E2P BİLİŞİM TEKNOLOJİ TİC. SAN. A.Ş. ISMS and QMS POLICY
The main theme of the TS EN ISO 27001:2022 and TS EN ISO 9001:2015 Information Security and Quality Management System is; to demonstrate that Information Security and Quality management is ensured at E2P Bilişim Teknoloji TİC. SAN. A.Ş. across people, infrastructure, software, hardware, user information, organizational information, information belonging to third parties and financial resources, to secure risk management, to measure the process performance of Information Security and Quality management, and to ensure the regulation of relations with third parties on matters related to information security.
The main theme of the Information Security and Quality Management System;
It covers all software used within the scope of E2P Bilişim Teknoloji Tic. San. A.Ş., all hardware and software on the basis of corporate business process management, all server system components and end-user computers together with all physical and electronic information assets included in their support and maintenance services, software development, integration, software maintenance processes and personal data processing activities.
Accordingly, the purpose of our ISMS and QMS Policy is;
- To protect the information assets of E2P Bilişim Teknolojileri against all kinds of threats that may arise from inside or outside, knowingly or unknowingly,
- To ensure accessibility to information as required by business processes,
- To meet legal regulatory requirements,
- To carry out work aimed at continual improvement,
-
To ensure the continuity of the three fundamental elements of the Information Security and Quality Management System in all activities carried out:
Confidentiality: Preventing unauthorized access to information of importanceIntegrity: Demonstrating that the accuracy and integrity of information is ensuredAvailability/Accessibility: Demonstrating that those who are authorized can access information when required
- To be concerned with the security not only of data kept in electronic media, but of all data held in written, printed, verbal and similar media,
- To ensure awareness by providing Information Security and Quality Management training to all personnel,
- To report to the ISMS Team all vulnerabilities in Information Security that actually exist or are suspected, and to ensure that they are investigated by the ISMS Team,
- To prepare, maintain and test business continuity plans,
- To identify existing risks by carrying out periodic assessments on Information Security,
- To review and follow up action plans as a result of the assessments,
- To prevent all kinds of disputes and conflicts of interest that may arise from contracts,
- To meet business requirements for accessibility to information and for information systems,
- To closely follow current developments, and to continuously improve service quality and diversity,
- To adhere to the principles of impartiality, independence, confidentiality, equality and reliability, and to fulfil the requirements of legal obligations and of all standards with which we are obliged to comply,
- In the light of the values we hold, together with our management and all our employees, to ensure and maintain the highest level of customer satisfaction in our services,
- To comply with all obligations under KVKK (the Turkish Personal Data Protection Law), GDPR (where applicable), Intellectual property rights, and national and international legislation,
- We undertake to assess information security risks that may arise from climate change AND to aim for the efficient use of natural resources.
General Manager
21.07.2026
| PREPARED BY | CHECKED BY | APPROVED BY |
|---|---|---|
| Quality Specialist | Administrative Affairs Manager | General Manager |