Information Security Policy
Corporate

Information Security Policy

Document No
POL01
Publication Date
01.04.2018
Revision No
00
Revision Date

As CNC, within the scope of our Information Security Management System, we commit to the following principles:

Highlights

  • To ensure the confidentiality and integrity of the information of CNC, its customers and employees,
  • To provide the infrastructure required to guarantee the availability and continuity of CNC business processes,
  • To identify and provide the resources necessary for the implementation, maintenance and continual improvement of the information security management system,
  • To carry out regular risk assessments for CNC business processes and ensure the implementation of risk treatment plans,
  • To ensure that information is protected in line with its value,
  • To assign access rights according to the “need to know” principle in order to control access to information and to prevent unauthorized access,
  • To protect information assets against malware, malicious code and internal or external cyber attacks on CNC,
  • To develop an incident response process for information security events and to ensure timely response,
  • To provide information security awareness training to all employees and, where relevant, all contractors, and to raise awareness,
  • To meet applicable requirements arising from all relevant legal regulations and contracts,
  • To ensure that all relevant parties comply with CNC Information Security policies,
  • To continually improve the Information Security Management System.

Approved by

Neşe YILDIRIM
Company Director
Enis ÜNER
Customer Relations Director
Özcan EREN
Services Coordinator
Cem YILDIRIM
Financial & Administrative Affairs Director