Information & Quality Security Policy
ISO/IEC 27001:2022 · Information Security Management System
As the top management of DENTISTINN YAZILIM VE TEKNOLOJİ ANONİM ŞİRKETİ, the core theme of the systems established to the ISO/IEC 27001:2022 Information Security Management System (ISMS) standard across our services is: to demonstrate that information security management is ensured across people, infrastructure, software, hardware, customer information, organizational information, all business and operations, third-party information and financial resources; to safeguard quality and risk management; to measure the process performance of information-quality security management; and to govern relationships with third parties on matters of quality, information security and customer satisfaction.
Purpose of Our ISMS Policy
To protect the information assets of DENTISTINN YAZILIM VE TEKNOLOJİ ANONİM ŞİRKETİ against any threat that may arise from inside or outside, knowingly or unknowingly; to ensure appropriate access to information through business processes; to meet legal and regulatory requirements; and to carry out work aimed at continual improvement.
To ensure the continuity of the three fundamental elements of the Information Security Management System across all activities carried out:
- Confidentiality: preventing unauthorized access to sensitive information.
- Integrity: demonstrating that the accuracy and integrity of information are maintained.
- Availability: demonstrating that those who are authorized can access information when needed.
Leadership and Commitment
Our top management leads the establishment and implementation of the ISMS and participates in ISMS practices at the highest level. In this context, we commit to the following:
- To address the security of all data — not only that held electronically, but also written, printed, verbal and similar forms.
- To raise awareness by providing Information Security Management training to all personnel.
- To report all actual or suspected vulnerabilities in information security to the ISMS Team and ensure they are investigated by the ISMS Team.
- To prepare, maintain and test business continuity plans.
- To identify current risks through periodic information-security assessments, and to review and follow up action plans based on the results.
- To prevent any dispute or conflict of interest that may arise from contracts.
- To meet business requirements for information accessibility and information systems.