Compliance and Audit
Log Management, Turkish Law 5651 Compliance and Time Stamping
Turkish Law No. 5651 requires organisations that provide internet access to record traffic data accurately, protect its integrity with a time stamp and retain it for a defined period. ONGSEC turns that obligation into a working sy…
Scope of service
What we do under this heading
Scope and Obligation Assessment
We first determine in what capacity the organisation is liable; requirements differ for hosting, access and mass-use p…
VIEWLog Collection and a Trusted Time Source
The evidential value of a record depends on an accurate, provable time source. The collection layer is designed so tha…
VIEWIntegrity, Signing and Time Stamping
A record becomes evidence only if it can be shown not to have been altered, which puts hashing and qualified time stam…
VIEWRetention, Archiving and Disposal
Records are retained for the period the law requires and then destroyed under record. Indefinite retention is itself a…
VIEWQuery, Reporting and Presentation at Audit
When a request arrives, the record must be found within minutes and handed over in a verifiable form.…
VIEWIntegration with Security Operations
The records collected for compliance are also used for detection and response, without a second investment.…
VIEWScope and Obligation Assessment
We first determine in what capacity the organisation is liable; requirements differ for hosting, access and mass-use providers.
- Determination and justification of the organisation’s legal capacity
- Inventory of in-scope systems, links and user groups
- Derivation of retention period and record content requirements
- Assessment of guest network, wireless and hotspot scenarios
- Gap analysis of the current state and a roadmap
Log Collection and a Trusted Time Source
The evidential value of a record depends on an accurate, provable time source. The collection layer is designed so that nothing is lost.
- Collection of firewall, proxy, NAC and DHCP records
- NTP infrastructure synchronised to a national time source
- Clock drift monitoring with alerting
- Detection of missing records and monitoring of collection continuity
- Resolution of user-to-IP mapping, including behind NAT
- Normalisation of record formats and field mapping
Integrity, Signing and Time Stamping
A record becomes evidence only if it can be shown not to have been altered, which puts hashing and qualified time stamping at the centre of the chain.
- Hashing and signing of log files
- Integration with a qualified electronic time stamp service
- Time stamp verification and periodic re-stamping
- Immutable (WORM) storage
- Access logging and four-eyes authorisation
- Automatic generation of integrity verification reports
Retention, Archiving and Disposal
Records are retained for the period the law requires and then destroyed under record. Indefinite retention is itself a risk.
- Tiered hot, warm and cold storage architecture
- Capacity planning and growth forecasting
- Backup, secondary copy and disaster scenarios
- Recorded disposal of expired data
- Joint management of KVKK and Law 5651 retention periods
Query, Reporting and Presentation at Audit
When a request arrives, the record must be found within minutes and handed over in a verifiable form.
- Response workflow for judicial and regulatory requests
- Fast querying by user, IP, time range and destination
- Export together with a verification digest
- Report templates ready for audit
- Logging of the query operations themselves
Integration with Security Operations
The records collected for compliance are also used for detection and response, without a second investment.
- Consumption of the same log pool by the SIEM
- Security use cases derived from compliance records
- Detection of anomalous access and data egress
- Timeline construction during incident response
- Provision of evidence for forensic examination
On this page
Typical deliverables
- Obligation and scope report
- Logging architecture document
- Time stamp verification report
- Retention and disposal policy
- Audit evidence pack
Let us define the scope together
A short discovery call is enough to identify the slice of this portfolio you actually need.
Request a quoteRelated services
What usually runs alongside this
ISMS Certification and Compliance Services
From ISO 27001 certification to KVKK and GDPR compliance, from SOC 2 to sector regulation.
EXPLORE Compliance and AuditCyber Security Maturity Model and Strategy
Objective measurement of cyber security maturity, a prioritised roadmap and turnkey transformation.
EXPLORE Critical InfrastructureData Centre Consultancy, Feasibility and Design
We shape data centre investment from feasibility to tender documentation with independent engineering judgement.
EXPLOREGet started
Let us talk about your project.
The first meeting is a discovery session, not a sales pitch. You are also welcome to evaluate our capability directly through a short pilot or proof of concept (PoC) in your own environment.