Award-Winning IT Brand
TREN
Home/Our Integrated Management System Policy
ERY System Corporate

Our Integrated Management System Policy

Our Integrated Management System Policy
ERY System logo Our TS EN ISO 27001:2022-27701-20000-1 Information Security/Personal Data Protection/Service Management System Policy At ERY Bilişim, in order to ensure information security management at the highest level in the services we provide, we operate an Information Security Management System (ISMS), a Personal Data Protection Management System and a Service Management System that conform to the TS EN ISO 27001:2022, ISO 27701 and ISO 20000-1 standards. Our aim is to protect our valuable assets, such as people, infrastructure, software, hardware, customer information, organizational information, information belonging to third parties and financial resources, and to continuously improve the performance of our information security management processes. We also aim to continuously improve our service capability infrastructure. Objectives of Our Integrated Policy:
  1. Protection of Information Assets: To protect ERY Bilişim's information assets against all kinds of threats that may arise from inside or outside, deliberately or accidentally.
  2. Availability of Information: To ensure the availability of information in line with business processes.
  3. Legal Compliance: To ensure compliance with applicable legislation and regulations.
  4. Continuous Improvement: To continuously measure and improve the performance of information security management processes.
Core Principles of Our Information Security Management System:
  • Confidentiality: Preventing unauthorized access to important information.
  • Integrity: Preserving the accuracy and integrity of information.
  • Availability: Ensuring that authorized persons can access information when needed.
Our TS EN ISO 20000-1 Information Technology – Service Management System Policy
  • To increase our proactive approach in the delivery of IT services,
  • To understand the business units to which IT services are delivered and to strengthen relations with those business units,
  • To make IT services more measurable and, in this way, to be able to make more rational decisions,
  • To review service level criteria (metrics) and, where necessary, to change them in light of customer feedback and the data collected,
  • To hold regular service meetings with customers and to gather ideas for improvement from these meetings,
  • To continuously improve the effectiveness of the service management system.
Scope of Application: This policy concerns the security not only of data held in electronic form, but of all data in written, printed, verbal and similar forms. The continuity of the three core principles of our Integrated Security Management System will be ensured in all activities carried out. Our Policy Commitments:
  • Training and Awareness: To raise awareness by providing integrated security management training to all our personnel.
  • Reporting and Investigation: To report actual or suspected information security breaches to the ISMS Quality Coordinator and to ensure that they are investigated by the coordinator.
  • Meeting Business Requirements: To meet business requirements for the availability of information and for information systems.
  • Ensuring Continuity: To design all our processes so that they support business continuity and to ensure that they are sustained.
This policy has been adopted and is implemented by all employees and stakeholders in order to achieve ERY Bilişim's integrated system security objectives.