Secure by habit.
The principles Codlean uses to protect information, sustain services and improve its information security management system.
Purpose and scope
Codlean Teknoloji Anonim Şirketi provides software development, computer programming, MES, web development, R&D, discovery, consultancy, design, implementation, training and service activities. This policy applies to the information, systems, people, suppliers and facilities supporting those activities.
Our objective is to protect business, customer, employee and partner information throughout its lifecycle and to keep security requirements aligned with our business goals and contractual obligations.
Security principles
Our information security decisions are guided by three connected principles.
Confidentiality
Need-to-know accessInformation is available only to authorized people, systems and organizations for an approved purpose.
Integrity
Accurate and completeInformation and processing methods are protected against unauthorized or accidental change.
Availability
Ready when requiredAuthorized users can access information and services within the continuity levels the business requires.
Governance and risk
Management provides suitable people, competence, technology, infrastructure and financial resources for the information security management system. Responsibilities are assigned, objectives are measured and material risks are reported through the appropriate governance channels.
We identify information assets, assess threats, vulnerabilities, likelihood and impact, and select controls proportionate to the risk. Risk treatment is reviewed when services, suppliers, technology or legal requirements materially change.
Core controls
Our control environment is selected according to risk and includes organizational, technical and physical measures.
- 01Identity, access and privilege management based on business need.
- 02Secure development, change control, vulnerability management and protection against malicious software.
- 03Logging, monitoring, backup, recovery testing and secure disposal of information.
- 04Physical and environmental safeguards for workplaces and supporting infrastructure.
- 05Supplier security requirements and review of services that process or host information.
- 06Incident reporting, assessment, containment, recovery and lessons learned.
People and partners
Employees are expected to make information security part of their daily work. Role-appropriate awareness and training are provided, and confidentiality and acceptable-use responsibilities continue for as long as required.
Relevant contractors, suppliers and other third parties are required to follow security obligations appropriate to the information and services in their scope.
Continuity and improvement
Business continuity, emergency response, backup and recovery arrangements are maintained for critical activities. Security events and incidents are reported promptly so their impact can be controlled and recurrence can be reduced.
We monitor applicable requirements, audit the effectiveness of controls and improve the management system through objectives, corrective actions and management review.
Review and contact
This policy is reviewed at least annually and after significant organizational, technological, contractual or regulatory change. Management and relevant process owners participate in the review.
Security concerns should be reported without delay to Codlean Teknoloji Anonim Şirketi.