Information Security Policy

 

KYT.FR.05

1. PURPOSE AND SCOPE

This policy has been prepared to ensure that the information systems strategies of Mistral Gayrimenkul Yatırım Ortaklığı A.Ş. are aligned with its business objectives so that it can maintain its operations in a stable, competitive, evolving and secure structure, and to ensure the confidentiality, integrity and, where necessary, availability of information in relation to the establishment, operation, management and use of information systems.

This document covers;

  • The definition of the roles and responsibilities required for the operation of information security processes,
  • The establishment of processes for managing risks related to information systems,
  • The establishment and oversight of the necessary controls.
  1. REGULATORY COMPLIANCE FRAMEWORK

Due to the capital markets and real estate investment trust sector in which it operates, Mistral GYO A.Ş. has adopted full compliance with the legislation issued by all relevant regulatory and supervisory authorities, primarily the Capital Markets Board (CMB), as a fundamental principle.

In this context, information systems management is structured within the framework of;

  • The Communiqué on Procedures and Principles Regarding Information Systems Management (VII-128.10),
  • The Capital Markets Law No. 6362.
  1. EXTERNAL SERVICE PROVIDERS

In order to carry out information security processes effectively, the Company procures information security consultancy, cyber security controls, penetration testing and technical security services from expert external service providers.

Confidentiality, data security and regulatory compliance obligations are clearly defined in the contracts concluded with external service providers. Even where operational activities related to information systems are carried out through external services, ultimate responsibility and oversight rest with Company Management.

  1. ACQUISITION, DEVELOPMENT AND MAINTENANCE OF INFORMATION SYSTEMS
  • Information systems are planned in line with the Company’s scale and activities.
  • Vendor-independent, widely used and sustainable technologies are preferred.
  • Hardware, operating systems and applications are covered by periodic maintenance.
  • Updates and changes are carried out in a controlled manner.
  • Development, test and production environments are separated from each other.
  1. DATA BACKUP AND RECOVERY PROCESSES

Data belonging to the Company’s information systems are backed up in accordance with the 3-2-1 backup rule.

In this context:

  • Primary data are kept in the production environment,
  • Secondary copies are kept on local NAS storage,
  • Tertiary copies are kept in the cloud in immutable form.

Backup processes are managed by the external service provider and checked periodically. Restore tests from backups are performed at regular intervals.

  1. LOG MANAGEMENT AND RECORDS

Within the current infrastructure, system logs can only be retained for as long as the capacity of the relevant devices themselves allows.

Separate logging software and a log server are required for long-term and centralized logging under Law No. 5651 and the Personal Data Protection Law (KVKK). As the current infrastructure does not include the virtualization and server environment to support this structure, centralized logging cannot be implemented.

This situation is monitored as a controlled risk within the scope of the information systems risk assessment and will be re-evaluated if an infrastructure investment is made.

  1. ACCESS AND REMOTE CONNECTION SECURITY

Access to the Company’s information systems from outside the company is provided only via VPN and through encrypted connections. Unauthorized remote access methods are prohibited.

  1. OPERATING SYSTEM AND ENDPOINT SECURITY

Some server operating systems used within the Company have reached end of vendor support or can only receive limited security updates. For this reason, current security patches and antivirus software may not be applied at the desired level.

This situation has been recorded within the scope of information security risk management, and it is aimed to be remedied if an infrastructure renewal and virtualization investment is made.

  1. RISK MANAGEMENT AND AUDIT

Risks related to information systems are assessed at least once a year. The Company’s information systems may be subjected to penetration testing at least once a year by competent and independent organizations.

  1. FUNDAMENTAL INFORMATION SECURITY PRINCIPLES

The Company adopts the following information security principles:

  • Confidentiality
  • Integrity
  • Availability

All employees and external service provider personnel are obliged to comply with these policies.

  1. NON-COMPLIANCE AND DISCIPLINE

Disciplinary procedures are applied to employees who act contrary to the provisions of this policy, depending on the nature of the violation. Where necessary, the matter is reported to the competent authorities. These practices are carried out in order to ensure the continuity of information security and compliance with the legislation.