Compliance and Audit
ISMS Certification and Compliance Services
ONGSEC manages your organisation's compliance with national and international information security standards from beginning to end, providing both technical and advisory support throughout certification. Our approach aims not at p…
Scope of service
What we do under this heading
ISO/IEC 27001 Information Security Management System
Current state (gap) analysis and improvement roadmap; Scope definition, asset inventory and information classification…
VIEWInformation and Communication Security Guide (BİGR) Compliance
Defining asset groups and determining their criticality level; Gap analysis against the guide's measures and a priorit…
VIEWKVKK and GDPR Compliance Consultancy
Preparation of the personal data inventory and data flow map; Creating the record of processing activities and the VER…
VIEWSOC 2 Type I / Type II Consultancy
Readiness analysis against the Trust Services Criteria (TSC); Control design and establishment of evidence generation …
VIEWOther Standards and Sector Regulations
ISO 22301 Business Continuity Management System implementation and exercise programme; ISO/IEC 27017 and 27018 cloud s…
VIEWNIS2, DORA and Sector Regulations
Preparation and gap closure for organisations entering the European market or operating in regulated sectors.…
VIEWSupplier and Third-Party Risk Management
A significant share of breaches arrive through suppliers. Supplier risk is managed before and throughout the contract.…
VIEWISO 22301 Business Continuity and Disaster Recovery
Floods, fire and power loss stop a service just as a security incident does; the continuity plan addresses both.…
VIEWISO/IEC 27001 Information Security Management System
- Current state (gap) analysis and improvement roadmap
- Scope definition, asset inventory and information classification work
- Establishing a risk assessment methodology and preparing the risk treatment plan
- Preparing the Statement of Applicability (SoA) and control justification
- Preparation of policies, procedures, instructions and record documents
- Implementation of technical controls and linking evidence generation to the system
- Awareness training and enabling process owners
- Conducting internal audit and running the management review meeting
- Preparation for the certification body audit, audit attendance and nonconformity closure
- Preparation for post-certification surveillance audits and continual improvement support
Information and Communication Security Guide (BİGR) Compliance
- Defining asset groups and determining their criticality level
- Gap analysis against the guide's measures and a prioritised implementation plan
- Implementation of technical and administrative measures, creation of evidence files
- Audit preparation, evidence management and nonconformity remediation
- Periodic self-assessment and management reporting
KVKK and GDPR Compliance Consultancy
- Preparation of the personal data inventory and data flow map
- Creating the record of processing activities and the VERBİS notification
- Privacy notices, explicit consent forms and retention–destruction policy
- Assessment of technical and administrative data security measures
- Establishing the data breach response process and defining the notification workflow
- Assessment of cross-border data transfers and structuring of contractual safeguards
- Contractual regulation of controller / processor relationships
- Employee awareness training and periodic compliance audit
SOC 2 Type I / Type II Consultancy
- Readiness analysis against the Trust Services Criteria (TSC)
- Control design and establishment of evidence generation mechanisms
- Monitoring control operating effectiveness throughout the observation period
- Preparation for independent auditor processes and audit coordination
Other Standards and Sector Regulations
- ISO 22301 Business Continuity Management System implementation and exercise programme
- ISO/IEC 27017 and 27018 cloud security and personal data protection in the cloud
- ISO/IEC 27701 privacy information management system
- ISO 20000 IT service management and ITIL process adaptation
- NIST Cybersecurity Framework compliance assessment
- PCI DSS compliance consultancy and scope reduction work
- Mapping requirements for sector regulators (BDDK, SPK, BTK, EPDK)
- Compliance with security guides for the energy and critical infrastructure sectors
- Bringing multiple standards together under a single integrated management system
NIS2, DORA and Sector Regulations
Preparation and gap closure for organisations entering the European market or operating in regulated sectors.
- NIS2 scope assessment and obligation mapping
- IT risk and third-party management under DORA
- Gap analysis against BDDK, EPDK and SPK regulations
- Process design aligned to incident notification deadlines
- Board accountability and reporting framework
Supplier and Third-Party Risk Management
A significant share of breaches arrive through suppliers. Supplier risk is managed before and throughout the contract.
- Supplier inventory and criticality classification
- Security assessment questionnaire and evidence requests
- Security and notification clauses added to contracts
- Minimising and monitoring the scope of access
- Periodic reassessment and an offboarding process
ISO 22301 Business Continuity and Disaster Recovery
Floods, fire and power loss stop a service just as a security incident does; the continuity plan addresses both.
- Business impact analysis (BIA) and critical process prioritisation
- RTO / RPO targets agreed with business units
- Drafting of continuity and disaster recovery plans
- Alternative work site and communication plan
- A cycle of drills, measurement and plan updates
Data Breach Response and Notification
Under KVKK a breach must be notified to the Authority as soon as possible and within 72 hours; the process is built in advance.
- Breach detection, classification and decision criteria
- Notification templates for the Authority and data subjects
- Evidence collection and preservation of integrity
- Division of duties between legal, communications and technical teams
- A breach register and the file to be presented at audit
On this page
- ISO/IEC 27001 Information Security Management System
- Information and Communication Security Guide (BİGR) Compliance
- KVKK and GDPR Compliance Consultancy
- SOC 2 Type I / Type II Consultancy
- Other Standards and Sector Regulations
- NIS2, DORA and Sector Regulations
- Supplier and Third-Party Risk Management
- ISO 22301 Business Continuity and Disaster Recovery
- Data Breach Response and Notification
Typical deliverables
- Gap analysis
- Risk register
- Document set
- Internal audit report
- Audit evidence pack
Let us define the scope together
A short discovery call is enough to identify the slice of this portfolio you actually need.
Request a quoteRelated services
What usually runs alongside this
Log Management, Turkish Law 5651 Compliance and Time Stamping
Traffic records collected accurately, sealed with a time stamp, retained for the statutory period and presented at audit.
EXPLORE Compliance and AuditCyber Security Maturity Model and Strategy
Objective measurement of cyber security maturity, a prioritised roadmap and turnkey transformation.
EXPLORE Critical InfrastructureData Centre Consultancy, Feasibility and Design
We shape data centre investment from feasibility to tender documentation with independent engineering judgement.
EXPLOREGet started
Let us talk about your project.
The first meeting is a discovery session, not a sales pitch. You are also welcome to evaluate our capability directly through a short pilot or proof of concept (PoC) in your own environment.