KYT.FR.05
1. PURPOSE AND SCOPE
This policy has been prepared to ensure that the information systems strategies of Mistral Gayrimenkul Yatırım Ortaklığı A.Ş. are aligned with its business objectives so that it can maintain its operations in a stable, competitive, evolving and secure structure, and to ensure the confidentiality, integrity and, where necessary, availability of information in relation to the establishment, operation, management and use of information systems.
This document covers;
Due to the capital markets and real estate investment trust sector in which it operates, Mistral GYO A.Ş. has adopted full compliance with the legislation issued by all relevant regulatory and supervisory authorities, primarily the Capital Markets Board (CMB), as a fundamental principle.
In this context, information systems management is structured within the framework of;
In order to carry out information security processes effectively, the Company procures information security consultancy, cyber security controls, penetration testing and technical security services from expert external service providers.
Confidentiality, data security and regulatory compliance obligations are clearly defined in the contracts concluded with external service providers. Even where operational activities related to information systems are carried out through external services, ultimate responsibility and oversight rest with Company Management.
Data belonging to the Company’s information systems are backed up in accordance with the 3-2-1 backup rule.
In this context:
Backup processes are managed by the external service provider and checked periodically. Restore tests from backups are performed at regular intervals.
Within the current infrastructure, system logs can only be retained for as long as the capacity of the relevant devices themselves allows.
Separate logging software and a log server are required for long-term and centralized logging under Law No. 5651 and the Personal Data Protection Law (KVKK). As the current infrastructure does not include the virtualization and server environment to support this structure, centralized logging cannot be implemented.
This situation is monitored as a controlled risk within the scope of the information systems risk assessment and will be re-evaluated if an infrastructure investment is made.
Access to the Company’s information systems from outside the company is provided only via VPN and through encrypted connections. Unauthorized remote access methods are prohibited.
Some server operating systems used within the Company have reached end of vendor support or can only receive limited security updates. For this reason, current security patches and antivirus software may not be applied at the desired level.
This situation has been recorded within the scope of information security risk management, and it is aimed to be remedied if an infrastructure renewal and virtualization investment is made.
Risks related to information systems are assessed at least once a year. The Company’s information systems may be subjected to penetration testing at least once a year by competent and independent organizations.
The Company adopts the following information security principles:
All employees and external service provider personnel are obliged to comply with these policies.
Disciplinary procedures are applied to employees who act contrary to the provisions of this policy, depending on the nature of the violation. Where necessary, the matter is reported to the competent authorities. These practices are carried out in order to ensure the continuity of information security and compliance with the legislation.