Information Security Management System Policy


The purpose of this policy is to define the senior management's approach and goals to follow and apply national / international standards / legislation on information security, and to inform all employees and interested parties.

This policy covers all information assets of MKS Marmara Entegre Kimya Sanayi A.Ş. in Foreign Trade, Information Technologies, Finance-Accounting and Administrative Affairs.

Our vision, as a modern and reliable organization in its field, is to always fulfill the quality and performance that will meet the needs and expectations of its customers with its products and services.

ISO 27001 compliant Information Security Management System has been established to realize our vision. In this way:

  • Information security risks are evaluated by the units within the scope in line with the processes, the risks are prioritized and the necessary measures are taken.
  • In decisions and actions, importance and priority are given to the use of reliable objective information and all possibilities of technology. The data in the IT systems used is ensured to be up to date and accurate.
  • Confidentiality is given importance as a requirement of corporate values, all kinds of customer information, organization that provides competitive advantage to the institution, infrastructure, process and technology information, the confidentiality of all kinds of personal information are ensured by policies, processes and necessary security measures, especially advanced technology. Information is not shared unless the owner of the information requests it, authorization is granted or legal requirements arise.
  • Continuity of our infrastructure and supplier network is ensured to ensure that our solutions comply with customer needs and international standards.
  • Relevant legal requirements are followed and enforced.
  • Information security requirements are defined by policies, announced to all employees and all employees are ensured to comply with these policies.
  • Our management team allocates the necessary resources and assigns roles and responsibilities to ensure the continuity of the Information Security Management System.
  • As a requirement of continuous improvement, information security targets are determined annually and approved by management.
  • If necessary, project plans are created and the situation is monitored to achieve the targets.
  • The information security policy is announced to all employees and related third parties.