Consulting Services

We provide ISO 27001, KVKK and BİG Guide compliance consulting.

Information & Communication Security Guide

Information and Communication Security Guide Consulting Service

The Information and Communication Security (BİG) Guide sets out the information and communication security measures that public institutions and operators providing critical infrastructure services must comply with.

The BİG Guide was prepared under Presidential Circular No. 2019/12 of 06.07.2019, coordinated by the Presidency of the Digital Transformation Office (DDO) of the Republic of Türkiye, and approved on 24.07.2020.

The Information and Communication Security Guide and the Information and Communication Security Audit Guide

Compliance with the measures in the Guide is mandatory for existing and new information systems at all public institutions and organizations and at operators providing critical infrastructure services.

Existing IT infrastructures are expected to be brought into line with these principles gradually, within the plan set out in the Guide and according to their security level priorities.

The benefits targeted by the Guide can only be achieved and sustained through effective audit and oversight.

To this end, the Presidency of the Digital Transformation Office prepared the Information and Communication Security Audit Guide to guide institutions and organizations in carrying out audits.

Public institutions and organizations and operators providing critical infrastructure services are expected to complete their compliance activities within the period specified in the Guide, and to carry out audits at least once a year to determine whether the activities performed and measures taken are adequate.

Our Information and Communication Security Guide compliance consulting follows these steps:

  • Classifying the organization’s assets in line with the Guide’s principles
  • Dividing the classified assets into appropriate sub-groups
  • Determining the criticality levels of the classified and grouped assets
  • Identifying the relevant application and technology areas and hardening measures for every asset group, and the Guide articles each group is subject to
  • Performing a gap analysis by examining how well each asset group meets the requirements of the articles it is subject to
  • Creating a work plan for the paths and methods to follow to achieve compliance with the Guide
  • Defining compensating controls
  • Planning and running awareness activities for the Guide
  • Evaluating the results of the penetration tests to be performed
  • Evaluating the results of technical checks performed or commissioned during the work
  • Supporting the organization’s auditors with planning for compliance audits
  • Implementing the audit plans
  • Evaluating the audit findings
  • Preparing and reviewing the audit reports and the related audit guide annexes

ISO 27001 Consulting

Our ISO 27001 Consulting Service

The ISO 27001:2022 Information Security Management System (ISMS) provides an international framework that ensures companies protect their financial data, intellectual property and sensitive customer information.

Organizations that establish an ISO 27001:2022 ISMS can identify and manage their information security risks, and so prevent unwanted incidents or minimize their impact.

Applied consistently, an ISO 27001:2022 system protects your company’s reputation and gives your customers and stakeholders confidence.

CenterOnDigital’s ISO 27001 Consulting Method

Our ISO 27001:2022 consulting methodology consists of the following phases:

1. Preparation

In the preparation phase, the scope of the ISO 27001:2022 ISMS project is defined, the project team is oriented through information security training, and the organization’s management support is made concrete.

2. Planning

In the planning phase, a gap analysis is carried out to collect information on the organization’s business and legal requirements for information security, its IT infrastructure and its information security control points. Once the organization’s valuable assets are identified, an ISO 27001:2022 risk analysis establishes the current state and determines the needs for developing and improving controls.

3. Implementation

In this step, the ISMS components covering management processes (policies, procedures, guidelines, etc.) and the controls found lacking in the risk analysis are developed and put into practice. Staff receive information security awareness training tailored to the organization’s needs.

4. Checking

An internal audit is carried out covering the whole of the ISO 27001:2022 standard and part of ISO 27002:2022, “Information Security Controls”. Management review steps identify the need for corrective and preventive actions.

5. Acting

In this final step of our ISO 27001 consulting, the necessary improvement plans are implemented in line with the corrective and preventive action requirements identified and reported by the various parties.

Cybersecurity

KVKK Consulting

Our KVKK Process Management, Legal and Technical Consulting Service

Protecting the privacy of personal data, such as a person’s identity, contact, health and financial information, private life, religious beliefs and political views, is a legal obligation for organizations.

Personal data is frequently processed by automated means through IT systems, in both the private and the public sector.

While using this information brings convenience and advantages for individuals and for providers of goods and services, it also brings the risk of the information being misused.

With our experienced team, we provide legal and technical consulting on KVKK (Turkey’s Personal Data Protection Law) process management and auditing.

KVKK Compliance Process Management Software

With the CenterOnDigital KVKK Compliance Process Management Software, developed as part of our in-house R&D, you can manage your organization’s KVKK processes easily, quickly and effectively.

Based on the organization’s personal data processing activities, the application builds a legally compliant Personal Data Inventory and automates data management processes, saving time, cost and workload.

KVKK software login screenKVKK software dashboardKVKK software data types listKVKK software personal data processing inventory

Our Other Services

Our Accreditations