# ISO 27001 ISMS Policy

**URL:** https://securesys.com.tr/en/iso-27001-isms-policy

### Information Security Policy

Our organization is committed to protecting the confidentiality, integrity, and all physical and electronic information assets. **Information and information security requirements** will be aligned with our corporate objectives.

The management of our organization will employ open-minded, well-trained, and competent personnel; provide the funding required to compete with industry rivals; and maintain sufficient hardware and infrastructure. The necessary funding will be provided together with this infrastructure and personnel.

Business continuity and emergency response plans, data backup procedures, protection against viruses and hackers, access control systems, and information security incident reporting will form the cornerstones of our core activities.

Vulnerabilities and threats identified through risk assessments will be eliminated, and secure access to customer and personnel information will be ensured. Additionally, risk assessment outcomes will guide the definition of our objectives and the provision of the resources and conditions required to achieve them.

To implement this policy, we expect our employees in particular to make the Information Security Management System requirements part of their daily work. All personnel and specified third parties will receive appropriate training on the Information Security Management System.

Applicable information security requirements and the opportunities and obligations they bring will be fulfilled, and these requirements will be continuously improved. In addition, our department personnel and all relevant parties will be supported in adapting to this system.

Our Information Security Policy is reviewed and kept current at least once a year, or whenever significant changes occur in our company, with the participation of management and unit owners to ensure its suitability, accuracy, and effectiveness.
