Information and Communication Security Guide Compliance

We turn the Guide requirements overseen by the Türkiye Cyber Security Directorate into a measurable program for public institutions and critical infrastructure operators, extending from assets and criticality to safeguards and audit evidence.

Assess your compliance scope

Read the safeguards.
Adapt them to your organization.

The Information and Communication Security Guide is more than a standard checklist; it is a security framework that must be operated through the organization’s assets and risks.

Prepared in line with Presidential Circular No. 2019/12, the Guide aims to reduce information-security risks and protect critical data in public institutions and critical-infrastructure operators.

ION maps the requirements to the organization’s actual technology, processes, and responsibilities. Compliance therefore becomes an applicable and auditable program instead of documentation alone.

Visit the official information and guide page

The Guide considers not only devices, but also the technology that processes information, the people who use it, and the physical environments that host the systems.

See the asset first.
Then select the safeguard.

Networks and systems

Servers, network components, security devices, storage, and communication infrastructure.

Applications

Business software, databases, web services, and applications supporting operational processes.

Portable devices and media

Laptops, mobile devices, and removable data-storage media.

Internet of Things

Connected sensors, smart devices, and components that generate or process data.

Physical locations

Data centers, system rooms, offices, and archives that host information-processing capabilities.

Personnel

Employees and stakeholders who use, manage, or have access to information-processing capabilities.

Not every asset
is equally critical.

Criticality is determined by evaluating the information-security need of each asset group together with the potential organizational, sectoral, and societal impact of a breach.

Information-security need
Confidentiality
The need to protect information against unauthorized access.
Integrity
The need to preserve the completeness and accuracy of information.
Availability
The need for authorized users to access information when required.
Breach impact area
  • Impact on dependent assets
  • Number of people affected
  • Organizational consequences
  • Sectoral impact
  • Societal consequences

Find the gap.
Turn it into a roadmap.

Existing safeguards are compared with the Guide’s requirements so gaps, dependencies, and priorities become visible. An actionable roadmap then assigns ownership, timing, and evidence.

Legal, regulatory, and contractual requirements are also considered. The goal is to establish the right sequence based on risk and organizational capacity, not to begin every activity at once.

  • Capability building and training
  • Product or service procurement
  • Development and redevelopment
  • Design and redesign
  • System hardening
  • Version upgrades
  • Documentation
  • Organizational process improvement

Information and Communication Security Guide Compliance

Asset groups and dependencies

We group networks, systems, applications, portable media, IoT, physical spaces, and people, then map their critical dependencies.

Criticality rating

Each group is evaluated against confidentiality, integrity, availability, and the organizational or societal impact of a breach.

Safeguard and gap analysis

Existing administrative and technical safeguards are compared with guide requirements to identify missing, partial, or weakly evidenced controls.

Implementation roadmap

Training, procurement, development, hardening, upgrades, documentation, and process improvements are organized into a risk-based program.

Audit evidence and sustainability

We help maintain records, ownership, and monitoring mechanisms that demonstrate controls are actually operating.

Clear steps.
Measurable progress.

  1. Scope and asset discovery

    Information-processing capabilities, people, locations, asset groups, and dependencies are identified.

  2. Criticality and current state

    Groups are rated and the operation and evidence level of current safeguards is assessed.

  3. Gap prioritization

    Gaps are ranked by business impact, risk, dependency, and feasibility.

  4. Implementation and audit readiness

    Owners, timeline, resources, and evidence requirements are defined and progress is monitored.

What we deliver

  • Scope and asset-group workset
  • Dependency and criticality assessment
  • Guide safeguard gap analysis
  • Risk-prioritized action list
  • Owned implementation roadmap
  • Control evidence and audit-readiness model
  • Monitoring and improvement recommendations

Frequently asked
questions.

Who is covered by the Information and Communication Security Guide?

It covers relevant public institutions and critical infrastructure operators. Exact scope and duties must be assessed for each organization.

Is Guide compliance only an IT responsibility?

No. It also covers people, business processes, and physical environments, requiring participation across the organization.

How is asset criticality determined?

Confidentiality, integrity, availability, dependencies, affected population, and organizational or societal impact are evaluated together.

Does compliance end after the gap analysis?

No. Gaps must be remediated, evidence produced, responsibilities operated, and controls continually improved.

Guide ComplianceLet’s discuss your needs.

Let’s review your scope and goals together and define the right working model for your organization.