What is the DDO Information and Communication Security Guide?
According to Presidential Circular No. 2019/12, dated 06.07.2019, public institutions and enterprises that provide critical infrastructure services are required to comply with certain Information and Communication Security measures. As part of this initiative, the "Information and Communication Security Guide" was prepared under the coordination of the Digital Transformation Office and approved on 24.07.2020.
The Circular highlights the importance of Information and Communication Security measures that must be implemented by public institutions and enterprises providing critical infrastructure services. The main objective is to minimize and mitigate security risks associated with information systems and to safeguard critical data that may pose a threat to national security or disrupt public order, especially when the confidentiality, integrity or accessibility of the data is compromised. The Circular serves as a significant legal framework that aims to enhance the overall level of information security throughout the country.
The Information and Communication Security Guide is a reference document that is unique to Turkiye and aims to increase the level of information and communication security. It is the first of its kind in the field of information and communication security and was prepared with the participation of all relevant stakeholders. It continues to be updated to take into account evolving technology, changing conditions, and national policies and strategies.
It is mandatory for all public institutions and organizations and enterprises providing critical infrastructure services to comply with the measures in the Guide in both existing and newly established information systems. The existing information technology infrastructures will be gradually harmonized with these principles in accordance with the plan in the Guide, taking into account the security level priorities.
Information and Communication Security Audit Service
Achieving and maintaining the objectives set out in the Information and Communication Security Guide can only be possible through effective audit and surveillance activities.
Public institutions, organizations, and critical infrastructure service providers are expected to complete their compliance activities within the timeframe specified in the Information and Communication Security Guidelines. Furthermore, they are required to perform audits at least once a year to evaluate the effectiveness of the activities performed and the measures taken.
Accordingly, the Digital Transformation Office prepared an Information and Communication Security Audit Guide to guide institutions and organizations in conducting audit activities.
The "Information and Communication Security Guideline Compliance Audit Service Provider Personnel and Company Certification Program" is a certification program that has been implemented in cooperation with TSE and TÜBİTAK BİLGEM under the coordination of the Presidency of the Digital Transformation Office. The program includes criteria for companies and personnel who provide audit services, as well as training and certification requirements.
ADEO is authorized to conduct Information and Communication Security Guide Compliance Audits by participating in the relevant programs and obtaining the necessary certificates.
Information and Communication Security Audit Methodology
The methodology to be applied in the Guidelines compliance audit is based on three main processes: Planning the audit, performing the audit procedures and reporting the audit results. The main objective of the audit is to measure the following criteria:
a) Effectiveness of the guidance implementation process
b) Effectiveness of measures applied to groups of assets
Information and Communication Security Consultancy Service
Within the scope of compliance with the Information and Communication Security Guide published by the Digital Transformation Office of the Presidency of the Republic of Turkey, for which Public Institutions and Critical Infrastructure Organizations are held responsible according their companies, we can optionally provide Consultancy or Audit Services organisation.