CyberMap Group
CyberMap Group
Home
About
Team
Contact

SPK VII-128.10 Information Security Compliance

An audit-ready, communiqué-specific compliance model for real-estate appraisal firms.

The SPK VII-128.10 Information Systems Management Communiqué took effect on 13 March 2025 and directly covers all TDUB-member appraisal firms. SPK audits began on 31 December 2025.

Passing these audits is impossible without both documents and proof of application. Our model builds on the exemption the Communiqué grants appraisal firms, focusing only on mandatory requirements for a lean, cost-effective compliance.

Request an SPK Compliance Call
8–10 Weeks

Audit-Ready Setup

14

Documents Delivered

13

Exempt Technical Clauses (Art. 30)

20+

Years of ISMS Experience

Article 30 of the Communiqué exempts appraisal firms from 13 heavy technical obligations such as SIEM, SOC, penetration testing, internal audit and DLP.

This exemption makes compliance achievable without unnecessary hardware or cost. We don't just produce documents; we also build the process and record infrastructure that proves each document is actually applied.

Service Model — Three Layers

Each layer produces concrete output that can be presented as audit evidence.

Governance

Roles and responsibilities, appointment of an Information Security Officer (BGS), policy development and board-ready reporting.

Technical Controls

Access management, authorization matrix, information-asset inventory and an audit-valid 5-year log-retention policy.

Risk & Continuity

Annual risk assessment via a 5×5 qualitative matrix, a business-continuity plan with RTO/RPO, and third-party provider management.

Setup Process — 8–10 Weeks

01

GAP Analysis

Assessment of current state and gaps.

02

Information Security Policy

Board-approved policy preparation.

03

Outsourced BGS Appointment

Appointment of an Information Security Officer via a virtual/remote model.

04

Risk Assessment

Annual assessment with a 5×5 qualitative matrix.

05

Asset Inventory

Classification of all information assets.

06

Access & Authorization Matrix

Definition and recording of user permissions.

07

Log Management Policy

Log and audit-trail policy meeting the 5-year retention rule.

08

Incident & Continuity Plans

Incident-management procedure and a business-continuity plan with RTO/RPO.

09

Training & Contract Review

Staff security training and review of third-party provider contracts.

The 14 Documents Delivered

Every document is prepared in a format valid as audit evidence.

  • GAP Analysis Report
  • Information Security Policy
  • BGS Appointment Decision
  • Information Asset Inventory
  • Risk Assessment Report
  • Access Control Policy
  • User Authorization Matrix
  • Log Management Policy
  • Incident Management Procedure
  • Business Continuity Plan
  • Third-Party Provider Procedure
  • Staff Training Package
  • Board Briefing Report
  • Audit Evidence File

Ongoing Support

Outsourced BGS — reporting to top management, incident tracking and annual updates

Mock audit — a thorough internal review 4–6 weeks before the official audit

Interview rehearsal for the BGS/IT manager and a board-preparation meeting

Assurance & framework

Regulatory Compliance (SPK VII-128.10)
Audit Assurance with a Full Evidence File
Independent, Experienced BGS
Cost Efficiency via the Exemption

Be ready for the audits after 31 December 2025.

Let's start with a free discovery call for a roadmap tailored to your appraisal firm.

Request an SPK Compliance Call
CyberMap Group

A results-driven cybersecurity ecosystem with an adversary mindset: offensive testing, compliance consultancy, corporate training and R&D.

  • info@cybermapgroup.com
  • YDA Center — Kızılırmak Mah. Dumlupınar Bul. No: 9A, Çankaya / Ankara

Services

  • Penetration Testing
  • Hardware Threat Simulation
  • Security & Compliance
  • SPK VII-128.10 Compliance
  • Corporate Training

Products

  • ARQ
  • Corvox
  • Monorisk

Company

  • About
  • Team
  • Hardware Lab
  • Brand Assets
  • CyberMap Blog
  • Contact

Legal

  • Terms of Service
  • Privacy Policy
  • Cookie Policy
  • Disclaimer

© 2026 CyberMap Group

Built by Enes Can Adil 💟