INFORMATION SECURITY POLICY
The purpose of this policy is to set out the rules to be followed and top management's commitment to protecting the confidentiality, integrity and availability of Medianova's employees, systems, information and assets, and to ensure business continuity within this scope.
The aim is not to create restrictive rules but to establish a culture of openness, trust and integrity. Strong information security is achieved through the participation of all employees; every member of staff is responsible for knowing and applying the information security policies (ISO/IEC 27001:2022).
1. PURPOSE
The purpose of this policy is to set out the rules to be followed and top management's commitment to protecting the confidentiality, integrity and availability of Medianova's employees, systems, information and assets, and to ensure business continuity within this scope.
The aim is not to create restrictive rules but to establish a culture of openness, trust and integrity. Strong information security is achieved through the participation of all employees; every member of staff is responsible for knowing and applying the information security policies (ISO/IEC 27001:2022).
2. SCOPE
This policy covers all activities, information assets, employees, suppliers and visitors within the scope of the Information Security Management System (ISMS). Scope boundaries are defined in DD.02 Integrated Management System Scope.
3. CORE SECURITY OBJECTIVES
- Confidentiality: Ensuring that information is accessible only to those authorised to access it.
- Integrity: Safeguarding the accuracy and completeness of information and processing methods; preventing unauthorised modification.
- Availability: Ensuring that authorised users have access to information and associated assets when required.
4. POLICY PRINCIPLES
- The confidentiality, integrity and availability of information assets are protected under all circumstances.
- Information assets are inventoried, classified and protected with controls appropriate to their value.
- Information security risks are assessed and treated using a defined methodology (PR.05); the controls applied are recorded in the Statement of Applicability (DD.06).
- Legal, regulatory and contractual obligations, including the Personal Data Protection Law (KVKK), are complied with.
- Information security objectives are set, measured and regularly reviewed.
- Employees' information security awareness and competence are continuously developed.
- Information security events and incidents are managed through defined processes (PR.16).
- Business continuity and personal data protection are handled in an integrated manner with information security.
- The ISMS is continually improved through internal audits, management reviews and corrective actions.
5. IMPLEMENTATION POLICIES
This top-level policy is detailed by topic-specific implementation policies (POL-01.01 Information Security Implementation Policies): general information security, internet access, e-mail, anti-virus, passwords and authentication, physical security, server security, network management, remote access, third-party security, acceptable use, clear desk/clear screen, mobile devices, database security, change management, incident management, cryptographic controls, secure software development, access control, identification and authorisation, visitors, data masking, data leakage prevention, cloud services, configuration management, use of AI tools, remote working, and logging and monitoring.
6. RESPONSIBILITY
The Integrated Management Representative is responsible for reviewing and updating this policy and the implementation policies. All employees, suppliers and visitors are responsible for complying with them. Top management is responsible for providing the necessary resources.
7. ENFORCEMENT
Personnel who fail to comply with the policies are subject to the Disciplinary Procedure (PR.17) and applicable legislation. For customers, suppliers and visitors, the relevant legal provisions apply.
8. REVIEW
This policy is reviewed at least annually and upon significant changes, and is evaluated at the management review.
9. COMMUNICATION AND ACCESS
This policy is documented, communicated to all employees and made available to interested parties (suppliers, customers, visitors) as appropriate.
FOUNDER & CEO