Information Security Policy

This policy outlines the necessary standards, rules, responsibilities, and procedures that align with the business goals of Ay-Tim Tekstil Sanayi ve Dis Ticaret A.S. It is based on the needs of the business and is structured according to relevant laws and standards. This policy aims to guide all aspects of information security at Ay-Tim Tekstil Sanayi ve Dis Ticaret A.S., and to detail the information security processes and controls, supported by additional documents.

Purpose

The purpose of the Information Security Policy is to set up a framework for managing information security; to define the main goals and principles of information security; and to highlight the management's support for the information security management system.

Scope

The Information Security Policy covers principles designed to support the strategic goals of Ay-TIM Tekstil San. ve Dis Tic. A.S., protect its brand value, and ensure compliance with relevant regulations.

Policy

We are committed to:

- Meeting the information security obligations that come from national or international laws, legal requirements, and agreements with both internal and external parties, which are important for our business activities,

- Protecting information by maintaining the accessibility, integrity, and confidentiality of critical data related to our company and our stakeholders,

- Enhancing our employees’ involvement in information security by improving their skills and understanding within the organization,

- Keeping our company's main and supporting business activities going with minimal interruption in case of any challenges,

- Establishing, implementing, reviewing, and continuously improving an information security management system based on the ISO/IEC 27001:2013 Standard on Information Security Management Systems.