Information Security Policy
The primary objective of the ISO 27001 Information Security Management System (ISMS) is to demonstrate that information security management is effectively implemented across all services provided by BYS GRUP BİLİŞİM SİSTEMLERİ DANIŞMANLIK TİCARET VE SANAYİ ANONİM ŞİRKETİ within the scope of our business activities. This includes the protection of people, infrastructure, software, hardware, customer information, organizational information, third-party information, and financial resources; ensuring effective risk management; measuring the performance of information security management processes; and regulating relationships with third parties regarding information security.
In line with this, the purpose of our Information Security Management System (ISMS) Policy is to:
- Protect the information assets of BYS GRUP BİLİŞİM SİSTEMLERİ DANIŞMANLIK TİCARET VE SANAYİ ANONİM ŞİRKETİ against all internal and external threats, whether intentional or accidental; ensure that information is accessible in accordance with business process requirements; and comply with all applicable legal and regulatory obligations.
- Ensure the continuity of the three fundamental principles of the Information Security Management System throughout all business activities.
Confidentiality: Preventing unauthorized access to sensitive and valuable information.
Integrity: Ensuring and maintaining the accuracy, completeness, and consistency of information.
Availability: Ensuring that authorized users have access to information whenever required.
- Protect all information assets, not only electronic data, but also information stored in written, printed, verbal, or any other form.
- Promote information security awareness by providing Information Security Management System training to all personnel.
- Report all actual or suspected information security vulnerabilities to the ISMS Team and ensure that they are investigated by the ISMS Coordinator.
- Develop, maintain, and regularly test business continuity plans.
- Conduct periodic information security assessments to identify existing risks, review action plans based on assessment results, and monitor their implementation.
- Prevent any disputes or conflicts of interest that may arise from contractual obligations.
- Ensure that business requirements related to information accessibility and information systems are effectively met.


