Skip links

INFORMATION SECURITY POLICY

Türk Tasavvuf Musikisi ve Folklorunu Araştırma ve Yaşatma Vakfı

INFORMATION SECURITY POLICY

As the FOUNDATION FOR THE RESEARCH AND PRESERVATION OF TURKISH SUFI MUSIC AND FOLKLORE, ensuring the security of all types of information belonging to us and our stakeholders, as well as the security of the premises where we carry out our activities and our organisational information processing procedures, whilst taking into account the principles of confidentiality, integrity and availability, is among our top priorities.

In this context, as the Turkish Sufi Music and Folklore Research and Preservation Foundation, we comply with the requirements set out in legislation, standards and our organisational policies and procedures regarding information security. We operate an Information Security Management System compliant with the ISO/IEC 27001 standard, which ensures that applicable information security requirements are met.

To ensure full compliance with and continuous improvement of the Turkish Sufi Music and Folklore Research and Preservation Foundation’s Information Security Management System, we conduct internal audits and take their results into account.

To protect our information assets, we maintain control over activities such as the storage, transmission, modification, access and processing of assets, based on current best practices. By adopting a cyber resilience approach, we actively monitor emerging technologies and cyber security threats. By implementing the most up-to-date security measures, we enhance the organisation’s resilience and ensure we are prepared to respond swiftly and effectively to potential cyber attacks.

In this regard, processes are monitored by personnel appointed on the basis of merit within our foundation, and the necessary resources relating to this matter are also provided.

The necessary measures are being taken to enable the detection and reporting of information security breaches and to ensure that action is taken as quickly as possible in response to such breaches.