The main theme of the Information Security Management System is to demonstrate that information security management is provided within human resources, infrastructure, software, hardware, organizational information, third-party information, and financial resources in IT activities used in our institution's services; to manage information security risks, measure the performance of information security management processes, and regulate relationships with third parties regarding information security matters.
To ensure information security, AKIŞ ASANSÖR commits to:
· Ensuring secure access to information assets for employees and suppliers,
· Protecting the confidentiality, integrity, and availability of information,
· Safeguarding the institution's reliability and brand image,
· Meeting information security requirements arising from national and international regulations, relevant legislation, standard requirements, contractual obligations, and corporate responsibilities toward internal and external stakeholders,
· Reducing the impact of information security threats on business/service continuity and ensuring business continuity and sustainability,
· Maintaining and improving the level of information security with the control infrastructure of the Information Security Board,
· Fulfilling all responsibilities regarding the collection, processing, transfer, protection, and secure destruction of personal data/information belonging to employees, suppliers, business partners, and other relevant third parties under the Personal Data Protection Law No. 6698 (KVKK) and other relevant legislation,
· Providing training to enhance competencies in order to increase information security awareness.