Information Security Policy
TEMSA Information Security Policy
The information assets owned by Temsa Skoda Sabancı Transportation Vehicles Inc., together with its ability to generate, process, and present information, are among the company’s most valuable assets. Ensuring the confidentiality, accuracy, and availability of the information assets required by Temsa Skoda Sabancı Transportation Vehicles Inc. to perform its corporate functions constitutes the main objective of the Information Security Management System (ISMS).
Temsa Skoda Sabancı Transportation Vehicles Inc. Management has decided to implement the ISO/IEC 27001 Standard to ensure the identification of information assets related to the company’s business processes, assignment of security classifications to these assets, identification of threats and vulnerabilities, calculation and rating of security risks, planning and implementation of necessary security measures to reduce risks to acceptable levels, and ensuring their continuous review and improvement.
The management of Temsa Skoda Sabancı Transportation Vehicles Inc. has established an Information Security Management Board to implement the requirements and controls of the ISO 27001 Standard. The Board is responsible for preparing information security policies, procedures, and annexes, training all employees on information security, planning necessary security measures within the scope of risk management, implementing and monitoring them, and ensuring the operation of the system by taking necessary actions according to control results.
The established Information Security Management System supports the company's core activities and includes policies, procedures, and instructions designed to prevent violations of any legal, regulatory, contractual, or security requirements related to the company’s main operations and support units. Preparing, updating, and maintaining these documents in line with new requirements is under the responsibility and management of the ISMS Board on behalf of senior management of Temsa Skoda Sabancı Transportation Vehicles Inc.
All employees of Temsa Skoda Sabancı Transportation Vehicles Inc. and contractor personnel working at company premises on behalf of the company are obliged to comply with the Information Security Policies, Procedures, and Instructions.
Temsa Skoda Sabancı Transportation Vehicles Inc. management declares its commitment to providing the necessary support to fulfill the requirements of the Information Security Management System, which has been established to maintain the company's credibility and corporate image, and to ensure the uninterrupted continuity of its core and supporting business processes.
Definition of Information Security
Temsa Skoda Sabancı Transportation Vehicles Inc. requires numerous types of information and information assets to perform its corporate functions. These information assets and the systems facilitating the generation, processing, and presentation of information are among the company's most important values. Ensuring confidentiality, accuracy, and availability of information is crucial for fulfilling corporate obligations. Security problems arising intentionally, negligently, or due to errors constitute the main obstacles to the effective, uninterrupted, and accurate use of corporate information.
The necessary steps to prevent security issues and ensure the effective and secure use of Temsa Skoda Sabancı Transportation Vehicles Inc.’s information assets, along with authority and responsibility distribution, are included in the ISMS Documentation.
Three fundamental components define information security:
Information may exist in various forms, such as electronic, physical, paper-based, human memory, computer networks, or oral communication. Appropriate protection must be ensured for each form.
Purpose of the ISMS
Information, as described above, is a highly valuable asset for Temsa Skoda Sabancı Transportation Vehicles Inc. Protection of the confidentiality, integrity, and availability of information is directly related to service quality, legal obligations, and the company’s professional image.
Temsa Skoda Sabancı Transportation Vehicles Inc., like other modern companies, relies heavily on information technologies and uses these systems to carry out its production activities. New software, hardware, and applications may be introduced in upcoming projects, and new personnel may be employed. This expansion may lead to increasing security vulnerabilities and new threats. Therefore, it is critically important for the company to protect and manage its information assets systematically and consciously. The ISMS has been established precisely to achieve this goal.
Scope of the ISMS
The ISO/IEC 27001 Information Security Management System scope at Temsa Skoda Sabancı Transportation Vehicles Inc. includes:
• Temsa Skoda Sabancı Transportation Vehicles Inc. Adana Bus Factory
• Temsa Skoda Sabancı Transportation Vehicles Inc. Istanbul Office
Foreign subsidiaries and representative offices of the company are excluded from the ISMS scope in order to initiate improvement efforts in a more contained environment. Activities not directly or indirectly interacting with information systems are also outside the scope.
ISMS Risk Management and ISMS Board
ISMS Risk Management involves identification of IT‑interactive information assets within the defined scope, classification of these assets, identification of threats and vulnerabilities, calculation and rating of risks, planning and implementing necessary security measures to reduce risks to acceptable levels, and ensuring continuous review and improvement.
The ISMS Board is responsible for prioritizing actions and measures against identified risks, decision‑making, revising policies and related documents, coordinating corporate security awareness, and improving the ISMS on behalf of senior management.
Sanctions
All employees of Temsa Skoda Sabancı Transportation Vehicles Inc. and personnel specified in Article 6 are responsible for fulfilling the provisions of this document and all related documents. In cases of non‑compliance, disciplinary actions may be taken against individuals violating these provisions in accordance with company regulations.