EN
Choose a language:
TR AZ RU UZ KS

The Information Security Management System Policy

The Information Security Management System Policy includes the ISO 27001:2013 certificate and the prevention of unauthorized access to important information with information processing units.

ISO 27001:2013 certificate All hardware and software, all server system elements and end-user computers and all physical support services, cyber security and penetration testing services used within the scope of Intergen Genetics and Rare Diseases Diagnosis Research and Application Center Information Processing Unit. and electronic information assets.

• To comply with all legal and business requirements and contractual information security obligations regarding information security,

• To create and maintain an effective and sufficient information security risk management approach to eliminate or reduce the risks defined on information assets to an acceptable level,

• To ensure the continuity of the three basic elements of the Information Security Management System in all activities carried out;

Confidentiality: preventing unauthorized access to important information,

Integrity: Demonstrating that the accuracy and integrity of the information is provided,

Accessibility: Demonstrating the accessibility of information when necessary by those with authority,

 

• Developing and maintaining appropriate business continuity plans and systems to ensure that business activities continue with minimum interruption,

• Not only data kept in electronic media; To deal with the security of all data in written, printed, oral and similar media,

• To raise awareness by giving Information Security Management training to all personnel,

• To report all actual or suspicious vulnerabilities in Information Security to the ISMS team and to ensure that they are investigated by the ISMS team,

• To ensure the continuous improvement of ISMS with regular audits and reviews by determining information security control targets,

• To manage information security violations and to ensure that appropriate measures are taken and necessary sanctions are enforced to prevent their recurrence.