- Job title
- Customer service representative
- Sector
- Leather
- Organization type
- family business
- Joined
- May 2024
- Message
- 1
We are a private educational institution in Istanbul with 850 students from kindergarten through high school and around 90 staff members. We have a two-person IT team. We recently received an audit notice from the district national education directorate regarding cybersecurity directives and cyber incident response processes. We are required to set up a framework compliant with the ministry's incident response procedure, designate an authorized in-house team, and document the entire workflow in writing.
Our school network runs a basic firewall and centralized logging system, but we are unsure about the standardized procedures required by the ministry, the exact nature of the mandatory logs to be kept, and the official notification deadlines. In the event of ransomware, website defacement, or a student data breach, it is not entirely clear when and with which documentation we must notify the relevant ministry departments.
I would appreciate guidance from colleagues who have gone through similar audits or successfully implemented this procedure at their institution: Which documents should we begin drafting first, who must mandatorily sit on the commission, and how should technical logs be archived to remain fully compliant with the regulations?