Turkish Technology is a technology organization that has long been dedicated to fulfilling the technology needs of Turkish Airlines and its affiliates, and now leverages its experience to provide innovative, agile and value-driven products and services at an international scale, with a focus on the aviation and air cargo sectors in local and global markets.
Turkish Technology is committed to ensuring the confidentiality, integrity and accessibility of all information assets and personal data (e.g. electronic records, video and audio recordings, images, printed documents, oral information, customer and passenger data, etc.) that it owns or is obliged to protect in accordance with national and international laws, regulations, conventions, standards and ethical principles. Accordingly, Turkish Technology hereby declares the Information Security and Privacy Policy in order to provide protection against risks that may threaten the security of information and personal data, to prevent unauthorized access, disclosure, alteration, or intentional/unintentional deletion, as well as to destroy and anonymize such data in accordance with the law when necessary. With the Information Security and Privacy Policy, Turkish Technology undertakes to comply with all applicable laws and regulations it is obliged to comply with, in particular the ISO/IEC 27001 Information Security Management System standard.
This policy covers;
- All Turkish Technology employees, both fixed-term and permanent contract, and its subsidiaries,
- All parties, service providers, suppliers, consultants, etc., that have access to information assets and PII (Personally Identifiable Information) related to civil aviation operations, and that process, manage, or store these assets/information,
- The information assets and PII stored on Turkish Technology technical infrastructure, stored on company devices, or managed by third-party service providers and on cloud systems.
It is obligatory for the parties within the scope to comply with the rules and requirements specified in the documents, including the sanctions, created by Turkish Technology to manage its relations with its employees and stakeholders.
According to Turkish Technology Information Security and Privacy Policy,
- Principles of confidentiality, integrity and accessibility are the basic principle for information security and privacy in the processing, transmission and storage of information and personal data.
- Employees and stakeholders of Turkish Technology protect all information and personal data assets and access information allocated to them in accordance with the written rules and commitments, and act within the framework of Turkish Technology policies when they need to be shared.
- On-site or remote access is not provided for any facilities, resources and information that have not been directly granted. Access authorizations are checked, tested when necessary or periodically, and rearranged if necessary.
- Any and all information systems of Turkish Technology are monitored, recorded, and tested continuously in accordance with the applicable regulations.
- Appropriate cryptographic methods are used when transmitting and storing all information that is legally obligatory to be protected or that is defined as critical by Turkish Technology.
- Turkish Technology conducts information security management with a risk-based approach. It identifies and assesses information security risks related to its critical assets, and implements the necessary controls to reduce these risks to acceptable levels.
- The management of all access authorizations and any transactions to be performed on these information and personal data assets are carried out by considering the asset’s information class (General, Service Restricted, Private) and risk value.
- Turkish Technology implements processes necessary for the timely detection, reporting, and management of information security incidents and vulnerabilities.
- All Turkish Technology employees act with the principle of “knowing on a need-to-know basis” and make a written commitment to abide by the confidentiality rules and the policies and procedures issued by Turkish Technology.
- Turkish Technology ensures the security and privacy of information and access in its relations with third parties through written contracts and the commitments received from third parties.
- Turkish Technology is committed to controlling, monitoring, reviewing the efficiency of the Information Security Management System (ISMS) through internal and external audits and to continuously make the system compliant, within the scope of the continuous improvement framework.
- Turkish Technology defines and implements the principles, processes, and activities necessary to secure its information and communication technology systems and data. Measurable targets are set for the management of information security performance; and these targets are periodically monitored, evaluated, and updated when necessary.
- Turkish Technology organizes awareness-raising activities on personal data security and information security issues for all employees and, if deemed necessary, for employees of subsidiaries and third parties, thus ensuring that security awareness is integrated into the corporate culture.
- Within the scope of the Information Security Management System (ISMS), Turkish Technology supports practices that raise awareness and provide a preventive effect in combating climate change by considering the environmental and social impacts; increases the resilience of information security processes by analyzing the physical and environmental risks that climate change may pose; in this direction, it is committed to protecting information assets against environmental threats, regularly assessing risks and taking proactive measures within the framework of sustainability principles.
Information security violations are subject to the disciplinary process, and necessary measures and sanctions are taken in accordance with corporate policies.
