Information security; It means taking precautions by making necessary security analyzes in order to protect against unwanted threats and dangers in order to prevent unauthorized or unauthorized access, use, modification, disclosure, destruction, damage or change of hands of information.
ISO 27001 Standard; It is a standard prepared to create a model for the establishment, development, operation, monitoring, review, continuity and sustainability of the Information Management System.
This standard was published by ISO on October 14, 2005 and took its place in the ISO/IEC 27000 STANDARD Series. It was accepted as a Turkish Standard at the meeting of the TSE Technical Board on March 2, 2006 and published under the name TS ISO/IEC 27001 Information Technology-Security Techniques-Information Management Systems-Requirements.
This standard includes the standards required for the certification of organizations about Information Security Management Systems.
All organizations, regardless of sector, can install this system and obtain the ISO 27001 certificate.
Steps to be taken in an institution that wants to implement an Information Security Management System:
1. Security policy should be created,
2. Information Security Organization should be established
3. Asset management is done
4. Duties and responsibilities are determined by human resources and agreements regarding confidentiality are made.
5. Physical and environmental security is ensured
6. Communication and business management are regulated
7. Access-related controls are provided, authorizations and access based on authorizations are determined.
8. Updates are made on information systems supply, development and maintenance.
9. Information security incidents management order is created.
10. Business continuity management should be improved.
11. It is necessary to ensure that information complies with laws, contracts and regulations.
ISO 27001 Information Security Management System; It helps organizations become aware of their information assets and understand the importance of their assets, identify and manage risks, and ensure business continuity.