Information Security Management System Policy
Türk Loydu Top Management is committed to;
Establishing ISMS objectives and policies integrated with the company's strategic direction and corporate objectives,
Effectively operating and continually improving the ISMS to ensure the confidentiality, integrity, and availability of information assets,
Complying with legal requirements, applicable ISMS requirements, and the needs and expectations of relevant parties,
Conducting the ISMS based on systematic identification, analysis, evaluation, and management of risks and opportunities,
Identifying and managing risks, including climate and environmental risks, and prioritizing improvement actions,
Communicating the importance of effective information security management and compliance with ISMS requirements throughout Türk Loydu, and fostering awareness of these requirements,
Supporting awareness by treating environmental incidents, hazards, and feedback from employees and customers as valuable learning and improvement opportunities,
Ensuring the achievement of the targeted outputs of the ISMS,
Guiding and supporting employees to contribute to the effectiveness of the ISMS,
Ensuring the planning, allocation, and continuity of resources required for an effective ISMS,
Supporting the system by investing in the research and development of new technologies and practices that contribute to climate targets and the energy transition,
Ensuring continuous improvement, engaging Top Management in improvement activities, and regularly reviewing ISMS performance,
Supporting other management roles to enable them to demonstrate leadership within their respective areas of responsibility,
Complying with Türk Loydu Ethical Principles and observing ethical conduct in all activities related to information security,
Enhancing reliability by fulfilling information security requirements in services provided to customers, and delivering consistent, sustainable services aligned with customer expectations,
Encouraging employee participation in decision-making processes related to information security, and seeking feedback from employees and relevant stakeholders, when necessary,
Developing and implementing plans for response and recovery regarding information security breaches, cyber-attacks, system outages, or any emergencies that may affect business continuity.