TÜRKIYE Law and Practice Contributed by: Bora Yazıcıoğlu, Alper Işık, Emre Öntekin and Ferat Gümüş, YAZICIOGLU Legal
• reporting cyber incidents to their institutions, notifying the TR-CERT and their sectoral CERTs without delay; • primarily trying to eliminate a cyber incident inter - nally, and requesting assistance from the TR-CERT and their sectoral CERT, as applicable; • reporting suspected criminal activity to the compe - tent authorities and the TR-CERT without delay; • having 24/7-accessible contact information and notifying their sectoral CERTs and the TR-CERT thereof; • recording vulnerabilities; • monitoring the types, quantities and costs of cyber incidents; and • submitting to the management of the institution for corrective/preventative actions. The Sectoral CERTs, on the other hand, have the fol - lowing obligations: • co-ordinating with the TR-CERT to prevent or miti - gate incidents; • immediately notifying the TR-CERT of cyber inci - dents affecting their CERTs; • having 24/7-accessible contact information and notifying their CERTs and the TR-CERT thereof; • supporting their CERTs in cyber incidents; and • reporting suspected crimes to the competent authorities and the TR-CERT without delay. 5. Security Certification for ICT Products, Services and Processes 5.1 Key Cybersecurity Certification Legislation Currently, there is no general legal framework for the certification requirements of ICT products and ser - vices. However, there is sector-specific legislation with certification requirements. The Cybersecurity Act provides for certain certifica - tion requirements. According to the Cybersecurity Act, cybersecurity products, systems and services to be used in public institutions and organisations and criti - cal infrastructures have to be procured from cyberse - curity experts and companies that will be certified by the Directorate. Procurement from uncertified experts
or companies will be subject to an administrative fine of between TRY1,254,900 and TRY12,549,000. TS ISO/IEC 27001 Certificate In the e-communications and energy sector, and for e-invoice service providers, obtaining a TS ISO/IEC 27001 certificate is a de jure standard. However, many other organisations also choose to voluntarily com - ply with this standard as a good practice to improve cybersecurity. ICS Guide Compliance Audit Service Providing Personnel and Firm Certification Persons or firms auditing the public institutions and businesses providing critical infrastructure services are certified by a programme conducted by the DTO, Turkish Standards Institute and STRCT. The Financial Sector The BRSA requires all banks to meet Control Objec - tives for Information and Related Technologies (COBIT) standards. COBIT process management is also used in the finance and production sectors. The By-Law on Banking Cards and Credit Cards requires organisations entering into merchant agree - ments with banks to comply with the Payment Card Industry Data Security Standards (PCI DSS) stand - ards. According to the CMB’s Communiqué on Independ - ence Audit of Information Systems, auditors who audit publicly held companies must have a Certified Infor - mation System Auditor (CISA) certificate. The Healthcare Sector The By-Law on Health Information Management Sys - tems requires health information systems’ service pro - viders to have the following certificates: • TS ISO/IEC 27001; • TS ISO/IEC 15504 Software Process Improvement and Capability Determination (SPICE) certificate at a minimum of the second level, which is obtained from institutions and organisations with TS ISO/ IEC 17065 accreditation and include SPICE lead auditor; or
430 CHAMBERS.COM
Powered by FlippingBook