Compliance and Audit

ISMS Certification and Compliance Services

ONGSEC manages your organisation's compliance with national and international information security standards from beginning to end, providing both technical and advisory support throughout certification. Our approach aims not at p…

ISO/IEC 27001KVKKGDPRSOC 2PCI DSSBİGR
01

ISO/IEC 27001 Information Security Management System

  • Current state (gap) analysis and improvement roadmap
  • Scope definition, asset inventory and information classification work
  • Establishing a risk assessment methodology and preparing the risk treatment plan
  • Preparing the Statement of Applicability (SoA) and control justification
  • Preparation of policies, procedures, instructions and record documents
  • Implementation of technical controls and linking evidence generation to the system
  • Awareness training and enabling process owners
  • Conducting internal audit and running the management review meeting
  • Preparation for the certification body audit, audit attendance and nonconformity closure
  • Preparation for post-certification surveillance audits and continual improvement support
02

Information and Communication Security Guide (BİGR) Compliance

  • Defining asset groups and determining their criticality level
  • Gap analysis against the guide's measures and a prioritised implementation plan
  • Implementation of technical and administrative measures, creation of evidence files
  • Audit preparation, evidence management and nonconformity remediation
  • Periodic self-assessment and management reporting
03

KVKK and GDPR Compliance Consultancy

  • Preparation of the personal data inventory and data flow map
  • Creating the record of processing activities and the VERBİS notification
  • Privacy notices, explicit consent forms and retention–destruction policy
  • Assessment of technical and administrative data security measures
  • Establishing the data breach response process and defining the notification workflow
  • Assessment of cross-border data transfers and structuring of contractual safeguards
  • Contractual regulation of controller / processor relationships
  • Employee awareness training and periodic compliance audit
04

SOC 2 Type I / Type II Consultancy

  • Readiness analysis against the Trust Services Criteria (TSC)
  • Control design and establishment of evidence generation mechanisms
  • Monitoring control operating effectiveness throughout the observation period
  • Preparation for independent auditor processes and audit coordination
05

Other Standards and Sector Regulations

  • ISO 22301 Business Continuity Management System implementation and exercise programme
  • ISO/IEC 27017 and 27018 cloud security and personal data protection in the cloud
  • ISO/IEC 27701 privacy information management system
  • ISO 20000 IT service management and ITIL process adaptation
  • NIST Cybersecurity Framework compliance assessment
  • PCI DSS compliance consultancy and scope reduction work
  • Mapping requirements for sector regulators (BDDK, SPK, BTK, EPDK)
  • Compliance with security guides for the energy and critical infrastructure sectors
  • Bringing multiple standards together under a single integrated management system
06

NIS2, DORA and Sector Regulations

Preparation and gap closure for organisations entering the European market or operating in regulated sectors.

  • NIS2 scope assessment and obligation mapping
  • IT risk and third-party management under DORA
  • Gap analysis against BDDK, EPDK and SPK regulations
  • Process design aligned to incident notification deadlines
  • Board accountability and reporting framework
07

Supplier and Third-Party Risk Management

A significant share of breaches arrive through suppliers. Supplier risk is managed before and throughout the contract.

  • Supplier inventory and criticality classification
  • Security assessment questionnaire and evidence requests
  • Security and notification clauses added to contracts
  • Minimising and monitoring the scope of access
  • Periodic reassessment and an offboarding process
08

ISO 22301 Business Continuity and Disaster Recovery

Floods, fire and power loss stop a service just as a security incident does; the continuity plan addresses both.

  • Business impact analysis (BIA) and critical process prioritisation
  • RTO / RPO targets agreed with business units
  • Drafting of continuity and disaster recovery plans
  • Alternative work site and communication plan
  • A cycle of drills, measurement and plan updates
09

Data Breach Response and Notification

Under KVKK a breach must be notified to the Authority as soon as possible and within 72 hours; the process is built in advance.

  • Breach detection, classification and decision criteria
  • Notification templates for the Authority and data subjects
  • Evidence collection and preservation of integrity
  • Division of duties between legal, communications and technical teams
  • A breach register and the file to be presented at audit

Get started

Let us talk about your project.

The first meeting is a discovery session, not a sales pitch. You are also welcome to evaluate our capability directly through a short pilot or proof of concept (PoC) in your own environment.

Fill in the enquiry form

WhatsApp