TÜRKIYE Law and Practice Contributed by: Bora Yazıcıoğlu, Alper Işık, Emre Öntekin and Ferat Gümüş, YAZICIOGLU Legal
• conducting security clearances for personnel of critical importance; and • requiring communication service providers to establish internet exchange points in Türkiye. For comprehensive measures, the Presidency Decree refers to the ICS Guide, which provides the following for critical infrastructure security in public entities and businesses providing critical infrastructure services: • network and system security measures; • application and data security measures; • portable device and media security measures; • IoT devices security measures; • personnel security measures; and • physical environment security measures. The ICS Guide also provides: • a roadmap for compliance; • responsible personnel for each process of compli - ance; • guidance on categorising asset groups and deter - mining critical assets; • measures required for supply chain security; • measures required for threat and vulnerability man - agement; and • measures required for disaster recovery and busi - ness continuity. The ICS Guide also prescribes security measures for the e-communications and energy sectors. There are also other sector-specific regulations governing critical infrastructure cybersecurity, which are detailed below. E-Communications Sector Security measures to be taken by actors in the e-com - munications sector in accordance with the ICS Guide include the following: • service security and continuity; • signalling traffic security; • establishing trusted communication; • ensuring equipment security; • threat intelligence management; • communication with authorities; • prevention of caller ID manipulation; and
• ensuring that domestic communication traffic remains within the country. The By-Law on NIS in the E-Communications Sector requires operators to prepare a report on NIS annually – until the end of March – and to retain it for five years, to be submitted to ICTA upon request and/or during inspections. The report includes information such as details on information security breach incidents that have occurred. Per the By-Law, operators cannot allow unlicensed software and software violating Information Security Management Systems Policy rules. They must pro - tect information and software against harmful codes, and identify security measures for external networks downloads. Operators must also define and docu - ment rules related to the software’s transfer from the development environment to the production environ - ment. Energy Sector Actors in the energy sector must take the following security measures per the ICS Guide: • device configurations; • network, physical and user access management; • authentication; • ensuring system continuity; • prevention of data manipulation; • SSL/TLS protected communication; • security of GPS communication and synchronisa - tion; • ensuring equipment security; • threat intelligence management; • communication with authorities; and • using safe methods for data transmission. The competency model under the By-Law on Cyber - security Competency Model in the Energy Sector sets out three basic competency levels. The applica - ble competency level that must be implemented by obligated organisations will be identified with sectoral criticality degrees determined by the EMRA. Banking and Finance Sector Banks and other financial institutions under the authority of the BRSA must take the measures out -
423 CHAMBERS.COM
Powered by FlippingBook