Information Security Unit


Duties and Authorities

The Information Security Unit is a technical unit responsible for the protection of institutional information assets, the implementation and auditing of information security policies, and the management of cybersecurity processes.

Focus
Cybersecurity
Scope
Institutional
Approach
Preventive & Auditing
🔐

Information Classification

To classify institutional information assets according to criticality and sensitivity levels based on confidentiality, integrity, and availability principles, and to ensure the implementation of necessary information security controls.

📘

ISCG Management

To implement the principles, processes, and roadmap defined within the scope of the Information Security and Communication Guide (ISCG), conduct ISCG audit activities, and report the results.

📄

Policy & Procedure Management

To prepare, keep up to date, implement, and audit information security policies, procedures, and instructions in accordance with the ISO/IEC 27001 standard.

🕵️‍♂️

Audit Findings Management

To plan, implement, and monitor necessary corrective and preventive actions for findings identified during information technology and information security audits conducted by internal and external audit bodies.

⚠️

USOM & SOME Notifications

To evaluate cybersecurity vulnerabilities reported by USOM, the SOME Communication Platform, and the Presidential Digital Transformation Office, ensure necessary measures are taken, and monitor the process.

🧭

Business Continuity & Emergency Management

To plan and coordinate business continuity activities related to emergency and crisis scenarios within the scope of information security.

💾

Backup & Recovery

To prepare, implement, test, and audit backup, restore, business continuity, and disaster recovery plans related to institutional information systems.

🛡️

Cybersecurity Audits

To periodically audit information technology processes, information systems, and the software life cycle in line with cybersecurity requirements.

🎓

Awareness Trainings

To prepare training and informational content and carry out activities aimed at increasing information security awareness among academic and administrative staff and users.

📌

Other Duties

To perform other information security-related duties assigned by applicable legislation and senior management.

📍
Where is the Directorate?
Boğaziçi University Kandilli Campus
Kandilli Neighborhood, Rasathane St. No:104 Floor:2, 34684 Üsküdar / Istanbul