Information Security Policy
The Information Security Management System at Eren Holding Inc., Eren Enerji Electricity Generation Inc., and other Group companies is based on the following key principles:
- Protecting the confidentiality, integrity, and availability of information assets processed, transmitted, stored, or shared with third parties.
- Continuously improving the management system established to identify, assess, and control security needs, risks, vulnerabilities, and opportunities related to information security processes.
- Implementing controls against IT and communication system security risks while monitoring technological developments.
- Ensuring full compliance with laws, regulations, contractual requirements, and corporate principles.
- Meeting the legal obligations set by the Energy Market Regulatory Authority.
- Minimizing the impact of information security risks and ensuring business continuity.
- Being capable of responding swiftly to potential information security incidents and mitigating their effects.
- Raising employee awareness and responsibility regarding information security.
- Ensuring Group companies and external service providers comply with information security system requirements.
- Defining and enforcing information security requirements for third parties, suppliers, and visitors.
- Protecting Eren Holding's reputation from information security-based threats.
- Defining measurement methods and reporting to enhance the effectiveness of implemented information security controls.