INFORMATION SECURITY MANAGEMENT SYSTEM POLICY
Since 1958, GÜRİŞ Construction and Engineering Co. Inc. is one of Türkiye’s leading construction companies and has operated in almost every sector of the construction industry; from Thermal Power Plants to Tunnels, Rail Transportation Systems, Dams, Pipelines, Treatment Facilities, Ports, Buildings, Natural Gas and Petrochemical Plants. The Information Security Management System Policy of GÜRİŞ Construction and Engineering Co. Inc. states that management fully supports the establishment, implementation and control stages of the ISMS, as well as the enforcement of necessary sanctions in case of security violations.
The company is committed to the following principles in order to ensure the confidentiality, integrity and availability of information under controlled conditions for all stakeholders who utilize the company's information assets within the framework of the Information Security Management System (ISMS) standard:
- Not to use the company's IT resources for activities contrary to laws and related regulations,
- To ensure compliance of conducted activities with legislation, contracts, standards, and business requirements,
- Determining the objectives and goals of the Information Security Management System and identifying internal and external factors as well as the expectations of relevant stakeholders that may influence the achievement of these objectives,
- Ensuring all stakeholders comply with the rules related to our Information Security Management System and supporting awareness-raising actions,
- Supporting the effectiveness of information security by ensuring the determination of the impact value of all information assets used in the IT infrastructure during activities.
- Identifying risks by assessing information security's existing and potential hazards and minimizing risk through appropriate risk treatments,
- Determining ISMS activities affecting business continuity, ensuring the implementation of actions to reduce disruption periods to an acceptable level through applied scenarios,
- Ensuring the continuous improvement of the Information Security Management System by committing to meeting the applicable requirements related to information security,
- The aim is to announce, make accessible, create awareness, and ensure the implementation of these policies.
The purpose of this policy is to communicate information security requirements, raise awareness, and support the effective implementation of the Information Security Management System throughout the organization.