From the Directorate of Information Technology at MEF University:
MEF University has established the ISO/IEC 27001 Information Security Management System (ISMS) to ensure the robust implementation, operation, monitoring, review, and continuous improvement of information security across all our Higher Education Services. This system meets all the mandatory requirements prescribed by relevant information security laws, standards, and our internal procedures. Our foremost commitment is to safeguard all information assets and personal data used for University services, including data belonging to the institution itself, our students, personnel, suppliers, and solution partners.
In pursuit of this core objective, the management of MEF University pledges and commits to the following principles:
Protecting Information Assets: We will control all activities related to the storage, transmission, access, and processing of our assets by implementing best practices and ensuring in-process controls are established based on the principle of segregation of duties.
Ensuring Secure Access: We will provide secure access to information assets for our personnel, students, suppliers, and all stakeholders, while protecting information from unauthorized access.
Upholding Core Security Tenets: Adhering to the fundamental tenets of information security, confidentiality, integrity, and availability, we will prevent unauthorized or unwarranted access, use, modification, disclosure, deletion, transfer, or damage to our available information assets.
Maintaining Institutional Trust: We will implement and monitor information security activities designed to protect the University's credibility and reputation, and enforce necessary sanctions in the event of any security violation.
Managing Risk and Business Continuity: We will identify potential risks arising from security incidents and situations that could disrupt business continuity, and take prompt corrective action to prevent their occurrence.
Meeting Compliance Obligations: We will fulfill all legal and regulatory requirements stemming from applicable national and international regulations, meet contractual obligations, and satisfy information security needs arising from our corporate responsibilities to both internal and external stakeholders.
Continuous Improvement: We will establish internal control mechanisms to guarantee and continually enhance information security, aligning with this policy and the security objectives determined in line with the University's mission.
MEF University’s Information Security Policies are mandatory for and binding upon all MEF University personnel, whether full-time, part-time, permanent, or contracted, who use the University’s information or business systems, irrespective of their department or location. Any third parties requiring access to MEF University information who do not fall under these classifications, including students, service providers, and their supporting personnel, must comply with the general principles of this policy and all other specified security responsibilities and obligations.