In order to ensure the continuous development of our Information security management system within our organization: Identifying the information assets of these assets, Impact on the business: addressing issues such as the cost of replacing the asset, confidentiality of the information, its effect on the image, the damage it will cause in terms of legal and legal obligations, Possibility of threat: the multitude of weaknesses and how well existing controls can cover these weaknesses, attacker motivation, attractiveness of information to competitors, gaps in access controls and threats to the integrity of information, To identify and evaluate risks related to the confidentiality, integrity and access of information, To establish the necessary controls for all assets above the acceptable level. We undertake to implement, measure the performance of information security processes, produce targets from these data, minimize our weaknesses and threats through infrastructure, working environment, hardware, software and training investments, and meet the security requirements required by our business, customers and legal conditions. Policies are reviewed at management review meetings and revised as necessary in line with the determined goals. When determining policies in information security; It is also explained that confidentiality, integrity and accessibility will be taken as basis when processing, transmitting and preserving information, and the risk management approach is also emphasized.