INFORMATION SECURITY MANAGEMENT SYSTEM POLICY

INFORMATION SECURITY MANAGEMENT SYSTEM POLICY

Our Company recognizes ensuring the highest level of security for the payment services and financial technology solutions it provides as one of its core objectives.

Information security is critical to protecting the information of our customers, employees, business partners, and other stakeholders, ensuring the continuity of our services, and fulfilling our legal and regulatory obligations.

Accordingly, we adopt the principles of confidentiality, integrity, and availability in safeguarding our information assets and business processes. We manage our information security activities in accordance with applicable national and international standards and regulatory requirements.

Our Commitments

As part of our information security management framework, we:

  • Protect the confidentiality of customer, employee, and business partner information by implementing controls designed to prevent unauthorized access, use, disclosure, and sharing.
  • Establish and maintain processes and technologies that preserve the accuracy, integrity, and reliability of information.
  • Support uninterrupted access to critical information and systems to ensure service continuity.
  • Regularly assess information security risks and implement appropriate safeguards based on a risk-based approach.
  • Comply with applicable legal obligations and regulations relating to the protection of personal data.
  • Maintain processes for the identification, reporting, investigation, and prevention of recurring information security incidents.
  • Conduct regular training and awareness activities to enhance information security awareness among our employees.
  • Periodically review and continuously improve our Information Security Management System.
    Protection of Information and Systems
    To ensure the protection of our information assets, we:
  • Maintain an inventory of information assets, classify them appropriately, and assign ownership responsibilities.
  • Manage access to information based on business needs and the principle of least privilege.
  • Regularly review user access rights and implement appropriate access control measures.
  • Utilize encryption, masking, and similar security mechanisms to protect sensitive data during storage and transmission.
  • Ensure the secure management of cryptographic keys.
  • Adopt a layered security approach to safeguard networks, systems, and applications.
  • Implement preventive and detective security controls against external cyber threats.
  • Maintain logging and audit mechanisms to ensure the traceability of activities performed within information systems.

Secure Software Development and Operations

We consider information security requirements as an integral part of the lifecycle of our products and services, including design, development, testing, deployment, and operational processes. By adopting secure software development principles, we implement security controls from the design stage and establish authorization and approval mechanisms in accordance with the segregation of duties principle.

We maintain physical and logical separation between development, testing, and production environments to reduce the risk of unauthorized access and changes. We conduct regular assessments, monitoring, and improvement activities to identify and remediate security vulnerabilities within our systems. Furthermore, we implement appropriate security testing, security controls, and change management practices to support the security of our applications, infrastructure, and operational processes, thereby ensuring the reliability and continuity of our services.

Third-Party and Supplier Security

We assess information security risks associated with our suppliers, business partners, and service providers and incorporate appropriate security requirements into our contractual arrangements and operational processes. We aim to effectively manage risks arising from third-party relationships.

Business Continuity and Operational Resilience

To ensure the continuity of critical services, we establish, maintain, and regularly test business continuity and disaster recovery plans. We strive to continue delivering reliable services to our customers in the event of disruptions or adverse circumstances.

Compliance and Continuous Improvement

We conduct our information security activities in accordance with applicable national and international standards, primarily including Law No. 6493, relevant regulations issued by the Central Bank of the Republic of Türkiye (CBRT), the Personal Data Protection Law No. 6698 (KVKK), and other applicable legal obligations.

We regularly monitor, audit, and continuously improve our Information Security Management System to adapt to the evolving threat landscape and changing business requirements.

DESCRIPTION ITEM NUMBER DATE UPDATED BY
The document has been reviewed. 27.12.2022 Haluk Serkan Akman
PDF dosyası simgesiInformation Security Policy
Download

Information Security Management System Policy

whatsapp-icon