TCI Kabin İçi Sistemleri Sanayi ve Ticaret A.Ş. (TCI) recognizes the protection of information assets and systems that may affect aviation safety as a corporate priority.
The Purpose of this Policy is to protect the confidentiality, integrity, and availability of information assets, manage information security risks, keep cyber risks that may affect aviation safety under control, and ensure the continual improvement of the Information Security Management System.
The Scope of this Policy covers all activities carried out within TCI, information assets, information technology systems, employees, suppliers, and processes that may affect aviation safety.
The Objectives of the Policy are to protect the confidentiality, integrity, and availability of information assets, manage information security risks that may affect aviation safety, ensure compliance with legal and regulatory requirements, effectively manage security incidents, develop an information security culture, and ensure continual improvement.
1.COMPLIANCE WITH LEGAL REQUIREMENTS AND STANDARDS
Information security activities are carried out in accordance with the ISO/IEC 27001 standard, EASA Part 21 / Part 145 - Part-IS, SHT-Cyber Instruction, KVKK, GDPR, all applicable national and international legislation, and recognized best practices for the aviation industry. Full compliance with legal and regulatory requirements is essential. TCI ensures that information security incidents are reported in accordance with applicable legislation and regulatory requirements.
2.INFORMATION SECURITY OBJECTIVES AND PERFORMANCE MEASUREMENT
Information security objectives are based on reducing cyber risks that may affect aviation safety, protecting the confidentiality, integrity, and availability of critical information assets, effectively managing security incidents, controlling third-party risks, and reducing cyber threats that may affect aviation safety.
These objectives are monitored through measurable performance indicators and provide input to management reviews.
3.INFORMATION SECURITY MANAGEMENT SYSTEM (ISMS)
TCI protects its information and communication technology systems, safety-critical data, and supporting processes through appropriate technical and organizational controls.
ISMS requirements are implemented by integrating them into engineering, production, quality, safety, supply chain, and management processes. Information security is managed in an integrated manner with corporate governance and safety management processes.
4.RISK MANAGEMENT APPROACH
Information security and safety risks are addressed in an integrated manner through the ISO/IEC 27001 risk management methodology and the safety risk assessment approaches used within the SMS framework. The impacts of cybersecurity incidents on aviation safety are additionally assessed. Risks are evaluated by considering their effects on confidentiality, integrity, availability, and aviation safety and are managed with an awareness of “residual risk”.
5.CONTINUAL IMPROVEMENT
TCI regularly evaluates audit, testing, and monitoring results in order to increase the maturity of its information security processes, implements corrective and preventive actions, and adopts a continual improvement approach.
6.MANAGEMENT COMMITMENT AND RESOURCES
This policy has been approved by Top Management.
Top Management commits to providing the necessary human resources, budget, and technological infrastructure for the effective operation of the ISMS. The policy is reviewed at planned intervals or following significant changes.
7.RESPONSIBILITIES OF MANAGERS
The coordination and oversight of information security management activities are ensured through the Common Responsible Person (CRP) appointed in accordance with EASA Part-IS requirements. Information security is one of the fundamental responsibilities of all managers. Managers are responsible for ensuring that activities within their areas of responsibility are carried out in accordance with ISMS requirements. Information security is the shared responsibility of all employees and stakeholders.
8.AWARENESS AND TRAINING
All employees receive Information Security Awareness Training at least once a year. Additional training and awareness activities are conducted in the event of significant changes to policies or processes. The establishment of a strong information security and cybersecurity culture throughout TCI is supported.
9.JUST CULTURE AND INCIDENT REPORTING
TCI adopts a “Just Culture” approach that encourages the reporting of security vulnerabilities, suspicious or abnormal events, and information security breaches without fear of punishment.
10.THIRD-PARTY AND PHYSICAL SECURITY
Third parties are required to comply with information security and safety requirements. Access to areas containing information assets and safety-critical systems is restricted based on roles and authorizations. Information security risks associated with suppliers and service providers are managed through appropriate controls.
11.CYBERSECURITY AND AVIATION SAFETY
TCI recognizes that information security and cybersecurity activities are an integral part of aviation safety. Potential impacts on aviation safety are taken into consideration when assessing information security risks.
12.INCIDENT, ACCOUNT, AND ACCESS MANAGEMENT
Information security incidents and incidents affecting aviation safety are recorded through designated channels, root cause analyses are conducted, and necessary preventive measures are implemented. User accounts and access rights are managed securely, and all activities are logged.
13.COMMITMENT
In line with this policy, we commit to continuously reviewing and improving the effectiveness of our Information Security Management System in order to ensure aviation safety and to maintaining transparent communication with our employees, customers, business partners, and regulatory authorities.
ATİLLA ÇOŞKUN
GENERAL MANAGER