{"id":151328,"date":"2024-02-15T17:00:26","date_gmt":"2024-02-15T17:00:26","guid":{"rendered":"https:\/\/bas-ip.com\/security-policy\/"},"modified":"2025-11-28T13:11:38","modified_gmt":"2025-11-28T13:11:38","slug":"security-policy","status":"publish","type":"page","link":"https:\/\/bas-ip.com\/tr\/security-policy\/","title":{"rendered":"G\u00fcvenlik Politikas\u0131"},"content":{"rendered":"<h1 class=\"wp-block-heading\">G\u00fcvenlik A\u00e7\u0131\u011f\u0131 Bildirim Politikas\u0131<\/h1>\n\n\n\n<h1 class=\"wp-block-heading\">Genel Bilgiler<\/h1>\n\n\n\n<p>BAS-IP, \u00fcr\u00fcnlerimizde ke\u015ffedilen g\u00fcvenlik a\u00e7\u0131klar\u0131n\u0131 y\u00f6netme ve bunlara yan\u0131t verme konusunda sekt\u00f6r lideri uygulamalar\u0131 takip etmektedir. \u015eirketimiz taraf\u0131ndan sa\u011flanan \u00fcr\u00fcn ve hizmetlerin g\u00fcvenlik a\u00e7\u0131klar\u0131ndan tamamen ar\u0131nm\u0131\u015f oldu\u011funu garanti etmek imkans\u0131zd\u0131r. Bu, benzersiz bir \u00f6zellik de\u011fil, t\u00fcm yaz\u0131l\u0131mlar ve hizmetler i\u00e7in ortak bir ko\u015fuldur, ancak geli\u015ftirmenin her a\u015famas\u0131nda potansiyel g\u00fcvenlik a\u00e7\u0131klar\u0131n\u0131 tespit etmek ve ortadan kald\u0131rmak i\u00e7in \u00e7aba g\u00f6sterece\u011fimizi, b\u00f6ylece BAS-IP \u00fcr\u00fcn ve hizmetlerinin m\u00fc\u015fteri ortamlar\u0131nda konu\u015fland\u0131r\u0131lmas\u0131yla ili\u015fkili riski azaltaca\u011f\u0131m\u0131z\u0131 garanti edebiliriz.<\/p>\n\n\n\n<p>BAS-IP, baz\u0131 standart a\u011f protokollerinin ve hizmetlerinin istismar edilebilecek do\u011fal zay\u0131fl\u0131klara sahip olabilece\u011fini kabul etmektedir. BAS-IP bu protokollerden ve hizmetlerden sorumlu olmasa da, BAS-IP \u00fcr\u00fcnleri, yaz\u0131l\u0131mlar\u0131 ve hizmetleriyle ili\u015fkili riskleri azaltmaya y\u00f6nelik tavsiyeleri \u00e7e\u015fitli k\u0131lavuzlar <a href=\"https:\/\/basip.atlassian.net\/wiki\/spaces\/HP\/pages\/5046705\/The+practice+of+building+IP+intercom+systems\" target=\"_blank\" rel=\"noopener\">\u015feklinde sunmaktay\u0131z<\/a>.<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">Politikan\u0131n Kapsam\u0131<\/h1>\n\n\n\n<p>Bu belgede a\u00e7\u0131klanan g\u00fcvenlik a\u00e7\u0131\u011f\u0131 y\u00f6netimi politikas\u0131, BAS-IP markas\u0131 alt\u0131ndaki t\u00fcm \u00fcr\u00fcnler, yaz\u0131l\u0131mlar ve hizmetler i\u00e7in ge\u00e7erlidir.<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">Politikan\u0131n Kapsam\u0131na Girmeyenler<\/h1>\n\n\n\n<p>Baz\u0131 g\u00fcvenlik a\u00e7\u0131klar\u0131 BAS-IP g\u00fcvenlik a\u00e7\u0131\u011f\u0131 y\u00f6netimi politikas\u0131 kapsam\u0131nda de\u011fildir. L\u00fctfen g\u00fcvenlik a\u00e7\u0131\u011f\u0131 y\u00f6netimi politikas\u0131 kapsam\u0131nda olmayan g\u00fcvenlik a\u00e7\u0131\u011f\u0131 raporlar\u0131n\u0131 <a href=\"mailto:security@bas-ip.com\">security@bas-ip.com<\/a> adresine g\u00f6ndermeyin:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Y\u00fcksek ayr\u0131cal\u0131klar ve\/veya <em>root<\/em>\/y\u00f6netici eri\u015fimi ile tetiklenen\/y\u00fcr\u00fct\u00fclen ve\/veya karma\u015f\u0131k kullan\u0131c\u0131 etkile\u015fimi gerektiren <strong>sosyal m\u00fchendislik<\/strong> gerektiren g\u00fcvenlik a\u00e7\u0131klar\u0131<\/li>\n\n\n\n<li><strong>Alt alan ad\u0131 devralma<\/strong> (<em>Subdomain takeover<\/em>), \u00f6rne\u011fin, o anda kullan\u0131lmayan bir hizmeti i\u015faret eden bir d\u00fc\u011f\u00fcm \u00fczerinde kontrol kazanma<\/li>\n\n\n\n<li>BAS-IP k\u0131lavuzlar\u0131na uyularak \u00f6nlenebilecek <strong>yanl\u0131\u015f kullan\u0131c\u0131 yap\u0131land\u0131rmalar\u0131<\/strong><\/li>\n\n\n\n<li>\u00dc\u00e7\u00fcnc\u00fc taraf kullan\u0131c\u0131lar veya ortaklar taraf\u0131ndan olu\u015fturulan i\u00e7erik veya uygulamalardaki g\u00fcvenlik a\u00e7\u0131klar\u0131, \u00f6rne\u011fin BAS-IP cihazlar\u0131nda indirilebilen ve \u00e7al\u0131\u015ft\u0131r\u0131labilen uygulamalar<\/li>\n\n\n\n<li>Kullan\u0131c\u0131y\u0131 k\u00f6t\u00fc ama\u00e7l\u0131 bir web sitesini ziyaret etmeye veya BAS-IP cihazlar\u0131n\u0131n web aray\u00fcz\u00fcne eri\u015firken gizlenmi\u015f bir ba\u011flant\u0131ya t\u0131klamaya kand\u0131ran <strong>Siteler Aras\u0131 \u0130stek Sahtecili\u011fi (CSRF)<\/strong> veya <strong>Siteler Aras\u0131 Komut Dosyas\u0131 \u00c7al\u0131\u015ft\u0131rma (XSS)<\/strong> g\u00fcvenlik a\u00e7\u0131klar\u0131<\/li>\n\n\n\n<li>BAS-IP \u00fcr\u00fcnleri, yaz\u0131l\u0131mlar\u0131 veya hizmetlerinde kullan\u0131lan yaz\u0131l\u0131m bile\u015fenlerinde veya paketlerinde bulunan, bir CVE tan\u0131mlay\u0131c\u0131s\u0131 ile kaydedilmi\u015f <strong>\u00fc\u00e7\u00fcnc\u00fc taraf a\u00e7\u0131k kaynak g\u00fcvenlik a\u00e7\u0131klar\u0131<\/strong>. Bu t\u00fcr yaz\u0131l\u0131m bile\u015fenlerine yayg\u0131n \u00f6rnekler aras\u0131nda Linux \u00e7ekirde\u011fi, OpenSSL, AOSP ve di\u011ferleri bulunur<\/li>\n\n\n\n<li>X-Frame-Options gibi <strong>HTTP(S) g\u00fcvenlik ba\u015fl\u0131klar\u0131n\u0131n eksikli\u011fi<\/strong><\/li>\n\n\n\n<li>\u00dc\u00e7\u00fcnc\u00fc taraf a\u011f g\u00fcvenlik taray\u0131c\u0131lar\u0131 taraf\u0131ndan olu\u015fturulan g\u00fcvenlik a\u00e7\u0131\u011f\u0131 raporlar\u0131<\/li>\n\n\n\n<li><strong>Desteklenmeyen<\/strong> \u00fcr\u00fcnler\/yaz\u0131l\u0131mlar\/hizmetler<\/li>\n\n\n\n<li><strong>A\u011f Hizmet Reddi (DoS veya DDoS)<\/strong> testleri veya sisteme veya verilere eri\u015fimi bozan veya onlara zarar veren di\u011fer testler<\/li>\n<\/ul>\n\n\n\n<h1 class=\"wp-block-heading\">Y\u00fck\u00fcml\u00fcl\u00fckler<\/h1>\n\n\n\n<p>BAS-IP, ara\u015ft\u0131rmac\u0131lar\u0131n BAS-IP \u00fcr\u00fcnleri, yaz\u0131l\u0131mlar\u0131 ve hizmetlerindeki g\u00fcvenlik a\u00e7\u0131klar\u0131n\u0131 belirleme ve raporlama \u00e7abalar\u0131n\u0131 takdir eder ve te\u015fvik eder. Sorumlu a\u00e7\u0131klama s\u00fcrecini takip ederek, BAS-IP \u00fcr\u00fcn g\u00fcvenlik ekibi, a\u00e7\u0131klama s\u00fcreci boyunca kar\u015f\u0131l\u0131kl\u0131 i\u015fbirli\u011fi ve \u015feffafl\u0131k yoluyla ara\u015ft\u0131rmac\u0131lar\u0131n \u00e7\u0131karlar\u0131na ellerinden gelen en iyi \u015fekilde sayg\u0131 g\u00f6sterecektir.<\/p>\n\n\n\n<p>BAS-IP \u015eirketi, ara\u015ft\u0131rmac\u0131lar\u0131n <strong>90 g\u00fcnl\u00fck s\u00fcrenin dolmas\u0131na veya kar\u015f\u0131l\u0131kl\u0131 olarak kararla\u015ft\u0131r\u0131lan bir tarihe kadar<\/strong> g\u00fcvenlik a\u00e7\u0131klar\u0131n\u0131 if\u015fa etmemesini ve g\u00fcvenlik a\u00e7\u0131\u011f\u0131 ara\u015ft\u0131rmas\u0131n\u0131 <strong>yasal s\u0131n\u0131rlar<\/strong> i\u00e7inde, zarar vermeden, gizlili\u011fi if\u015fa etmeden veya BAS-IP \u015eirketi, ortaklar\u0131 ve m\u00fc\u015fterilerinin g\u00fcvenli\u011fini tehlikeye atmadan y\u00fcr\u00fctmesini bekler.<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">G\u00fcvenlik A\u00e7\u0131\u011f\u0131 Y\u00f6netimi<\/h1>\n\n\n\n<p>BAS-IP \u015eirketi, g\u00fcvenlik a\u00e7\u0131klar\u0131n\u0131 iyi bilinen <a href=\"https:\/\/www.first.org\/cvss\/calculator\/3-1\" target=\"_blank\" rel=\"noopener\"><strong>CVSS<\/strong> derecelendirme<\/a> sistemini kullanarak de\u011ferlendirir.<\/p>\n\n\n\n<p>A\u00e7\u0131k kaynak bile\u015fen g\u00fcvenlik a\u00e7\u0131klar\u0131 ile ilgili olarak, BAS-IP, g\u00fcvenlik a\u00e7\u0131\u011f\u0131n\u0131, BAS-IP&#8217;nin \u00fcr\u00fcnlerini, yaz\u0131l\u0131mlar\u0131n\u0131 ve hizmetlerini nas\u0131l uygulamay\u0131 \u00f6nerdi\u011fi ba\u011flam\u0131ndaki \u00f6nemine ba\u011fl\u0131 olarak de\u011ferlendirebilir. G\u00fcvenlik dan\u0131\u015fmanl\u0131klar\u0131 genellikle yaln\u0131zca BAS-IP&#8217;ye \u00f6zg\u00fc g\u00fcvenlik a\u00e7\u0131klar\u0131 i\u00e7in sa\u011flan\u0131r.<\/p>\n\n\n\n<p>Bir g\u00fcvenlik a\u00e7\u0131\u011f\u0131 de\u011ferlendirildi\u011finde ve d\u00fczeltmeye tabi oldu\u011funda <strong>\u00f6ncelik da\u011f\u0131l\u0131m\u0131<\/strong>:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>CVSS 3.1 high\/critical (7.0 &#8211; 10.0)<\/strong><br>BAS-IP, harici a\u00e7\u0131klamadan \u00f6nce veya sonraki <strong>4 hafta i\u00e7inde<\/strong> g\u00fcvenlik a\u00e7\u0131\u011f\u0131n\u0131 gidermeye \u00e7al\u0131\u015f\u0131r. A\u00e7\u0131k kaynak bile\u015fenleri i\u00e7in, zaman \u00e7izelgesi genellikle daha uzundur, \u00e7\u00fcnk\u00fc BAS-IP bilgi, d\u00fczeltmeler ve\/veya do\u011frulama i\u00e7in d\u0131\u015f taraflara ba\u011fl\u0131d\u0131r<\/li>\n\n\n\n<li><strong>CVSS 3.1 medium (4.0 &#8211; 6.9)<\/strong><br>BAS-IP, g\u00fcvenlik a\u00e7\u0131\u011f\u0131n\u0131 gidermeyi hedefler, genellikle <strong>2-3 ay<\/strong> i\u00e7inde<\/li>\n\n\n\n<li><strong>CVSS 3.1 low (0.1 &#8211; 3.9)<\/strong><br>BAS-IP, g\u00fcvenlik a\u00e7\u0131\u011f\u0131n\u0131 <strong>bir sonraki planl\u0131 s\u00fcr\u00fcmde<\/strong> gidermeyi planlar<\/li>\n\n\n\n<li>Desteklenen yaz\u0131l\u0131m\/hizmetler<br>BAS-IP yaz\u0131l\u0131m\/hizmetlerinin destek a\u015famas\u0131, genel yaz\u0131l\u0131m ya\u015fam d\u00f6ng\u00fcs\u00fc s\u00fcreci i\u00e7inde belirlenir. BAS-IP yaz\u0131l\u0131mlar\u0131\/hizmetleri genellikle <em>end-of-life<\/em> (kullan\u0131m \u00f6mr\u00fc sonu) duyurusundan sonra <strong>1 y\u0131l boyunca<\/strong> desteklenir.<\/li>\n<\/ul>\n\n\n\n<h1 class=\"wp-block-heading\">G\u00fcvenlik A\u00e7\u0131\u011f\u0131 Raporlama<\/h1>\n\n\n\n<p>BAS-IP, \u00fcr\u00fcnlerimizdeki g\u00fcvenlik a\u00e7\u0131klar\u0131yla ili\u015fkili riskleri belirlemek ve azaltmak i\u00e7in s\u00fcrekli \u00e7al\u0131\u015fmaktad\u0131r. Ancak, bir BAS-IP \u00fcr\u00fcn\u00fc, yaz\u0131l\u0131m\u0131 veya hizmetiyle ilgili bir g\u00fcvenlik sistemi a\u00e7\u0131\u011f\u0131 ke\u015ffettiyseniz, sorunu <strong>derhal<\/strong> bildirmenizi \u015fiddetle tavsiye ederiz. G\u00fcvenlik sistemi a\u00e7\u0131klar\u0131n\u0131n zaman\u0131nda bildirilmesi, pratik kullan\u0131m olas\u0131l\u0131\u011f\u0131n\u0131 azaltmak i\u00e7in \u00e7ok \u00f6nemlidir. A\u00e7\u0131k kaynak yaz\u0131l\u0131m bile\u015fenleriyle ilgili g\u00fcvenlik a\u00e7\u0131klar\u0131 do\u011frudan sorumlu kurulu\u015fa bildirilmelidir.<\/p>\n\n\n\n<p>Potansiyel bir g\u00fcvenlik a\u00e7\u0131\u011f\u0131 ke\u015ffeden son kullan\u0131c\u0131lar, ortaklar, tedarik\u00e7iler, end\u00fcstri gruplar\u0131 ve ba\u011f\u0131ms\u0131z ara\u015ft\u0131rmac\u0131lar, bulgular\u0131n\u0131 <strong><a href=\"mailto:security@bas-ip.com\">security@bas-ip.com<\/a><\/strong> adresine veya <strong><a href=\"https:\/\/docs.google.com\/forms\/d\/e\/1FAIpQLSdetHDUfdt0Fxk9ctY1-XWJARmQA_2-wBeXVbX2fnweQasVAA\/viewform\" target=\"_blank\" rel=\"noopener\">anonim bir form<\/a><\/strong> doldurarak bildirmeye te\u015fvik edilir.<\/p>\n\n\n\n<p>G\u00f6nderilen rapor \u015funlar\u0131 i\u00e7ermelidir:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Potansiyel g\u00fcvenlik a\u00e7\u0131\u011f\u0131 hakk\u0131nda teknik bilgi<\/li>\n\n\n\n<li>Yeniden \u00fcretme ad\u0131mlar\u0131<\/li>\n\n\n\n<li>CVSS 3.1&#8217;e g\u00f6re s\u00f6m\u00fcr\u00fc durumunda tahmini etki ve \u00f6nem derecesi<\/li>\n\n\n\n<li>Varsa ara\u015ft\u0131rmac\u0131n\u0131n kendi g\u00fcvenlik a\u00e7\u0131\u011f\u0131 a\u00e7\u0131klama politikas\u0131<\/li>\n<\/ul>\n\n\n\n<p>BAS-IP \u015eirketinden a\u015fa\u011f\u0131dakileri bekleyebilirsiniz:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u0130lk yan\u0131t s\u00fcresi \u2014 ilk mesaj\u0131n al\u0131nmas\u0131ndan sonraki <strong>3 i\u015f g\u00fcn\u00fc<\/strong> i\u00e7inde<\/li>\n\n\n\n<li>\u0130\u015flem s\u00fcresi (ilk yan\u0131t\u0131n al\u0131nd\u0131\u011f\u0131 andan itibaren) \u2014 <strong>10 i\u015f g\u00fcn\u00fc<\/strong> i\u00e7inde<\/li>\n\n\n\n<li>\u00c7\u00f6z\u00fcm\u00fc geciktirebilecek sorular ve sorunlar da dahil olmak \u00fczere, iyile\u015ftirme s\u00fcrecinde att\u0131\u011f\u0131m\u0131z ad\u0131mlar konusunda m\u00fcmk\u00fcn oldu\u011funca \u015feffaf olaca\u011f\u0131z<\/li>\n\n\n\n<li>Sorunlar\u0131 tart\u0131\u015fmak i\u00e7in a\u00e7\u0131k bir diyalog s\u00fcrd\u00fcrece\u011fiz<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">G\u00fcvenlik A\u00e7\u0131\u011f\u0131 A\u00e7\u0131klamas\u0131<\/h2>\n\n\n\n<p>Ke\u015ffedilen bir g\u00fcvenlik a\u00e7\u0131\u011f\u0131 raporu incelenip ger\u00e7ek oldu\u011fu onayland\u0131ktan sonra, BAS-IP sorumlu a\u00e7\u0131klama s\u00fcrecini ba\u015flat\u0131r. BAS-IP, CVSS 3.1 de\u011ferlendirmesi, g\u00fcvenlik \u00f6nerisi i\u00e7eri\u011fi ve\/veya bas\u0131n b\u00fcltenleri (varsa) ve harici a\u00e7\u0131klama tarihi gibi ek detaylar konusunda ara\u015ft\u0131rmac\u0131 ile i\u015fbirli\u011fi yapmaya \u00e7al\u0131\u015f\u0131r.<\/p>\n\n\n\n<p>BAS-IP \u015eirketi ve ara\u015ft\u0131rmac\u0131 aras\u0131ndaki bir anla\u015fmadan sonra, g\u00fcvenlik a\u00e7\u0131\u011f\u0131 harici ama\u00e7lar i\u00e7in BAS-IP \u015eirketi taraf\u0131ndan g\u00fcvenlik \u00f6nerileri ve\/veya bir bas\u0131n b\u00fclteni yay\u0131nlanarak a\u00e7\u0131klanacakt\u0131r.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Belge De\u011fi\u015fiklik Ge\u00e7mi\u015fi<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><th>S\u00fcr\u00fcm<\/th><th>Tarih<\/th><th>A\u00e7\u0131klama<\/th><\/tr><tr><td>1.0<\/td><td>15.02.2024<\/td><td>\u0130lk s\u00fcr\u00fcm<\/td><\/tr><\/tbody><\/table><\/figure>","protected":false},"excerpt":{"rendered":"<p>G\u00fcvenlik A\u00e7\u0131\u011f\u0131 Bildirim Politikas\u0131 Genel Bilgiler BAS-IP, \u00fcr\u00fcnlerimizde ke\u015ffedilen g\u00fcvenlik a\u00e7\u0131klar\u0131n\u0131 y\u00f6netme ve bunlara yan\u0131t verme konusunda sekt\u00f6r lideri uygulamalar\u0131 takip etmektedir. \u015eirketimiz taraf\u0131ndan sa\u011flanan \u00fcr\u00fcn ve hizmetlerin g\u00fcvenlik a\u00e7\u0131klar\u0131ndan tamamen ar\u0131nm\u0131\u015f oldu\u011funu garanti etmek imkans\u0131zd\u0131r. Bu, benzersiz bir \u00f6zellik de\u011fil, t\u00fcm yaz\u0131l\u0131mlar ve hizmetler i\u00e7in ortak bir ko\u015fuldur, ancak geli\u015ftirmenin her a\u015famas\u0131nda potansiyel g\u00fcvenlik [&hellip;]<\/p>","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"inline_featured_image":false,"footnotes":""},"class_list":["post-151328","page","type-page","status-publish","hentry"],"acf":[],"_links":{"self":[{"href":"https:\/\/bas-ip.com\/tr\/wp-json\/wp\/v2\/pages\/151328","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/bas-ip.com\/tr\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/bas-ip.com\/tr\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/bas-ip.com\/tr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/bas-ip.com\/tr\/wp-json\/wp\/v2\/comments?post=151328"}],"version-history":[{"count":3,"href":"https:\/\/bas-ip.com\/tr\/wp-json\/wp\/v2\/pages\/151328\/revisions"}],"predecessor-version":[{"id":151416,"href":"https:\/\/bas-ip.com\/tr\/wp-json\/wp\/v2\/pages\/151328\/revisions\/151416"}],"wp:attachment":[{"href":"https:\/\/bas-ip.com\/tr\/wp-json\/wp\/v2\/media?parent=151328"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}