Information Security Policy

In carrying out import, export, transit, customs, and foreign trade operations related to the sales and marketing of all types of machinery, as well as logistics, storage, finance, R&D, accounting, and information technology activities associated with these processes, Durmazlar Makine aims to:

Demonstrate that information security management is ensured across human resources, infrastructure, software, hardware, customer information, corporate data, third-party information, and financial resources;
Guarantee effective risk management;
Measure the performance of information security management processes; and
Ensure the proper regulation of relations with third parties regarding information security matters.

In this context, we are committed to:
• Protecting our organization’s information assets against all kinds of threats that may arise intentionally or unintentionally, from internal or external sources, ensuring the accessibility of information in alignment with business processes, and meeting all legal and regulatory requirements.
• Ensuring the continuity of the three fundamental elements of the Information Security Management System (ISMS) in all operations:
 – Confidentiality: Preventing unauthorized access to sensitive information,
 – Integrity: Ensuring and demonstrating the accuracy and completeness of information,
 – Availability: Guaranteeing that authorized individuals can access information when necessary.
• Protecting not only electronically stored data but also all written, printed, verbal, and other forms of information.
• Raising awareness by providing information security management training to all employees.
• Reporting any actual or suspected information security breaches to the ISMS team and ensuring that such cases are investigated.
• Preparing, maintaining, testing, and continuously improving business continuity plans.
• Conducting periodic assessments on information security to identify existing risks, reviewing action plans, and ensuring proper follow-up.
• Preventing any kind of dispute or conflict of interest that may arise from contractual obligations.
• Meeting all business requirements for information accessibility and information systems.