This policy has been approved by the Chairman of the Board of Directors of Zeren Group Holding.
The Information Security Policy ensures all of the following requirements:
-
Identification of all processes and information assets and their risk assessments in accordance with the standard.
-
Minimizing the risks arising from unauthorized access, loss, corruption or misuse of Zeren Group Holding information assets.
-
Fulfillment of legal obligations arising from legal obligations and contracts.
-
Managing the existing ISMS structure by carrying out the necessary work within the scope of continuous improvement
-
Conducting regular trainings and awareness-raising activities to increase the information security awareness of all employees.
-
Regularly analyzing information security incidents and breaches, taking necessary corrective measures and ensuring that all information security breaches or suspected breaches are reported and investigated.
-
Allocating all necessary resources to ensure effective implementation of the information security policy.
Zeren Group Holding Information Security Policy is valid and mandatory for all Zeren Group Holding and its subsidiaries' personnel who use Zeren Group Holding's information or business systems, whether full-time, part-time, permanent or contracted, regardless of geographical location or business unit.
All persons who do not fall into these classifications and who need access to Zeren Group Holding information, such as third party service providers and their affiliated support staff, are required to adhere to the general principles of this policy and other security responsibilities and obligations that they must comply with.
Violations of the Information Security Policy may cause damage to Zeren Group Holding as a result of not implementing the necessary controls against risks, as well as criminal liability under the new Turkish Penal Code and liability for compensation for material damages. Therefore, such violations may also result in disciplinary action. Violations of the Information Security Policy, whether detected as a result of surveillance, audit or denunciation, may result in sanctions specified in the internal Discipline and Ethics Procedure, up to and including termination of employment and even the initiation of judicial and criminal legal proceedings.
Information security is critical to the success of Zeren Group Holding and demonstrates a commitment to information security. This policy must be understood and adopted by all our employees, business partners and stakeholders.
Document No: ZGH.IT.POL.001 Date: 01.05.2025 Rev.0