Skip to main content

Information Security Management System (ISMS) Policy

Document No: POL-02 · Document Date: 02.06.2025 · Revision: 00

Policy Statement

Our organization is committed to complying with legal requirements and to protecting the confidentiality, integrity, and availability of all physical and electronic information assets within the scope of its activities. ISMS requirements are carried out in line with ISMS objectives.

Our Policy within the Scope of ISO/IEC 27001 ISMS

  • To ensure that our information security management system is documented, certified, and continuously improved in a manner that fulfills the requirements of the ISO/IEC 27001:2022 standard;
  • To continuously improve the ISMS awareness of our personnel;
  • To fulfill our responsibilities for identifying, determining, assessing, and controlling the relevant risks in order to establish and maintain the ISMS, within the framework of strategic business plans, ISMS objectives, and risk and opportunity management;
  • To ensure compliance with all legal regulations and contracts related to the ISMS;
  • To ensure that risks to ISMS assets are monitored and managed;
  • To ensure the confidentiality of our stakeholders' information assets within the scope of the ISMS.

Special Categories of Personal Data

The Turkish Personal Data Protection Law No. 6698 dated 24 March 2016, published in the Official Gazette No. 29677 dated 7 April 2016, attaches particular importance to certain categories of personal data due to the risk of causing victimization or discrimination when processed unlawfully. These are data relating to race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and attire, membership of associations, foundations or trade unions, health, sexual life, criminal convictions and security measures, as well as biometric and genetic data. As an organization, we treat the protection of special categories of personal data, as defined by the Personal Data Protection Law and processed lawfully, with the utmost care. Within this scope, the technical and administrative measures taken by our organization to protect personal data are applied diligently to special categories of personal data, and the necessary audits are carried out.

Our Commitment

We are committed to continuous improvement in line with our ISMS objectives and to maintaining sustainable ISMS conditions in order to be an exemplary organization in terms of information security within our sector. General Manager Korsis Teknoloji A.Ş.