Information Security

Purpose and Scope

    This policy defines the core principles and management commitment of the ISMS (Information Security Management System) established to protect the confidentiality, integrity, and availability of information within the scope of Computer and Programming Activities and Software Development Services conducted by Kimlikpro.

    The scope encompasses all physical and electronic information assets, processes, and systems, as well as all personnel, contractors, and relevant third parties.

    1.  Information Security Commitment and Objectives

    Executive Management Commitment: Top management commits to providing the necessary resources and demonstrating leadership for the establishment, implementation, maintenance, and continual improvement of an ISMS in accordance with the requirements of the ISO/IEC 27001:2022 standard.

    Core Objectives:

    Confidentiality: Ensuring the protection of customer data, intellectual property, and sensitive corporate information against unauthorized access, use, disclosure, modification, or destruction. Maintaining the highest level of protection, particularly for personal and financial data involved in identity verification processes.

    Integrity: Ensuring the accuracy and completeness of information. Preventing unauthorized or unintended modification of Software and Development Services deliverables (code, products, systems).

    Availability: Ensuring that authorized users have timely access to information and systems—specifically Fraud Prevention Systems and critical Fintech infrastructures—when required.

    1.  Domain-Specific Critical Security Principles

    Software and System Development Security (DevSecOps): Security shall be integrated into every stage of the software development life cycle (SDLC), including secure coding, security testing, and static/dynamic analysis. Minimizing security vulnerabilities in developed products (such as identity verification applications) is essential.

    Identity and Access Management: To ensure the reliability of identity detection systems, the use of strong authentication mechanisms, the implementation of the principle of least privilege, and regular access reviews are mandatory.

    Fraud and Threat Prevention: Cyber threat intelligence and proactive monitoring mechanisms shall be established for Fraud Prevention Systems and Fintech Solutions. Preparedness against next-generation threats shall be maintained through continuous risk analysis.

    Compliance with Legal and Regulatory Requirements: Strict compliance shall be ensured with all national and international legal, regulatory, and contractual obligations applicable to our domain of activity (such as KVKK, GDPR, Financial Regulations, etc.).

    1.  Risk Management and Continual Improvement

    Risk Management Process: The ISMS risk management process is implemented to systematically identify, analyze, evaluate, and treat information security risks in line with Kimlikpro’s business objectives and corporate risk appetite.

    Regular internal audits, management reviews, and security incident analyses are conducted to ensure the performance and effectiveness of the ISMS. Corrective and preventive actions are initiated for identified non-conformities and security vulnerabilities, thereby supporting the continual improvement cycle.

    1.  Responsibilities and Awareness

    Information Security Manager: Primarily responsible for the operation and maintenance of the ISMS.

    All Employees: Responsible for understanding and complying with the requirements of this policy. Employee awareness levels shall be continuously enhanced through regular Information Security Awareness Trainings.

    Incident Management: Information security breaches and suspicious incidents shall be reported immediately and handled in accordance with the incident management procedure.