
Corporate
Information Security Policy
- Document No
- POL01
- Publication Date
- 01.04.2018
- Revision No
- 00
- Revision Date
- –
As CNC, within the scope of our Information Security Management System, we commit to the following principles:
Highlights
- To ensure the confidentiality and integrity of the information of CNC, its customers and employees,
- To provide the infrastructure required to guarantee the availability and continuity of CNC business processes,
- To identify and provide the resources necessary for the implementation, maintenance and continual improvement of the information security management system,
- To carry out regular risk assessments for CNC business processes and ensure the implementation of risk treatment plans,
- To ensure that information is protected in line with its value,
- To assign access rights according to the “need to know” principle in order to control access to information and to prevent unauthorized access,
- To protect information assets against malware, malicious code and internal or external cyber attacks on CNC,
- To develop an incident response process for information security events and to ensure timely response,
- To provide information security awareness training to all employees and, where relevant, all contractors, and to raise awareness,
- To meet applicable requirements arising from all relevant legal regulations and contracts,
- To ensure that all relevant parties comply with CNC Information Security policies,
- To continually improve the Information Security Management System.
Approved by
Neşe YILDIRIM
Company Director
Enis ÜNER
Customer Relations Director
Özcan EREN
Services Coordinator
Cem YILDIRIM
Financial & Administrative Affairs Director