TR
POLICY

Our Policies

shape shape shape

Information Security and Environmental Policy


Purpose

This policy aims to manage risks related to information security, protect information assets, promote an environmentally conscious approach, and ensure compliance with the ISO 27001 Information Security Management System (ISMS) requirements. Erfa commits to using technological innovations and sustainable solutions to maintain business continuity and minimize environmental impact in all information security activities.

Scope

This policy covers all parties with access to information within Erfa, including all employees, business partners, suppliers, and service providers.

Principles

1. Information Security Management

  • Necessary measures are taken to protect the confidentiality, integrity, and availability of all information assets.
  • Information security risks are regularly assessed, and preventive and corrective actions are implemented.
  • Information security incidents are managed quickly and effectively.

2. Environmentally Conscious Technology Use

  • Environmentally friendly technologies and energy-efficient systems are preferred in company operations.
  • Digitalization and cloud-based solutions are prioritized to minimize carbon footprint.
  • Waste management is considered in all activities, and actions comply with recycling and sustainability policies.

3. Continuous Improvement

  • The Information Security Management System is regularly reviewed, and improvement opportunities are evaluated.
  • Training is provided to raise employees’ awareness of information security.
  • Changes in relevant standards and regulations are rapidly adapted to.

4. Compliance and Legal Requirements

  • Full compliance with ISO 27001 ISMS requirements and relevant legal regulations is ensured.
  • A secure working environment is maintained considering the information security requirements of our customers and business partners.

5. Risk Management

  • Regular risk analyses are conducted to identify and manage information security risks.
  • Security measures are tailored to risk levels and continuously updated.

6. Business Continuity

  • Business continuity plans are established against potential information security breaches and are regularly tested.
  • Preparedness for emergencies and disaster scenarios ensures continuity of operations.

Conclusion

Erfa is committed to adopting best practices in information security, operating with environmental responsibility, and applying the principle of continuous improvement. All employees and business partners are expected to act in accordance with this policy.

This policy is reviewed annually and updated as necessary.