DDO Information and Communication Security Guide Compliance Consulting
Assess your institution against the DDO Information and Communication Security Guide, close the gaps with gap analysis, risk assessment, technical security controls and evidence management, and prepare for audit.
What Is the DDO Information and Communication Security Guide?
The DDO Information and Communication Security Guide is a comprehensive information security framework created to enable public institutions and organisations to manage information and communication security risks systematically, to protect critical information assets, and to determine the administrative, technical and organisational security measures that need to be applied.
The guide sets out the control and implementation principles that help institutions improve their information security posture, within the Information and Communication Security approach published by the Digital Transformation Office (DDO) of the Presidency of the Republic of Türkiye.
DDO compliance work should not be treated merely as a checklist-filling or document-preparation project. Effective compliance with the DDO Information and Communication Security Guide requires the following components to be addressed together:
Asset Management + Risk Analysis + Security Controls + Technical Analysis + Process Management + Audit + Monitoring + Continuous Improvement
SecureSys provides support under its DDO Information and Communication Security Guide Compliance Consulting service across the assessment of the institution's current security level, the creation of asset groups, the analysis of guide requirements, gap analysis, risk assessment, technical controls, the development of policies and procedures, evidence management and audit preparation.
The objective is not simply to satisfy the clauses of the guide, but to establish a measurable, traceable and sustainable information security management model within the institution's real IT and cyber security infrastructure.
Why Does the DDO Information and Communication Security Guide Matter?
As public institutions have digitalised, a significant proportion of their business processes has moved onto information systems.
Citizen records, personnel data, corporate documents, financial information, critical infrastructure data and operational systems are processed across a large number of digital platforms.
At the same time, the principal cyber security risks facing institutions include:
- Ransomware attacks
- Credential compromise
- Unauthorised access
- Data leakage
- Malware
- Insider threats
- Supply chain attacks
- Cloud security risks
- Exploitation of vulnerabilities
- Compromise of privileged accounts
- Insecure security configurations
The DDO Information and Communication Security Guide offers an approach that aims to reduce these risks not through the purchase of security products alone, but through the joint management of governance, process, people and technology.
What Is DDO Compliance Consulting?
DDO Compliance Consulting is a systematic compliance exercise in which the institution's existing information and communication security structure is analysed against the requirements of the guide and the shortcomings identified are remediated.
The consulting work does not assess merely whether the documents exist.
If, for example, the guide contains a requirement relating to access control, it is not enough to check whether the institution has an Access Control Policy.
Controls such as the following also need to be assessed in the real technical environment:
Are Active Directory users correctly authorised? Are privileged accounts under control? Is MFA in use? Are dormant user accounts disabled? Are Administrator privileges restricted? Is access being logged? Are permissions reviewed periodically?
SecureSys's DDO compliance approach aims for the documentation and the real technical implementation to corroborate one another.
How Does the DDO Compliance Process Work?
The DDO Information and Communication Security Guide compliance process can be tailored to the institution's size, organisational structure, information systems, locations and current security maturity level.
The general working model consists of the following stages.
1. Scope Definition
The organisational and technical scope of the compliance exercise is defined.
The scope is established by assessing the institution's:
- Organisational units
- Locations
- Information systems
- Applications
- Databases
- Network infrastructure
- Cloud systems
- Critical services
- Suppliers
- Data sources
2. Definition of Asset Groups
The institution's information assets and the associated asset groups are identified.
3. Current-State Analysis
Existing policies, processes, technologies and security practices are examined.
4. DDO Gap Analysis
The differences between the guide's requirements and the institution's current state are identified.
5. Risk Analysis
Threats and vulnerabilities affecting critical assets are assessed.
6. Control Mapping
The controls in the guide are mapped to the institution's systems and processes.
7. Technical Security Analysis
The extent to which the guide's requirements are implemented in the technical environment is examined.
8. Policies and Procedures
Missing information security documents, or those requiring an update, are produced.
9. Evidence Management
A management structure is established for the evidence that demonstrates the controls are being applied.
10. Remediation of Non-Conformities
The gaps and risks identified are prioritised and turned into an action plan.
11. Audit Preparation
The institution is supported in preparing for the assessments and audits to be carried out under the guide.
12. Continuous Monitoring
Mechanisms are established so that the DDO compliance level is tracked continuously, not only during the project period.
What Is a DDO Gap Analysis?
A DDO Gap Analysis is the systematic identification of the differences between the institution's existing information and communication security structure and the requirements of the Information and Communication Security Guide.
For each control, the following relationship can be established:
DDO Requirement → Current State → Compliance Level → Gap → Risk → Action → Owner → Deadline → Evidence
Controls can be classified into states such as:
Compliant Partially Compliant Non-Compliant Not Applicable / Out of Scope
Producing a percentage compliance score alone, however, is not sufficient.
The real objective is to determine which of the institution's gaps create high cyber security risk and to prioritise actions according to risk level.
DDO Asset Inventory and Asset Groups
One of the fundamental principles of information security is this:
The greatest risk is not the asset you cannot protect, but the asset you do not know about.
For this reason, the systematic identification of the institution's information assets is critical in DDO compliance work.
The asset inventory can cover:
- Servers
- User workstations
- Network devices
- Security appliances
- Applications
- Databases
- File systems
- Mobile devices
- Cloud services
- SaaS platforms
- Critical data
- Backup systems
- Virtualisation infrastructure
- OT/IoT systems
Establishing the following relationship for each asset allows subsequent risk assessments to be carried out on a sounder basis:
Asset Owner + Criticality + Data Class + Location + System Dependency + Security Controls
DDO Risk Analysis
A DDO Risk Analysis assesses the threats, vulnerabilities and potential impacts affecting the institution's information assets.
Risk analysis can be carried out using the following approach:
Asset → Threat → Vulnerability → Existing Control → Likelihood → Impact → Risk Level → Additional Control → Residual Risk
The risk created by an internet-facing application running out-of-date software components, for example, is not the same as the risk created by an isolated internal test system.
Risk assessments can take particular account of the following dimensions of information:
Confidentiality Integrity Availability
DDO Technical Compliance Work
One of the most important areas in DDO Information and Communication Security Guide work is technical security controls.
In the SecureSys consulting approach, whether the guide's requirements are actually applied in the institution's real systems can be assessed technically, within the agreed scope.
Active Directory is the central identity infrastructure for many institutions.
The work can assess:
- Domain Admin accounts
- Enterprise Admin accounts
- User and group permissions
- GPO structures
- Password policies
- MFA adoption
- Service accounts
- Dormant accounts
- Privileged access
- Segregation of duties
- Account lockout policies
- Logging
Network Security and Segmentation
An institutional network built as a single flat structure can make lateral movement easier for attackers.
DDO technical compliance work can assess:
- Network segmentation
- VLAN structures
- Firewall policies
- DMZ
- Server networks
- User networks
- Guest networks
- Management networks
- Critical system segments
- ACL rules
- Network access
The objective is not merely to have a firewall in place, but to ensure that the network architecture is designed to reduce the attack surface.
Firewall Security Controls
Firewall rule bases that grow without control over the years can create significant security risks.
Areas such as the following can be assessed under DDO compliance:
- Any-Any rules
- Unused rules
- Unnecessary services
- Internet-facing services
- Management access
- NAT rules
- VPN access
- Logging
- Rule ownership
- Periodic rule review
Privileged Access Management – PAM
The compromise of privileged accounts such as Administrator, root or Domain Admin can create high risk for an institution.
A Privileged Access Management – PAM approach allows the following to be implemented:
- Identification of privileged accounts
- Secure management of passwords
- Restriction of permissions
- Session monitoring
- Retention of activity records
- Temporary elevation of privilege
- Approval workflows for permissions
How privileged accounts are managed is one of the critical technical control areas in DDO compliance work.
MFA and Identity Security
A password on its own may no longer be a sufficient security mechanism against modern attacks.
The use of Multi-Factor Authentication – MFA should be considered in particular for:
- VPN
- Cloud services
- Administrator accounts
- Critical applications
- Remote access
Because identity-based attacks are increasing, identity security is one of the important components of DDO technical compliance work.
Log Management and SIEM
For security events to be detectable, the logs from critical systems need to be collected centrally and analysed.
DDO compliance work can assess:
- Which systems generate logs
- Which logs are forwarded to the central system
- Log retention periods
- Time synchronisation
- Log integrity
- Alert generation for critical events
- SIEM correlation rules
- Monitoring of security events
SIEM – Security Information and Event Management systems should be used not merely for log storage, but for the detection of security events.
SOC and DDO Compliance
Sending logs to a SIEM does not by itself amount to effective security monitoring.
SOC – Security Operations Centre processes matter for the assessment of critical alerts and the response to security incidents.
Within the SOC, the following chain needs to be established:
Log → Alert → Analysis → Incident → Response → Root Cause Analysis → Improvement
In DDO compliance processes, incident monitoring and response capabilities are among the important indicators of an institution's overall cyber security maturity.
EDR / XDR and Endpoint Security
User workstations and servers are among attackers' primary targets.
Alongside traditional antivirus solutions, EDR – Endpoint Detection and Response or XDR – Extended Detection and Response technologies can help detect advanced threats.
DDO technical analysis can assess:
- Endpoint coverage
- Agent health
- Policy enforcement
- Alert management
- Isolation capability
- Ransomware protection
- Central management
- Update status
Vulnerability Management
Scanning for security vulnerabilities only once a year is not an effective vulnerability management approach.
A Vulnerability Management process should be established:
Discovery → Scanning → Validation → Risk Rating → Assignment → Remediation → Retest
SLA periods can be defined for the closure of critical vulnerabilities.
A critical, internet-facing vulnerability, for example, should be addressed at a higher priority than a low-risk internal system vulnerability.
Patch Management
Failure to apply operating system and application updates on time can allow known vulnerabilities to be exploited by attackers.
Patch management should track:
- Out-of-date systems
- Critical patches
- Test processes
- Patch deployment
- Failed updates
- Exceptions
- EOL/EOS systems
EOL / EOS System Management
Operating systems, applications and devices for which vendor support has ended can create security risk.
Identifying End of Life / End of Support systems and building a controlled transition plan is one of the important technical areas that can be assessed in DDO compliance work.
Backup and Disaster Recovery
In ransomware attacks, a reliable backup infrastructure is one of an institution's most important lines of defence.
Saying "we take backups", however, is not sufficient on its own.
The following questions need to be answered:
Are backups genuinely being taken? Are restore tests carried out? Are backups isolated from the production environment? Is the backup administrator account protected? Is an offline or immutable backup available? Are backups encrypted?
Under DDO compliance, backup, business continuity and disaster recovery controls can be assessed together.
DLP and Data Security
Data Loss Prevention – DLP is one of the important security technologies for preventing critical data from leaving the organisation without authorisation.
The movement of critical data can be monitored across:
- USB
- Web
- Cloud
- File transfer
- Endpoints
Under DDO, the need for DLP should be assessed according to the institution's data classification and risk level.
Data Classification
Not all data requires the same level of security.
Corporate data can be classified, for example, as:
Public → Internal → Confidential → Highly Confidential / Critical
Based on the classification outcome, rules can be defined for:
- Access permissions
- Encryption
- DLP
- Sharing
- Retention
- Transfer
- Disposal
Database Security
A significant proportion of critical information is held in databases.
DDO technical compliance work can assess:
- Database administrator accounts
- User permissions
- Access to critical tables
- Encryption
- Logging
- Audit records
- Patch level
- Backup security
- Application accounts
Where required, critical database activity can be monitored using Database Activity Monitoring – DAM technologies.
Email Security
Email systems are among the most frequently used attack surfaces in phishing, malware and account takeover attacks.
DDO compliance can assess:
- SPF
- DKIM
- DMARC
- Anti-spam
- Anti-phishing
- MFA
- Mailbox audit
- External forwarding
- Malicious attachment controls
- URL security
Cloud Security
The growing use of cloud services across public and corporate organisations makes cloud security an important subject in DDO compliance work.
Areas such as the following can be assessed in cloud environments:
- IAM
- MFA
- Authorisation
- Storage security
- Public access
- Security Group rules
- Logging
- Encryption
- Backup
- API security
- Secret management
- Cloud posture
DDO and Penetration Testing
Penetration testing is an important technical validation method for measuring how resilient an institution's security controls are against real attack scenarios.
Depending on scope, the following can be carried out:
- External Network Penetration Testing
- Internal Network Penetration Testing
- Web Application Penetration Testing
- Mobile Application Penetration Testing
- API Penetration Testing
- Active Directory Penetration Testing
- Wireless Network Penetration Testing
- Social Engineering Testing
The aim here is not simply to find vulnerabilities, but to measure how effective the existing security controls are in real attack scenarios.
DDO and Cyber Hygiene
Cyber hygiene refers to an institution keeping its fundamental security practices in a consistently healthy state.
Basic cyber hygiene indicators include:
- Up-to-date systems
- Strong password policies
- MFA
- Active endpoint protection
- Regular vulnerability scanning
- Disabling of dormant accounts
- Backup verification
- Reduction of EOL systems
- Permission reviews
For DDO compliance to be sustainable, these controls need to be measured periodically.
DDO Supplier Risk Management
An institution's security level is not limited to its own infrastructure.
Software vendors, maintenance providers, cloud services, outsourced personnel and other suppliers may all have access to the institution's systems.
A Third Party Risk Management – TPRM approach is therefore one of the important components of DDO compliance.
The following model can be established for suppliers:
Criticality → Data Access → System Access → Security Controls → Contract → Risk Level → Periodic Assessment
DDO Incident Response Management
It may not always be possible to prevent a cyber attack entirely.
Institutions therefore need to be able to respond quickly and in a controlled manner when an incident occurs.
An incident response process can consist of the following stages:
Preparation → Detection → Analysis → Containment → Eradication → Recovery → Root Cause Analysis → Improvement
Testing incident response procedures through regular exercises increases the institution's readiness for real incidents.
DDO Business Continuity and Disaster Recovery
Availability is one of the fundamental elements of information security.
Critical systems becoming unusable as a result of a cyber attack, hardware failure, natural disaster or operational error can affect the institution's services.
Work such as the following can therefore be assessed within the DDO compliance approach:
- Identification of critical processes
- Carrying out a BIA
- Definition of RTO/RPO values
- Establishment of DR infrastructure
- Definition of the backup strategy
- Preparation of recovery procedures
- Execution of DR tests
DDO Policies and Procedures
The documents that may be created or updated, depending on the institution's scope, include:
- Information Security Policy
- Access Control Policy
- Password Policy
- Asset Management Procedure
- Risk Management Procedure
- Log Management Procedure
- Incident Response Procedure
- Backup Policy
- Business Continuity Policy
- Change Management Procedure
- Vulnerability Management Procedure
- Patch Management Procedure
- Data Classification Policy
- Supplier Security Procedure
- Remote Access Policy
- Mobile Device Policy
- Physical Security Policy
- Acceptable Use Policy
- Cryptography Policy
- Secure Software Development Policy
It is critical that the documents are consistent with how the institution actually operates.
DDO Evidence Management
Evidence management matters in DDO compliance because it is what allows an institution to demonstrate that a control is being applied.
Evidence can take the form of:
- System screenshots
- Configuration output
- Log records
- Reports
- Meeting minutes
- Approval records
- Training records
- Test results
- Policies or procedures
- Ticket records
For each control, the following relationship can be established:
Control → Owner → Evidence → Evidence Date → Validity → Next Review Date
This approach significantly reduces the burden of last-minute evidence collection during audit periods.
DDO Audit Preparation
DDO audit preparation involves reviewing the current control status and the available evidence.
The preparation work carried out by SecureSys can identify:
- Missing evidence
- Out-of-date policies
- Technical non-conformities
- Open actions
- Risk acceptance decisions
- Controls without an owner
- Untested processes
A mock audit carried out before the audit allows the institution to see its actual level of readiness.
DDO Compliance Score and Dashboard
Tracking hundreds of controls in a spreadsheet can, over time, become difficult to manage.
For this reason, it can be useful to track the DDO compliance level through a dashboard.
Management screens can track indicators such as:
Overall Compliance Rate Critical Open Controls High Risks Overdue Actions Technical Control Status Compliance by Business Unit Compliance by Asset Group Evidence Completion Rate Risk Trends
Senior management can then follow the institution's overall information security position through measurable indicators, rather than through hundreds of individual technical controls.
Continuous Compliance
Treating DDO compliance as an annual control exercise is not sufficient.
The IT infrastructure changes constantly.
New servers may be built, employees may leave, new applications may go live, firewall rules may change, or new vulnerabilities may emerge.
A continuous compliance approach can therefore be adopted.
The following, for example, can be tracked periodically:
MFA adoption rate Proportion of devices covered by EDR Number of critical vulnerabilities Patch level Systems not sending logs Backup failures Number of EOL systems Overdue risk actions
The Relationship Between DDO and ISO 27001
There are many shared information security areas between the DDO Information and Communication Security Guide and ISO/IEC 27001.
Both frameworks address:
- Risk management
- Asset management
- Access control
- Incident management
- Business continuity
- Supplier security
- Technical security
- Awareness
- Continuous improvement
The two are not, however, the same.
ISO 27001 is an international Information Security Management System standard, whereas the DDO Information and Communication Security Guide is a national information and communication security approach with its own scope and requirements.
For this reason:
Holding an ISO 27001 certificate does not automatically mean DDO compliance.
That said, in institutions with an ISO 27001 management system already in place, existing controls can be mapped to DDO requirements and a substantial amount of the work can be shared.
How Are DDO, ISO 27001 and KVKK Managed Together?
Implementing the same control repeatedly for different standards and regulations can be a source of inefficiency for institutions.
An MFA control, for example, can support different requirements simultaneously:
DDO → an information security control ISO 27001 → access and identity security KVKK → a technical measure for the protection of personal data
In the SecureSys approach, therefore, the requirements of:
DDO + ISO 27001 + KVKK + GRC
can be mapped under a common control library.
This model can be described as a unified compliance management approach.
DDO Compliance Maturity Analysis
Assessing institutions only as "compliant / non-compliant" does not always provide sufficient information.
Information security maturity can therefore be assessed at different levels.
Level 1 – Initial: Controls are person-dependent and applied reactively.
Level 2 – Developing: Basic security controls are in place, but standardisation is limited.
Level 3 – Defined: Policies and processes have been established and are applied across the institution.
Level 4 – Managed: Controls are measured through KPI/KRI indicators.
Level 5 – Optimised: Controls are monitored automatically and improved continuously.
The outcome of this assessment establishes the following relationship:
Current Level → Target Level → Gap → Action → Investment Requirement
DDO Compliance Consulting Deliverables
Depending on the scope of the SecureSys DDO consulting project, the following deliverables can be produced:
- DDO Current-State Analysis
- DDO Gap Analysis Report
- DDO Compliance Matrix
- Information Asset Inventory
- Asset Groups
- Risk Analysis
- Risk Register
- Risk Treatment Plan
- Technical Security Analysis Report
- Policy and Procedure Set
- Control-Evidence Matrix
- Supplier Risk Analysis
- Vulnerability Management Roadmap
- Cyber Security Maturity Analysis
- Corrective Action Plan
- DDO Compliance Dashboard Structure
- Audit Preparation Checklist
- Executive Summary Report
- Continuous Compliance Roadmap
Who Is DDO Compliance Consulting For?
Beyond the institutions that fall within the scope of the DDO Information and Communication Security Guide, the guide's approach can also serve as an important reference for organisations that provide services to the public sector and have high information security requirements.
DDO requirements can be particularly relevant for:
- Public institutions and organisations
- Ministries
- Municipalities
- Universities
- Public sector affiliates
- Critical infrastructure operators
- Companies providing technology services to the public sector
- Data centre service providers
- Defence industry organisations
- Technology firms working on public sector projects
The extent of an institution's direct obligation should be assessed separately against the current legislation and the provisions of the guide.
Frequently Asked Questions About the DDO Information and Communication Security Guide
What Is the DDO Information and Communication Security Guide?
It is a national information security guide that helps institutions manage the security risks affecting their information and communication systems and apply the necessary security measures systematically.
What Is DDO Compliance Consulting?
It is a consulting service covering the analysis of the institution's existing security structure against the guide's requirements, the identification of gaps, and the establishment of the necessary technical, administrative and organisational controls.
What Is a DDO Gap Analysis?
It is the identification of the gaps between the institution's existing security controls and the requirements of the DDO Information and Communication Security Guide.
How Is a DDO Risk Analysis Carried Out?
The institution's assets, threats, vulnerabilities, existing controls, and likelihood and impact values are assessed to determine the risk level, and the necessary improvement actions are defined.
Does an ISO 27001 Certificate Provide DDO Compliance?
No. Although there are many shared controls between ISO 27001 and DDO, the two frameworks are not the same. Organisations holding ISO 27001 need to assess the DDO requirements separately.
Are Technical Controls Assessed in DDO Compliance?
Yes. An effective compliance exercise assesses not only policies and procedures but also Active Directory, network security, firewalls, SIEM, logging, EDR/XDR, vulnerability management, backup, access control and other technical security areas.
How Long Does DDO Compliance Work Take?
The duration varies according to the institution's size, the number of locations, the number of assets, the current security level and the volume of gaps identified. A current-state and gap analysis is recommended first in order to produce a sound estimate.
Is Penetration Testing Required for DDO Compliance?
Penetration testing is one of the important technical security exercises for validating security controls against real attack scenarios. The test scope to be applied should be determined according to the institution's risks and the relevant requirements.
Why Does Evidence Matter in DDO Compliance?
It is not enough for a security control to have been defined; it must be possible to demonstrate that it is genuinely being applied. Evidence such as policies, logs, configurations, reports, tickets and test results therefore needs to be managed in an organised way.
Why SecureSys for DDO Compliance Consulting?
Compliance with the DDO Information and Communication Security Guide is not simply a matter of ticking control items in a spreadsheet.
Genuine compliance requires the following components to work together:
Policy + Process + People + Technology + Evidence + Continuous Monitoring
SecureSys approaches DDO compliance work by combining GRC and cyber security expertise.
Before a control is marked as "implemented", its real counterpart in the technical environment is verified where necessary.
Is MFA in the policy? → Is it genuinely active in the technical environment?
Is there a logging procedure? → Are critical systems genuinely sending logs to the SIEM?
Is there a backup policy? → Are restore tests being carried out?
Is there an access management procedure? → Are dormant and privileged accounts genuinely being reviewed?
This approach turns a DDO compliance project into more than audit preparation: it becomes a transformation project that raises the institution's real cyber security level.
DDO Compliance Consulting Proposal
Under its DDO Information and Communication Security Guide Compliance Consulting service, SecureSys can analyse your organisation's current state and build a roadmap tailored to you, covering DDO gap analysis, asset inventory, risk assessment, technical security controls, policies and procedures, the control-evidence matrix, audit preparation and continuous compliance processes.
Do More Than Comply With the Guide — Raise Your Security Level
Measure security instead of ticking controls. Don't just see the gaps, reduce the risks. Manage your DDO compliance process under one roof, with GRC, cyber security and technical expertise.
Request a proposal for DDO Information and Communication Security Guide gap analysis, technical compliance and audit preparation.
Want to learn more about this service?
Our expert team will reach out for a free consultation as soon as possible.