{"id":413,"date":"2023-08-22T17:48:24","date_gmt":"2023-08-22T14:48:24","guid":{"rendered":"https:\/\/www.lotustekstil.com.tr\/?page_id=413"},"modified":"2026-05-09T01:15:00","modified_gmt":"2026-05-08T22:15:00","slug":"bilgi-guvenligi-politikasi","status":"publish","type":"page","link":"https:\/\/www.lotustekstil.com.tr\/en\/bilgi-guvenligi-politikasi\/","title":{"rendered":"Information Security Policy"},"content":{"rendered":"<div id=\"modal-ready\"><p class=\"p1\">Document No.: 111.8<br \/>\nIssuance Date: 6\/20\/2023<\/p>\n<p class=\"p1\">Roles and responsibilities of LOTUS personnel are defined in internal job descriptions. The scope of information security is described in this document. Therefore, the following policies involve operations, layouts, and assets specified in the scope section. The legislation, statutory obligations, and customer agreements, which govern our organization, comprise the fundamental inputs of our Information Security Management System.<\/p>\n<ol class=\"ol1\">\n<li class=\"li1\">All information assets and other assets should be defined. In case of an undefined asset, Management Systems Representative should be informed promptly.<\/li>\n<li class=\"li1\">All information that is used or generated should be classified according to information classification criteria (Asset Inventory Management Guidelines). In case of an unclassified information, Management Systems Representative should be informed promptly.<\/li>\n<li class=\"li1\">Confidentiality of generated and\/or used information should be assured under any circumstances in consideration of the information classification criteria (Asset Inventory Management Guidelines).<\/li>\n<li class=\"li1\">In order to make information security sustainable, IS Risk Management System should be implemented for all assets and decisions made afterwards (risk monitoring, risk mitigation, risk transfer, risk avoidance, risk acceptance) should be implemented categorically.<\/li>\n<li class=\"li1\">Any change that is experienced in infrastructure, organization, or processes and that impacts Information Security risks should be monitored and necessary risk review activities should be conducted.<\/li>\n<li class=\"li1\">Access to information and activities that can be conducted with accessed information are described in documents under the title access management. All employees must work in compliance with the principles specified herein.<\/li>\n<li class=\"li1\">Business continuity management shall be implemented to protect critical business processes from the impacts of great disasters and operating faults. Trainings aimed at increasing information security awareness of the personnel and encouraging contribution to functioning of the system shall be provided regularly to company employees and new recruits.<\/li>\n<li class=\"li1\">All actual or suspected information security violations should be reported. Non-conformities that cause violations should be identified and necessary adjustments and corrective activities should be performed.<\/li>\n<li class=\"li1\">Measures, aimed at preventing information other than unclassified information from being viewed by other parties, should be taken in work spaces pursuant to the \u201cClear Screen\/Clear Desk Policy\u201d.<\/li>\n<li class=\"li1\">LOTUS employees should act in compliance with rules related to encryption in all information systems that they use.<\/li>\n<li class=\"li1\">Network and internet systems should be used pursuant to network and internet system manuals.<\/li>\n<li class=\"li1\">Attention should be paid to information security pursuant to relevant rules when work is conducted with third parties (contractor, supplier, customer, etc.).<\/li>\n<li class=\"li1\">Attention should be paid to information security, regardless of project type, in project management.<\/li>\n<li class=\"li1\">Attention should be paid to information security pursuant to relevant rules during communication with authorities and special interest groups.<\/li>\n<li class=\"li1\">Information processing assets should be used in a manner that ensures the highest level of information security and relevant parties should be contacted in the case of non-conformity.<\/li>\n<li class=\"li1\">All ISMSs are established, maintained, monitored pursuant to the requirements of the Standard and measures are taken as necessary.<\/li>\n<\/ol>\n<p class=\"p1\">Ahmet Murat G\u00d6N\u00dcL<br \/>\nCEO<\/p>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Document No.: 111.8 Issuance Date: 6\/20\/2023 Roles and responsibilities of LOTUS personnel are defined in internal job descriptions. The scope of information security is described in this document. Therefore, the following policies involve operations, layouts, and assets specified in the scope section. The legislation, statutory obligations, and customer agreements, which govern our organization, comprise the [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":[],"_links":{"self":[{"href":"https:\/\/www.lotustekstil.com.tr\/en\/wp-json\/wp\/v2\/pages\/413"}],"collection":[{"href":"https:\/\/www.lotustekstil.com.tr\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.lotustekstil.com.tr\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.lotustekstil.com.tr\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.lotustekstil.com.tr\/en\/wp-json\/wp\/v2\/comments?post=413"}],"version-history":[{"count":5,"href":"https:\/\/www.lotustekstil.com.tr\/en\/wp-json\/wp\/v2\/pages\/413\/revisions"}],"predecessor-version":[{"id":560,"href":"https:\/\/www.lotustekstil.com.tr\/en\/wp-json\/wp\/v2\/pages\/413\/revisions\/560"}],"wp:attachment":[{"href":"https:\/\/www.lotustekstil.com.tr\/en\/wp-json\/wp\/v2\/media?parent=413"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}