CHAPTER ONE: PURPOSE AND SCOPE
This policy document contains the set of rules and practices that govern the protection of the Turkish Journalists’ Union (TGS)’s critical functions by ensuring the management, protection, confidentiality, integrity, distribution, and accessibility of TGS information assets only by authorized individuals.
ARTICLE 1: Purpose
The purpose of this information security policy document is to define appropriate security requirements in accordance with TGS standards and best practices; to ensure the secure use of Information Technology services within TGS in compliance with applicable laws and regulations; and to protect TGS and other users against security threats at an acceptable level.
ARTICLE 2: Scope
TGS does not have a centralized information technology platform or server/processor infrastructure. All users at TGS have their own computers, and they are personally responsible for the information technology security measures regarding those computers. On the other hand, this policy covers all users, temporary staff, and visitors within TGS, as well as their information technology devices and software.
SECTION TWO: OBJECTIVES AND PRINCIPLES
ARTICLE 3: Information Security Objectives
TGS’s objectives under this policy are:
- To prevent TGS, its employees, and other users from facing administrative or legal sanctions due to potential regulatory violations by maintaining information it owns or is obligated to retain in compliance with applicable laws,
- To protect TGS’s credibility and the image of the authority it represents,
- To ensure compliance with the terms specified in contracts with third parties,
- To ensure that all of TGS’s core and supporting activities continue with minimal disruption
by securing the information security of all physical and electronic information assets used in the delivery of IT services.
ARTICLE 4: Information Security Principles
All personnel who use the TGS IT infrastructure and access information resources must:
- Must ensure the confidentiality of all information belonging to TGS and/or transmitted to TGS in personal and organizational electronic communications and in the exchange of information with third parties,
- Must back up the information they receive, send, and process according to its level of criticality,
- Must report information security incidents to the TGS Secretary-General in writing,
- Must not disclose TGS-internal and/or information sources transmitted to or received by TGS (such as announcements, documents, electronic information, and records) to third parties without authorization,
- TGS IT resources must not be used for personal purposes, in violation of regulations, for any purpose defined as a crime by law, or for activities that compromise TGS’s institutional identity, physical security, and/or electronic security.
- All computers may only be operated with a password, and all users are solely responsible for securely keeping their own passwords confidential from others.
- It is prohibited for any user to share any resources belonging to their own computer—including hard drives, flash drives, any type of storage device connected to the computer, internet connections, or devices at TGS (such as printers, scanners, etc.).
- In the event of a computer malfunction, should data loss occur or data recovery or a new installation be required, technicians may access the information on the computer with the permission of TGS administrators.
- Furthermore, all users are prohibited from installing remote access applications for any reason without the administrators’ permission; users have also been warned about the risks of installing unauthorized applications that request access to the computer’s data and resources.
SECTION THREE: POLICIES
ARTICLE 5: Information Technology Assets Management Policy
Information Technology asset management regulates the processes of clearly and explicitly identifying, assigning ownership to, classifying, labeling, and updating assets—including value-creating intellectual property (ideas, concepts, know-how, techniques, materials, and documentation), human resources, technology, buildings, and hardware—as well as the processes that constitute the organization’s institutional memory. This process covers the organization’s desktop computers, laptops, printers, mobile devices, and other hardware, as well as the inventory of applications and software, and includes the management of the asset assignment process.
- The information technology inventory should be used solely for assignment and/or authorization purposes within the relevant business activities.
- Information with a high criticality value and confidentiality level must be stored in locked cabinets or safes that are inaccessible to anyone other than authorized personnel.
- Printing, photocopying, and using a scanner, sharing, storing, and disposing of information—whether through internal or external union channels via verbal (presentations, meetings, etc.), physical (printed copies, etc.), or electronic (email, web conferencing, etc.) means—including the disposal of printed copies and information on removable media, must be determined based on the applicable confidentiality level.
- Users assigned devices (for devices for which they have signed an asset assignment form) are responsible for the protection and proper use of the IT inventory.
- Desktop and laptop computers must be secured physically when not in use.
- If confidential information is stored on these devices, it must be deleted in a manner that cannot be recovered without the use of professional resources.
- Users are required to use the assets assigned to them properly, protect them from accidents, and refrain from using them inappropriately.
- Configuration changes to the IT inventory may only be made with the approval of the TGS Board of Directors.
- The responsibility for protecting laptops, smartphones, tablets, and similar devices against theft lies with the staff members to whom they are assigned.
- Data on portable devices such as laptops, smartphones, and tablets must be protected against theft through encryption and data destruction methods.
- Loss, theft, damage, unauthorized access, or similar security incidents related to the inventory must be reported to the TGS Secretary-General as soon as possible.
- The data destruction process must be carried out in accordance with TGS procedures.
ARTICLE 6: Email Management Policy
The email management process establishes the requirements for the proper and secure management of TGS’s email systems. This process covers the organization’s messaging systems and related third-party systems.
- Email addresses and mailboxes assigned to users by TGS must be used solely for business purposes. The use of personal email addresses is prohibited.
- Encryption must be performed in accordance with the standard established by TGS.
- The use of TGS resources for unauthorized advertising, non-business messaging, spam, political campaigns, and any other use contrary to business processes is prohibited.
- The email system shall not be used to transmit information classified as confidential. The transmission of confidential information via email must be conducted in a controlled and encrypted manner.
- TGS email systems must not be used for aggressive, racist, obscene, or unlawful purposes, or in violation of laws and regulations.
- Use of the TGS email system must be active while employees are working at the organization. User accounts must be deactivated in the event of termination of employment or resignation.
- TGS has the authority to access the content of TGS emails in the event of special investigations or inquiries.
ARTICLE 7: Internet Access Management Policy
The Internet access management process establishes the requirements for ensuring that Internet access conducted using TGS resources is carried out correctly and securely.
- Access to websites falling under the categories prohibited under Regulation No. 5651, titled “Procedures and Principles Regarding the Regulation of Publications Made on the Internet,” must be blocked. In this context, websites that violate the following provisions of the Turkish Penal Code No. 5237, dated September 26, 2004, will be banned:
Inciting suicide (Article 84),
Sexual abuse of children (Article 103, paragraph 1),
Facilitating the use of narcotic or psychotropic substances (Article 190),
Supplying substances hazardous to health (Article 194),
Obscenity (Article 226),
Prostitution (Article 227),
Providing premises and facilities for gambling (Article 228),
Law No. 5816 on Crimes Committed Against Atatürk, dated July 25, 1951
- Users must use the internet access, electronic, and instant messaging services provided by TGS for business purposes in accordance with the policies established by TGS.
- Users are obligated to conduct themselves in a manner consistent with TGS’s culture and reputation when using internet access.
- Internet traffic must be monitored at the firewalls. Any attacks or harassment that occur must be reported to the TGS Secretary-General.
- When using data obtained through Internet access, one must comply with intellectual property restrictions, personal data protection principles, privacy policies, terms of use, and the provisions of applicable laws and regulations.
ARTICLE 8: Malware Protection Management Policy
The malware protection management process covers desktop computers, laptops, smartphones, tablets, and other mobile devices used within the organization. Compliance with the relevant provisions is the responsibility of the user.
- All computers, laptops, and tablets at TGS must use a licensed antivirus system and be updated to the latest version.
- File types that may contain malicious software or harmful/mobile code, as well as sources hosting such file types, must be scanned by the antivirus system before being opened to ensure they are safe.
- Personal firewalls must be actively running to prevent attacks that mobile devices may be exposed to when accessing external networks.
ARTICLE 9: Policy on Ensuring Compliance with the Personal Data Protection Law
The Personal Data Protection Law No. 6698 (the “Law”), which entered into force upon its publication in the Official Gazette No. 29677 dated April 7, 2016, aims to protect the privacy of private life and the fundamental rights and freedoms of individuals, and to regulate the procedures and principles that natural and legal persons processing personal data must comply with. This Policy is intended to ensure compliance with the Act.
This process covers all information generated, processed, owned, or managed by the Union.
- Personal data must be processed in accordance with the procedures and principles set forth in the Act and other laws, and in a manner that does not infringe upon the Union’s legitimate interests or the right to unionize arising from the law.
- While ensuring that the Union’s legitimate interests and the right to unionize arising from relevant laws are not infringed upon, the rights of data subjects must be protected; the unlawful processing of and access to personal data must be prevented, and the security of personal data must be ensured.
- The transfer of personal data abroad, as well as its deletion, destruction, or anonymization, must be managed in accordance with the law.
- Existing contracts must be brought into compliance with the Law.
- The obligations to inform data subjects and obtain their explicit consent must be fulfilled.
- There must be a mechanism for evaluating and resolving data subjects’ requests.
- The union is exempt from the registration process with the Data Controllers Registry (VERBİS) in accordance with the Law and the Decision No. 2020/315 of the Personal Data Protection Board dated April 22, 2020.
- Administrative and technical measures must be taken to ensure the security of personal data.
- The process must be reviewed regularly, at least once a year.
ARTICLE 10: Outsourcing Management Policy
The outsourcing management process establishes the minimum security requirements necessary to ensure that secure services can be obtained from the supplier. This policy covers the structure under which the company outsources its IT services, functions, and processes, as well as the supplier.
- Outsourcing should be implemented only after risks and financial impact have been assessed.
- To protect the confidentiality of information to be shared with an external firm, it is recommended that a Confidentiality Agreement be signed, if possible, prior to commencing work with the firm.
- When selecting a service provider, reputation, experience with similar services, proposals, and guarantees are taken into consideration.
- Service providers are required to formally notify their own employees of their personal responsibility to act in accordance with the information security rules of the company they serve and to ensure compliance with these responsibilities.
