Loading...

Information Security Management System Policy

Türk Loydu Top Management is committed to;

  • Establishing ISMS objectives and policies integrated with the company's strategic direction and corporate objectives,

  • Effectively operating and continually improving the ISMS to ensure the confidentiality, integrity, and availability of information assets,

  • Complying with legal requirements, applicable ISMS requirements, and the needs and expectations of relevant parties,

  • Conducting the ISMS based on systematic identification, analysis, evaluation, and management of risks and opportunities,

  • Identifying and managing risks, including climate and environmental risks, and prioritizing improvement actions,

  • Communicating the importance of effective information security management and compliance with ISMS requirements throughout Türk Loydu, and fostering awareness of these requirements,

  • Supporting awareness by treating environmental incidents, hazards, and feedback from employees and customers as valuable learning and improvement opportunities,

  • Ensuring the achievement of the targeted outputs of the ISMS,

  • Guiding and supporting employees to contribute to the effectiveness of the ISMS,

  • Ensuring the planning, allocation, and continuity of resources required for an effective ISMS,

  • Supporting the system by investing in the research and development of new technologies and practices that contribute to climate targets and the energy transition,

  • Ensuring continuous improvement, engaging Top Management in improvement activities, and regularly reviewing ISMS performance,

  • Supporting other management roles to enable them to demonstrate leadership within their respective areas of responsibility,

  • Complying with Türk Loydu Ethical Principles and observing ethical conduct in all activities related to information security,

  • Enhancing reliability by fulfilling information security requirements in services provided to customers, and delivering consistent, sustainable services aligned with customer expectations,

  • Encouraging employee participation in decision-making processes related to information security, and seeking feedback from employees and relevant stakeholders, when necessary,

  • Developing and implementing plans for response and recovery regarding information security breaches, cyber-attacks, system outages, or any emergencies that may affect business continuity.

Top