At Özdisan Elektronik, the core concept of the Information Security Management System is to demonstrate that information security management is maintained across people, infrastructure, software, hardware, customer and organizational information, third-party information, and financial resources. It aims to ensure risk management, measure the performance of information security management processes, and regulate relationships with third parties concerning information security.
In this regard, our objectives at Özdisan Elektronik are:
- To protect the company's information assets from all types of threats that may arise from internal or external sources, whether intentional or unintentional, and to ensure information accessibility as required by business processes, while meeting legal requirements.
- To ensure the continuity of the three fundamental elements of the Information Security Management System in all activities: confidentiality, integrity, and availability of information. This includes identifying, evaluating, and implementing necessary controls for all assets above acceptable levels of risk.
- To maintain and improve the information security level of all data, not just those stored electronically but also written, printed, verbal, and other forms of data, through established control infrastructure.
- To provide Information Security Management training to all staff to raise awareness.
- To report any real or suspected vulnerabilities in information security to the Information Security Management Team and ensure they are investigated by the team.
- To prepare, maintain, and conduct drills for business continuity plans.
- To periodically assess information security to identify current risks, review action plans, and monitor their implementation.
- To fulfill information security requirements arising from national, international, or sectoral regulations, legal and relevant legislative requirements, obligations arising from agreements, and corporate responsibilities towards internal and external stakeholders.
- To prevent any disputes and conflicts of interest arising from contracts.
- To meet the business requirements for information accessibility and information systems.