Information Security Policy
Through the implementation of this policy, Top Management aims and commits to fulfilling the following fundamental principles necessary to ensure the protection, continuity, and sustainability of the confidentiality, integrity, and availability of information and other relevant assets through the Information Security Management System (ISMS), which will be established as one of the requirements for maintaining and enhancing sustainable competitiveness while pursuing Teknorot Otomotiv Ürünleri Sanayi ve Ticaret Anonim Şirketi’s vision of being the first choice in Steering and Suspension Systems across all its commercial activities:
Ensuring the necessary participation and support to achieve compliance with the requirements and conditions of the Information Security Management System standards,
Ensuring compliance with the laws, regulations, and circulars of the Republic of Türkiye, customer contracts, and other legal and regulatory requirements applicable to the business,
Ensuring the confidentiality of personal, corporate, or third-party information produced and/or used under all circumstances,
Ensuring that information is accessible only to authorized persons in accordance with the “Need-to-Know” principle,
Preventing the intentional or unintentional unauthorized use, alteration, disclosure, or damage of all information assets and other relevant assets,
Providing the necessary support and contribution to activities aimed at assessing risks relating to information and other relevant assets and reducing identified risks to acceptable levels,
Providing the necessary support for planning awareness programs to be regularly delivered to employees and, where applicable, supplier employees in order to increase information security awareness and encourage contribution to the effective operation of the system,
Providing the necessary support for activities aimed at detecting, reporting, addressing, closing, and preventing the recurrence of all actual or suspected breaches related to information security incidents,
Providing the necessary support and contribution to ensure business continuity and maintain continuous access to information at planned levels,
Providing the necessary resources at all levels for the implementation, maintenance, and continual improvement of the Information Security Management System,
Ensuring compliance with Green IT policies in Information and Communication Technology processes and contributing to the reduction of carbon emissions,
Ensuring that the requirements of the ISO 27001 Information Security Management System are integrated into the company’s business processes and that information security requirements are taken into consideration at every stage.