The purpose of this procedure is to define senior management’s approach and objectives, and to communicate these objectives to all employees and relevant parties, in order to prevent violations of legal, regulatory, contractual obligations, and all types of security requirements. The organization has defined the boundaries and applicability of the Information Security Management System to establish its scope.
The ISMS has been established to ensure the security of critical information assets consisting of hardware and software in the office. Due to the characteristic nature of the business as an organizational service infrastructure, its processes, location, assets, and technology are included within the system.
The qualifications and competencies of individuals with defined responsibilities and authorities are outlined in their job descriptions. The IT Department, Management Representative, System Administrator, and Senior Management are responsible for the continuity and development of information security-related activities. The ISMS Team and Management Representative have been appointed by Senior Management. ISMS representatives have been designated from the departments within the scope.
Responsibility of All Employees:
• To carry out their work in accordance with information security objectives, policies, ISMS documentation, and their authorities.
• To monitor information security objectives related to their respective departments and ensure these objectives are met.
• To observe and report any observed or suspected information security vulnerabilities in systems or services.
• To be responsible for signing confidentiality agreements in addition to service contracts (consultancy, etc.) made with third parties not under purchasing responsibility, and for ensuring information security requirements are met.
• All job descriptions within the organization are available.
Responsibility of Third Parties:
Third parties are responsible for knowing and implementing the information security policy and for complying with the behaviors defined within the scope of the ISMS. Compliance with contracts made with third parties (confidentiality agreements) is mandatory, and in case of non-compliance, fulfilling the sanctions specified in the contract is among the defined responsibilities.
The ISMS has been established to ensure the security of critical information assets consisting of hardware and software in the office. Due to the characteristic nature of the business as an organizational service infrastructure, its processes, location, assets, and technology are included within the system.
The scope of the Organization’s ISMS is defined as: “Information Security for Electronic Information Assets and the Information Security Used to Protect These Assets in Customs and Foreign Trade Operations such as Import, Export, Transit, and Customs Clearance for International Transport and Logistics Activities, and Related Logistics, Warehousing, Accounting, Finance, and IT Activities.”
There are no out-of-scope items.
Internal Issues:
The structure, roles, and responsibilities related to the organization; these are the departments within the scope of the organization’s management structure.
Policies, objectives, and strategies to be implemented:
• Policies defined in all management systems,
• ISMS Policies,
• Annual ISMS objectives determined by management,
• Capabilities understood in terms of resources and knowledge (capital, time, people, processes, systems, and technologies),
• Management representative and ISMS team appointed by management for the establishment, operation, and maintenance of the information security management system,
Includes relationships with internal stakeholders and their perceptions, values, organizational culture, standards, guidelines, models adopted by the organization, and the form and extent of contractual relationships.
External Issues:
• Social and cultural, political, legal, regulatory, financial, technological, economic, natural, and competitive environment, whether international, national, regional, or local,
• Confidentiality of supplier (third-party) data,
• Quality orientation,
• Relationships with stakeholders whose impact affects the organization’s objectives, and their perceptions and values,
• All employees of the organization, including senior management, to ensure local public satisfaction,
• All relevant legal regulations, regulatory, contractual requirements, standards,
• Product certifications with other organizations are outside the scope.
ISMS: Information Security Management System.
Asset Inventory: All types of information assets and hardware important to the organization.
Senior Management: Authorities consisting of the organization’s senior management board.
Information Security: Information, like all other corporate and commercial assets, is an asset that has value for an organization and therefore must be appropriately protected. The organization classifies know-how, business processes, forms, contracts, third-party records, personnel information, commercial, industrial, and technological information and secrets according to asset class (top secret, confidential, internal, public) and treats them as assets according to their class.
Confidentiality: Restricting the viewing of information content only to persons authorized to view the information/data.
Integrity: The ability to detect unauthorized or accidental modification, deletion, or addition/removal of information, and ensuring its detectability.
Availability: The asset being ready for use whenever needed. In other words, systems must be continuously serviceable, and information in the systems must not be lost and must be continuously accessible. This document will use “Availability”.
Information Asset: Assets owned by the organization’s management that are important for the uninterrupted conduct of its operations. Within the scope of the processes covered by this policy, information assets include:
• Forms, contracts, files, all kinds of information and data presented in visual or auditory media,
• All kinds of software and hardware used to access and modify information,
• Networks that enable the transfer of information,
• Departments, units, teams, and employees,
• Services or products provided by third parties.
Information Security Objectives:
The information security policy aims to guide organization employees on acting in accordance with the organization’s security requirements, to increase their awareness and consciousness levels, and thereby ensure the continuity of the organization’s primary and supporting business activities with minimal interruption, to protect its reliability and image, and to protect physical and electronic information assets affecting all operations to ensure compliance defined in contracts with third parties. Objectives determined by management are monitored at defined periods and reviewed in Management Review Meetings (YGG).
The objective and target plan document is also found in the PL.001 Objective and Target Plan document under clause 6.2 of the ISO27001 Information Security Management System.
General Principles of Information Security:
• Details regarding the information security requirements and rules outlined by this policy, organization employees and third parties are obliged to know these policies and conduct their work in accordance with these rules.
• Unless otherwise specified, these rules and policies are essential to be considered for the use of all information systems and all information stored and processed in printed or electronic media.
• The Information Security Management System is structured and operated based on the TS ISO/IEC 27001 Information Technology Security Techniques and Information Security Management Systems Requirements standard.
• It carries out its efforts for the implementation, operation, and improvement of the ISMS with the contribution of relevant parties. The ISMS Officer is responsible for updating ISMS documents when necessary.
• Confidentiality agreements are made with employees, consulting firms, and supplier firms from which services are procured.
• Information security controls to be applied during recruitment, job changes, and termination processes are determined and implemented.
• Training sessions that will increase employees’ information security awareness and enable them to contribute to the system’s operation are regularly provided to existing employees and new hires.
• All actual or suspected information security breaches are reported; non-conformities causing breaches are identified, root causes are found, and preventive measures are taken to avoid recurrence.
• An inventory of information assets is created in line with information security management needs, and asset ownerships are assigned.
• Corporate data is classified, and the security needs and usage rules for data in each class are determined.
• Physical security controls are applied in parallel with the needs of assets stored in secure areas.
• Necessary controls and policies are developed and implemented for information assets against physical threats they may be exposed to inside and outside the organization.
• Procedures and instructions related to capacity management, third-party relationships, backup, system acceptance, and other security processes are developed and implemented.
• Audit log generation configurations for network devices, operating systems, servers, and applications are set in parallel with the security needs of the relevant systems. Protection of audit logs against unauthorized access is ensured.
FR.001 Internal and External Communication Form
TB.001 Needs and Expectations of Interested Parties
LS.009 List of Internal and External Issues