Efesan Group considers the delivery of superior value to society through sustainable growth to be an indispensable principle and adopts the following principles regarding information security management:
- To protect the information and values generated through production, innovation, research and development, and sustainability activities against unauthorised access and modification, and to ensure their security.
- To protect all commercial and financial information assets and processes belonging to our company, suppliers, subcontractors and customers, and to ensure their auditability.
- To protect the personal data of employees and stakeholders against unauthorised access and alteration.
- To ensure full compliance with all applicable local and international laws and regulations related to information security.
- To ensure the physical security, access management, auditability, confidentiality, integrity, availability and non-repudiation of our Customs and Foreign Trade processes and information assets.
Without compromising the principles set out above, Efesan Group aims to carry out its information security activities in accordance with the following objectives:
- Human life and health shall be the highest priority in all activities undertaken.
- To ensure the security of information assets, facilities and processes used in the conduct of the company’s activities, taking into account the principles of confidentiality, integrity and availability.
- The Information Security Management System (ISMS) shall be planned, implemented and continually improved in accordance with the requirements of the internationally recognised ISO/IEC 27001 standard.
- The internal audits, management reviews, corrective actions, and actions required to identify risks and opportunities necessary for the continual improvement of the ISMS shall be carried out by management and the teams assigned information security responsibilities by management.
- The necessary organisational structure, resources and infrastructure shall be established to enable information security incidents to be reported and appropriate actions to be taken as quickly as possible.
- All roles and responsibilities related to information security shall be defined; process controls shall be implemented in accordance with the principle of segregation of duties, and authorisations shall be granted by management.
- The resources required to carry out activities within the scope of the ISMS shall be provided by management.
- Information security risks shall be analysed, assessed and treated; appropriate measures shall be developed, and the necessary activities shall be planned and implemented to prevent potential risks.
- Constructive cooperation shall be maintained with public authorities, institutions, organisations and relevant individuals on matters relating to the ISMS.
- Appropriate sanctions shall be applied in the event of security violations.
- Information security objectives consistent with this policy and the purpose of the organisation shall be established. Compliance shall be measured at regular intervals, and opportunities for improvement shall be evaluated.
- Training and awareness programmes shall be developed and implemented to ensure that all employees and relevant stakeholders understand their roles and responsibilities within the scope of the ISMS.