ISO 27001 : 2022 Information Security Policy
- Ensure the highest level of satisfaction for customers, employees, and relevant stakeholders while preserving their rights and confidentiality.
- Aim to implement and continuously improve information security across all personnel.
- Aim to reduce costs and increase profitability by closely monitoring and implementing technological advancements.
- Emphasize teamwork to enhance the competence of all employees within the framework of management systems.
- Continuously enhance our modern infrastructure by utilizing the latest technologies.
- Establish management system objectives for our units and periodically evaluate these objectives, taking necessary measures as required.
- Comply with all applicable standards, regulations, management systems, and relevant legal requirements.
- Manage information assets, determine their security values, needs, and risks, and develop and implement controls for security risks.
- Define a framework for identifying the presence of threats, their frequencies, and evaluating their impacts on assets.
- Define a framework for assessing the impacts of threats on confidentiality, integrity, and accessibility of assets.
- Establish principles for managing risks.
- Continuously monitor risks by reviewing technological expectations within the scope of services provided.
- Fulfill obligations arising from national or international regulations, legal and regulatory requirements, agreements, and corporate responsibilities towards internal and external stakeholders regarding information security.
- Reduce the impact of information security threats on service continuity and contribute to continuity.
- Have the competency to rapidly respond to potential information security incidents and minimize their impacts.
- Maintain and improve the level of information security over time with a cost-effective control infrastructure.
- Enhance the company’s reputation and protect it from negative effects based on information security.
- Commit to continuously improving the Information Security Policy.
- Continuously improve the practices of quality management systems.