Networks and systems
Servers, network components, security devices, storage, and communication infrastructure.

We turn the Guide requirements overseen by the Türkiye Cyber Security Directorate into a measurable program for public institutions and critical infrastructure operators, extending from assets and criticality to safeguards and audit evidence.
Assess your compliance scopeThe Information and Communication Security Guide is more than a standard checklist; it is a security framework that must be operated through the organization’s assets and risks.
Prepared in line with Presidential Circular No. 2019/12, the Guide aims to reduce information-security risks and protect critical data in public institutions and critical-infrastructure operators.
ION maps the requirements to the organization’s actual technology, processes, and responsibilities. Compliance therefore becomes an applicable and auditable program instead of documentation alone.
Visit the official information and guide pageThe Guide considers not only devices, but also the technology that processes information, the people who use it, and the physical environments that host the systems.
Servers, network components, security devices, storage, and communication infrastructure.
Business software, databases, web services, and applications supporting operational processes.
Laptops, mobile devices, and removable data-storage media.
Connected sensors, smart devices, and components that generate or process data.
Data centers, system rooms, offices, and archives that host information-processing capabilities.
Employees and stakeholders who use, manage, or have access to information-processing capabilities.
Criticality is determined by evaluating the information-security need of each asset group together with the potential organizational, sectoral, and societal impact of a breach.
Existing safeguards are compared with the Guide’s requirements so gaps, dependencies, and priorities become visible. An actionable roadmap then assigns ownership, timing, and evidence.
Legal, regulatory, and contractual requirements are also considered. The goal is to establish the right sequence based on risk and organizational capacity, not to begin every activity at once.
We group networks, systems, applications, portable media, IoT, physical spaces, and people, then map their critical dependencies.
Each group is evaluated against confidentiality, integrity, availability, and the organizational or societal impact of a breach.
Existing administrative and technical safeguards are compared with guide requirements to identify missing, partial, or weakly evidenced controls.
Training, procurement, development, hardening, upgrades, documentation, and process improvements are organized into a risk-based program.
We help maintain records, ownership, and monitoring mechanisms that demonstrate controls are actually operating.
Information-processing capabilities, people, locations, asset groups, and dependencies are identified.
Groups are rated and the operation and evidence level of current safeguards is assessed.
Gaps are ranked by business impact, risk, dependency, and feasibility.
Owners, timeline, resources, and evidence requirements are defined and progress is monitored.
It covers relevant public institutions and critical infrastructure operators. Exact scope and duties must be assessed for each organization.
No. It also covers people, business processes, and physical environments, requiring participation across the organization.
Confidentiality, integrity, availability, dependencies, affected population, and organizational or societal impact are evaluated together.
No. Gaps must be remediated, evidence produced, responsibilities operated, and controls continually improved.
Let’s review your scope and goals together and define the right working model for your organization.