Communiqué on the Procedures and Principles Regarding the Management of Information Systems
- Vardar Şanlı

- Mar 13, 2025
- 6 min read
The Communiqué on the Procedures and Principles Regarding the Management of Information Systems (the “Communiqué”), published in the Official Gazette dated March 13, 2025 and numbered 32840, sets forth the procedures and principles governing the management of information systems by certain institutions, organizations, andnpartnerships operating in the capital markets and financial sector. Entities subject to the Communiqué include Borsa Istanbul, the Central Securities Depository (Merkezi Kayıt Kuruluşu – MKK), portfolio custodians, capital market institutions, publicly held companies and crypto asset service providers (the “CASPs”). In the remainder of this article, you will find an overview of the principal obligations imposed under the Communiqué.
A. Responsibilities of the Board of Directors
Relevant institutions and organizations are required to establish a comprehensive Information Security Policy to ensure the security of their information systems. This policy must be prepared with the knowledge and approval of senior management and must be formally approved by the Board of Directors before becoming effective.
To ensure the secure, efficient, and continuous operation of information systems, the Board must implement appropriate control mechanisms and subject these systems to regular audits. Audit findings should be promptly assessed, and corrective actions taken without delay. Furthermore, an Information Systems Continuity Plan must be developed within the scope of a Board-approved Business Continuity Plan and activated when necessary.
Users with access to information systems must be regularly monitored, their access rights reviewed, and compliance with security standards ensured. In this context, the principle of segregation of duties has been adopted to reduce the risk of errors, omissions, or misuse. These measures are of strategic importance in safeguarding not only the technical but also the organizational integrity and continuity of information systems.
B. Information Systems Risk Management and Asset Inventory
Comprehensive risk management procedures must be established to identify, assess, monitor and report risks related to information systems. These procedures should be regularly reviewed to ensure the continuity of information security and must be updated when necessary, taking into account emerging threats, technological advancements, and changes in business processes. Institutions and organizations are also required to create and maintain an Information Asset Inventory that covers all information assets they possess, for the purpose of ensuring the secure and efficient management of their information systems. This inventory serves not only to identify assets but also as a fundamental tool for their protection, classification, and management. It must be kept continuously up to date, and include at a minimum the following information for each asset:
Description: Name of the information asset and a brief explanation.
Acquisition Date, Warranty, and Maintenance Information: The date on which the asset was acquired, warranty period, and any maintenance requirements.
License Information or Serial Number: License or serial number associated with the software or hardware asset.
Location: The physical or digital location where the asset is stored.
Owner: The person or unit responsible for the administrative management of the asset.
User: The individual or department actively using the asset.
Security Classification: The classification of the asset based on confidentiality, integrity, and availability requirements.
Backup Information: The location where the asset is backed up, the frequency of backups, and the environment in which the backups are stored.
C. Data Center Security Measure
Under the Communiqué, it is mandatory to implement high-level security measures at data centers where critical information systems are hosted. These measures must be enforced to prevent unauthorized access, ensure system continuity, and protect data security. Within this scope, the key security measures to be implemented in data centers are outlined as follows:
Multi-factor authentication: To access the system, users must authenticate using at least two different methods (e.g., password + biometric data). This is considered a fundamental security requirement, particularly for access to critical systems.
Uninterruptible power supply, climate control, fire and disaster protection: Physical infrastructure must be resilient against all types of outages and disasters. Accordingly, data centers must be equipped with uninterruptible power supplies for continuous energy, climate control systems for proper environmental conditions, fire suppression systems, and structural safeguards against natural disasters.
Surveillance and retention of camera footage: Data centers and secure zones must be monitored 24/7 via surveillance cameras, and the recorded footage must be retained for a minimum of one year. This allows for retrospective analysis in the event of a security breach or incident.
Confidentiality agreement for maintenance and repair personnel: External or temporary personnel assigned for maintenance or repair tasks in the data center must sign a confidentiality agreement acknowledging their obligation to protect information security. Such personnel must be accompanied by organization staff during their time on-site.
In addition, authentication procedures must be designed to align with the user’s access level and the security classification of the information systems being accessed. Authentication must remain continuously valid throughout the session and be managed accordingly.
D. Audit Trail Mechanism
Institutions and organizations must establish an effective audit trail system to monitor actions within information systems, maintain system integrity, and respond swiftly to potential security breaches. This mechanism is essential for ensuring both regulatory compliance and the smooth operation of systems. Key obligations include:
All system activities must be logged, capturing details such as user identity, time, accessed data, system or application used, outcomes, and any errors.
Logs must be stored securely and protected from unauthorized access or tampering, using encryption and integrity controls to prevent unauthorized changes or deletion.
Audit logs must be archived for at least five years and remain securely accessible for review when needed.
E. Penetration Testing and Internal Audit Obligations for Information Systems
Under the Communiqué, institutions and organizations are required to conduct regular testing and audits to ensure the security of their information systems. Two primary controls are mandated:
1. Penetration Testing
Institutions must undergo at least one penetration test per year, in line with the standards outlined in the annex of the Communiqué.
These tests must be performed by experts holding national or international certifications.
The test results must be documented in a report and submitted to the Capital Markets Board of Türkiye (CMB) by January 31 of the following year at the latest.
2. Internal Audit of Information Systems
Institutions are obligated to carry out at least one internal audit of their information systems annually.
These audits must be conducted in-house; outsourcing is not permitted under the Communiqué.
Audit findings must be compiled into a report and submitted to senior management.
An action plan addressing the identified issues must be developed and approved by senior management.
This action plan must be followed up in the next audit cycle to ensure continuous improvement of processes.
F. Domestic Hosting Requirement for Information Systems
Institutions and organizations are required to host both their primary (main operational) and secondary (backup) information system infrastructures within the borders of Türkiye. This requirement is of critical importance for ensuring information security, data integrity, and compliance with national regulations. Secondary systems must be designed to take over operations within no more than 24 hours in cases where the primary system becomes unavailable due to natural disasters, infrastructure outages, or other emergency scenarios. These backup systems must be located in geographically distinct areas that are not exposed to the same risks as the primary site.
Use of foreign cloud service providers is permitted only in limited and exceptional cases. For instance, crypto asset service providers may utilize foreign cloud infrastructure for systems that match client orders, provided that the service provider has a local representative office in Türkiye, and all system records are transferred to domestic infrastructure by the end of each day. This regulation aims to ensure that data remains protected under local legislation, enables swift response to cybersecurity threats, and facilitates oversight by competent authorities.
G. Transitional Provisions
CASPs are required to establish the necessary infrastructure to host their information systems within Türkiye by December 31, 2025, in line with domestic hosting obligations. Additionally, CASPs must comply with the requirement that individuals conducting internal audits of information systems hold a valid license by December 31, 2026. For all other institutions, organizations, and partnerships subject to the Communiqué, the licensing requirement for individuals performing information systems internal audits must be met by December 31, 2026, while compliance with all other provisions must be achieved by December 31, 2025. During this transition period, for all other institutionsthe Communiqué on Information Systems Management (Communiqué No. VII-128.9) published in the Official Gazette dated January 5, 2018 and numbered 30292 will remain in force, and relevant operations shall continue in accordance with the provisions of the former communiqué until the respective deadlines.


