Trust is operational

Secure by habit.

The principles Codlean uses to protect information, sustain services and improve its information security management system.

Policy 02Last updated: 11 July 20266 min read
Read the policy
01

Purpose and scope

Codlean Teknoloji Anonim Şirketi provides software development, computer programming, MES, web development, R&D, discovery, consultancy, design, implementation, training and service activities. This policy applies to the information, systems, people, suppliers and facilities supporting those activities.

Our objective is to protect business, customer, employee and partner information throughout its lifecycle and to keep security requirements aligned with our business goals and contractual obligations.

02

Security principles

Our information security decisions are guided by three connected principles.

01

Confidentiality

Need-to-know access

Information is available only to authorized people, systems and organizations for an approved purpose.

02

Integrity

Accurate and complete

Information and processing methods are protected against unauthorized or accidental change.

03

Availability

Ready when required

Authorized users can access information and services within the continuity levels the business requires.

03

Governance and risk

Management provides suitable people, competence, technology, infrastructure and financial resources for the information security management system. Responsibilities are assigned, objectives are measured and material risks are reported through the appropriate governance channels.

We identify information assets, assess threats, vulnerabilities, likelihood and impact, and select controls proportionate to the risk. Risk treatment is reviewed when services, suppliers, technology or legal requirements materially change.

04

Core controls

Our control environment is selected according to risk and includes organizational, technical and physical measures.

  • 01Identity, access and privilege management based on business need.
  • 02Secure development, change control, vulnerability management and protection against malicious software.
  • 03Logging, monitoring, backup, recovery testing and secure disposal of information.
  • 04Physical and environmental safeguards for workplaces and supporting infrastructure.
  • 05Supplier security requirements and review of services that process or host information.
  • 06Incident reporting, assessment, containment, recovery and lessons learned.
05

People and partners

Employees are expected to make information security part of their daily work. Role-appropriate awareness and training are provided, and confidentiality and acceptable-use responsibilities continue for as long as required.

Relevant contractors, suppliers and other third parties are required to follow security obligations appropriate to the information and services in their scope.

06

Continuity and improvement

Business continuity, emergency response, backup and recovery arrangements are maintained for critical activities. Security events and incidents are reported promptly so their impact can be controlled and recurrence can be reduced.

We monitor applicable requirements, audit the effectiveness of controls and improve the management system through objectives, corrective actions and management review.

07

Review and contact

This policy is reviewed at least annually and after significant organizational, technological, contractual or regulatory change. Management and relevant process owners participate in the review.

Security concerns should be reported without delay to Codlean Teknoloji Anonim Şirketi.

info@codlean.com