SPK VII-128.10 Information Security Compliance
An audit-ready, communiqué-specific compliance model for real-estate appraisal firms.
The SPK VII-128.10 Information Systems Management Communiqué took effect on 13 March 2025 and directly covers all TDUB-member appraisal firms. SPK audits began on 31 December 2025.
Passing these audits is impossible without both documents and proof of application. Our model builds on the exemption the Communiqué grants appraisal firms, focusing only on mandatory requirements for a lean, cost-effective compliance.
Audit-Ready Setup
Documents Delivered
Exempt Technical Clauses (Art. 30)
Years of ISMS Experience
Article 30 of the Communiqué exempts appraisal firms from 13 heavy technical obligations such as SIEM, SOC, penetration testing, internal audit and DLP.
This exemption makes compliance achievable without unnecessary hardware or cost. We don't just produce documents; we also build the process and record infrastructure that proves each document is actually applied.
Service Model — Three Layers
Each layer produces concrete output that can be presented as audit evidence.
Governance
Roles and responsibilities, appointment of an Information Security Officer (BGS), policy development and board-ready reporting.
Technical Controls
Access management, authorization matrix, information-asset inventory and an audit-valid 5-year log-retention policy.
Risk & Continuity
Annual risk assessment via a 5×5 qualitative matrix, a business-continuity plan with RTO/RPO, and third-party provider management.
Setup Process — 8–10 Weeks
GAP Analysis
Assessment of current state and gaps.
Information Security Policy
Board-approved policy preparation.
Outsourced BGS Appointment
Appointment of an Information Security Officer via a virtual/remote model.
Risk Assessment
Annual assessment with a 5×5 qualitative matrix.
Asset Inventory
Classification of all information assets.
Access & Authorization Matrix
Definition and recording of user permissions.
Log Management Policy
Log and audit-trail policy meeting the 5-year retention rule.
Incident & Continuity Plans
Incident-management procedure and a business-continuity plan with RTO/RPO.
Training & Contract Review
Staff security training and review of third-party provider contracts.
The 14 Documents Delivered
Every document is prepared in a format valid as audit evidence.
- GAP Analysis Report
- Information Security Policy
- BGS Appointment Decision
- Information Asset Inventory
- Risk Assessment Report
- Access Control Policy
- User Authorization Matrix
- Log Management Policy
- Incident Management Procedure
- Business Continuity Plan
- Third-Party Provider Procedure
- Staff Training Package
- Board Briefing Report
- Audit Evidence File
Ongoing Support
Outsourced BGS — reporting to top management, incident tracking and annual updates
Mock audit — a thorough internal review 4–6 weeks before the official audit
Interview rehearsal for the BGS/IT manager and a board-preparation meeting
Assurance & framework
Be ready for the audits after 31 December 2025.
Let's start with a free discovery call for a roadmap tailored to your appraisal firm.
Request an SPK Compliance Call