EFESAN GROUP INFORMATION SECURITY POLICY
Efesan Group considers it essential to provide exceptional value to society through sustainable growth and adheres to the following principles regarding information security management.
- To protect the knowledge and value generated through production, innovation, research and development, and sustainability activities from unauthorized access and modification, and to ensure their security.
- To protect all commercial and financial information sources and processes belonging to our company, our suppliers, our subcontractors, and our customers, and to ensure their auditability.
- To protect employee and stakeholder personal information from unauthorized access and modification.
- Ensure full compliance with all local and international laws and regulations related to information security.
- To ensure that our customs and foreign trade processes and information resources meet the requirements for physical security, access management, auditability, confidentiality, integrity, availability, and non-repudiation.
Efesan Group aims to carry out its information security activities without compromising the principles outlined above, for the purposes listed below;
- In all work carried out, human life and health are the top priority.
- It is the process of ensuring the security of the information assets, locations, and processes used in the conduct of the company’s operations, taking into account the principles of confidentiality, integrity, and availability.
- The information security management system (ISMS) is planned, implemented, and improved in accordance with the requirements of the internationally recognized ISO 27001 standard.
- The internal audits, management reviews, and corrective actions necessary for the continuous improvement of the ISMS, as well as the actions required to identify risks and opportunities, are carried out by management and the teams designated by management to be responsible for information security.
- The necessary organizational structure, resources, and infrastructure will be established to enable the reporting of information security breaches and ensure that actions are taken as quickly as possible.
- All roles and responsibilities related to information security are defined, controls for the process are established in accordance with the principle of separation of duties, and authorizations are granted by management.
- Management provides the resources necessary to carry out the required work under the BGYS.
- To manage information security risks, risks are analyzed and assessed, and risk mitigation measures are implemented; the necessary precautions are developed, and the required actions to prevent potential risks are planned and carried out.
- We engage in constructive collaboration with government agencies, organizations, and individuals on matters related to the BGYS.
- Appropriate sanctions are imposed in cases of security breaches.
- Information security objectives consistent with this policy and the organization’s purpose are established, and compliance is measured at regular intervals to identify opportunities for improvement.
- Training and awareness programs are developed and implemented to ensure that all employees and relevant stakeholders are aware of their roles and responsibilities under the BGYS.
