Comply with information security control procedures and instructions,
- Achieve and maintain compliance with TS ISO/IEC 27001,
- Protect the company and its employees against penalties, threats and damage arising from improper information sharing,
- Protect the company’s reliability and corporate reputation.
Supporting Policies
- Clear Screen and Clear Desk Policy
- Email Policy
- Access Control Policy
Responsibilities
The senior management of TEKİŞ ELEKTRİK and TEK TRANSFORMATÖR is responsible for approving and regularly reviewing this policy. The Information Security Manager and Quality Management Representative support its implementation in accordance with the relevant standards and procedures.
All employees are responsible for complying with the information security policy and related procedures, reporting security incidents and notifying the relevant parties of identified vulnerabilities.
Any intentional act that may compromise the security of information belonging to TEKİŞ ELEKTRİK, TEK TRANSFORMATÖR, customers or suppliers, as well as any failure to comply with policies and instructions, may result in disciplinary action and legal proceedings under applicable legislation.
Review
This policy is regularly evaluated during Management Review meetings conducted within the scope of the Quality Management System.