Our Information Security Policy

MAVSAN is committed to establishing, implementing, maintaining, and continually improving its Information Security Management System (ISMS) to ensure the confidentiality, integrity, and availability of its information assets. In this context, we are committed to:

  • Identify the information security requirements of relevant interested parties, assess associated risks, and implement the necessary controls based on comprehensive risk analysis.
  • Develop, implement, and communicate policies, procedures, and guidelines to ensure that information security risks related to the ISMS are effectively managed and kept under control.
  • Enhance employees' awareness of information security through ongoing training, communication, and awareness initiatives.
  • Maintain an adequate number of qualified personnel for the Information Security Management System (ISMS) and continuously enhance the knowledge and competencies of existing staff.
  • Encourage, guide, and support employees to actively contribute to the effectiveness and continual improvement of the Information Security Management System (ISMS).
  • Support management roles related to the Information Security Management System (ISMS), enabling leaders to demonstrate effective leadership within their areas of responsibility.
  • Ensure that the resources required for the Information Security Management System (ISMS) are allocated at an acceptable level, based on the outcomes of information security risk assessments.
  • Identify, classify, and maintain an inventory of the organization's information assets.
  • Analyzing the risks associated with information assets,
  • Selecting and implementing appropriate controls related to the analyzed risks,
  • Establish and continually maintain a Statement of Applicability (SoA) by mapping the selected security controls to the controls defined in ISO/IEC 27001:2013 Annex A, ensuring their relevance and ongoing improvement.
  • Regularly measure the performance of implemented security controls to evaluate and ensure their effectiveness.
  • Conduct regular internal audits of the Information Security Management System (ISMS) to ensure its ongoing compliance, effectiveness, and continual improvement.
    Ensure that corrective actions and preventive measures related to identified nonconformities are implemented promptly and without unnecessary delay.
  • Commits to improving the ISMS by conducting regular Management Review Meetings.

As with all of our corporate activities, the Information Security Management System (ISMS) is operated in accordance with the principles of independence, integrity, impartiality, confidentiality, and reliability. All employees and third-party personnel are required to comply with the policies, procedures, and documentation within the management system in line with their respective roles and responsibilities.

WhatsApp