<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.4 20241031//EN"
        "https://jats.nlm.nih.gov/publishing/1.4/JATS-journalpublishing1-4.dtd">
<article  article-type="research-article"        dtd-version="1.4">
            <front>

                <journal-meta>
                                                                <journal-id>deneti̇şi̇m</journal-id>
            <journal-title-group>
                                                                                    <journal-title>Denetişim</journal-title>
            </journal-title-group>
                            <issn pub-type="ppub">1308-8335</issn>
                                                                                                        <publisher>
                    <publisher-name>Kamu İç Denetçileri Derneği</publisher-name>
                </publisher>
                    </journal-meta>
                <article-meta>
                                        <article-id pub-id-type="doi">10.58348/denetisim.1532057</article-id>
                                                                <article-categories>
                                            <subj-group  xml:lang="en">
                                                            <subject>Information Systems Organisation and Management</subject>
                                                    </subj-group>
                                            <subj-group  xml:lang="tr">
                                                            <subject>Bilgi Sistemleri Organizasyonu ve Yönetimi</subject>
                                                    </subj-group>
                                    </article-categories>
                                                                                                                                                        <title-group>
                                                                                                                        <article-title>UYAP’IN HOLİSTİK GÜVENLİK DENETİMİ</article-title>
                                                                                                                                                                                                <trans-title-group xml:lang="en">
                                    <trans-title>HOLISTIC SECURITY AUDIT OF UYAP</trans-title>
                                </trans-title-group>
                                                                                                    </title-group>
            
                                                    <contrib-group content-type="authors">
                                                                        <contrib contrib-type="author">
                                                                    <contrib-id contrib-id-type="orcid">
                                        https://orcid.org/0000-0002-5959-2691</contrib-id>
                                                                <name>
                                    <surname>Yıldırım</surname>
                                    <given-names>Hakan</given-names>
                                </name>
                                                                    <aff>TBMM</aff>
                                                            </contrib>
                                                                                </contrib-group>
                        
                                        <pub-date pub-type="pub" iso-8601-date="20250216">
                    <day>02</day>
                    <month>16</month>
                    <year>2025</year>
                </pub-date>
                                                    <issue>32</issue>
                                        <fpage>189</fpage>
                                        <lpage>203</lpage>
                        
                        <history>
                                    <date date-type="received" iso-8601-date="20240812">
                        <day>08</day>
                        <month>12</month>
                        <year>2024</year>
                    </date>
                                                    <date date-type="accepted" iso-8601-date="20240920">
                        <day>09</day>
                        <month>20</month>
                        <year>2024</year>
                    </date>
                            </history>
                                        <permissions>
                    <copyright-statement>Copyright © 2009, Denetişim</copyright-statement>
                    <copyright-year>2009</copyright-year>
                    <copyright-holder>Denetişim</copyright-holder>
                </permissions>
            
                                                                                                <abstract><p>UYAP (Ulusal Yargı Ağı Bilişim Sistemi), Türkiye&#039;nin adalet sisteminin dijitalleşmesi amacıyla oluşturulmuş büyük ve çok taraflı bir bilişim sistemidir. Bu geniş kapsamlı sistem, yargı süreçlerini daha hızlı, verimli ve şeffaf hale getirmeyi amaçlamaktadır. Ancak, bu büyüklükteki ve bu kadar tarafı olan bir sistemin yönetim karmaşası yaşaması çok normaldir ve sistemin Holistik olarak güvenliğinin sağlandığını söylemek mümkün değildir. Holistik yaklaşım, sistemin tüm bileşenlerinin ve güvenlik unsurlarının bir bütün olarak değerlendirilmesi gerektiğini ifade eder. Bir bilişim sisteminin güvenliğinin fiziksel, sanal, politika, veri, bilgi, mahremiyet, kişisel ve ulusal gibi pek çok boyutunun birlikte alınmasına ‘Holistik Güvenlik’ denmektedir. UYAP’ın güvenlik politikalarının tüm paydaşlarca belirlenmesi ve denetlenmesi büyük önem taşımaktadır, ancak mevcut durumda UYAP’ın güvenliğiyle ilgili olarak kimin ne ölçüde yetki ve sorumluluğu olduğuna dair belirsizlikler bulunmaktadır. Bu durum, UYAP&#039;ın denetiminin bağımsız ve UYAP&#039;ı kullanan tarafların geniş tabanlı temsilinden oluşan bir kurul tarafından yapılması gerektiğini ortaya koymaktadır. Bu kurul hem güvenlik hem de denetim politika ve standartlarını belirlemelidir. Bu makale, UYAP&#039;ın etkili yönetim ve denetimi için politika belirleyici olarak oluşturulması gerekli bir kurulda temsil edilmesi gereken tarafları ve kurulun yetkileri hakkında bir öneri sunmuştur.</p></abstract>
                                                                                                                                    <trans-abstract xml:lang="en">
                            <p>UYAP (National Judiciary Informatics System) is a large and multifaceted information system created to digitize Turkey&#039;s justice system. This comprehensive system aims to make judicial processes faster, more efficient, and transparent. However, it is quite normal for a system of this magnitude and with so many stakeholders to experience management complexity, and it is not possible to say that the system&#039;s security is ensured holistically. A holistic approach means that all components and security elements of the system need to be evaluated as a whole. The security of an information system is referred to as &#039;holistic security&#039; when the physical, virtual, policy, data, information, privacy, personal, and national dimensions are considered together. It is of great importance that UYAP&#039;s security policies are determined and supervised by all stakeholders. However, there are uncertainties regarding who has what degree of authority and responsibility for UYAP&#039;s security in the current situation. This situation indicates that UYAP&#039;s oversight should be carried out by an independent board consisting of broad-based representation of the parties using UYAP. This board should determine both the security and audit policies and standards. This article has proposed which parties should be represented and the authorities of the board necessary for policy determination for effective management and oversight of UYAP.</p></trans-abstract>
                                                            
            
                                                            <kwd-group>
                                                    <kwd>UYAP (Ulusal Yargı Ağı Bilişim Sistemi)</kwd>
                                                    <kwd>  Holistik Güvenlik</kwd>
                                                    <kwd>  Paydaş Katılımı</kwd>
                                                    <kwd>  Politika Kurulu</kwd>
                                                    <kwd>  Denetim</kwd>
                                            </kwd-group>
                                                        
                                                                            <kwd-group xml:lang="en">
                                                    <kwd>UYAP (National Judiciary Informatics System)</kwd>
                                                    <kwd>  Holistic Security</kwd>
                                                    <kwd>  Stakeholder Participation</kwd>
                                                    <kwd>  Policy Board</kwd>
                                                    <kwd>  Audit</kwd>
                                            </kwd-group>
                                                                                                            </article-meta>
    </front>
    <back>
                            <ref-list>
                                    <ref id="ref1">
                        <label>1</label>
                        <mixed-citation publication-type="journal">Adalet Bakanlığı Bilgi İşlem Genel Müdürlüğü. (2021). UYAP Bilişim Sistemi. Adalet Bakanlığı.</mixed-citation>
                    </ref>
                                    <ref id="ref2">
                        <label>2</label>
                        <mixed-citation publication-type="journal">Anadolu University. (2018). Ulusal Yargı Ağı Projesi-I. Anadolu University.</mixed-citation>
                    </ref>
                                    <ref id="ref3">
                        <label>3</label>
                        <mixed-citation publication-type="journal">Council of Europe. (2001). Convention on Cybercrime (Budapest Convention). Council of Europe.</mixed-citation>
                    </ref>
                                    <ref id="ref4">
                        <label>4</label>
                        <mixed-citation publication-type="journal">Demir, G. (2021). Ulusal Yargı Ağı Bilişim Sistemi’nin (UYAP) Güvenlik Politikaları. Bilgi Güvenliği Dergisi, 15(2), 45-61.</mixed-citation>
                    </ref>
                                    <ref id="ref5">
                        <label>5</label>
                        <mixed-citation publication-type="journal">European Union Agency for Cybersecurity (ENISA). (2019). Cybersecurity Culture Guidelines: Behavioural Aspects of Cybersecurity. ENISA.</mixed-citation>
                    </ref>
                                    <ref id="ref6">
                        <label>6</label>
                        <mixed-citation publication-type="journal">European Union Agency for Cybersecurity (ENISA). (2020). ENISA Threat Landscape 2020: Cybersecurity Challenges for the EU. ENISA.</mixed-citation>
                    </ref>
                                    <ref id="ref7">
                        <label>7</label>
                        <mixed-citation publication-type="journal">European Union Agency for Cybersecurity (ENISA). (2017). Guidelines on Data Protection Impact Assessment (DPIA) under Regulation (EU) 2016/679. ENISA.</mixed-citation>
                    </ref>
                                    <ref id="ref8">
                        <label>8</label>
                        <mixed-citation publication-type="journal">General Data Protection Regulation (GDPR). (2016). Regulation (EU) 2016/679.</mixed-citation>
                    </ref>
                                    <ref id="ref9">
                        <label>9</label>
                        <mixed-citation publication-type="journal">Home Office, UK Government. (2015). Security Guidance for Government Buildings. Home Office.</mixed-citation>
                    </ref>
                                    <ref id="ref10">
                        <label>10</label>
                        <mixed-citation publication-type="journal">Institute of Internal Auditors (IIA). (2012). Global Technology Audit Guide (GTAG): Information Technology Controls. IIA.</mixed-citation>
                    </ref>
                                    <ref id="ref11">
                        <label>11</label>
                        <mixed-citation publication-type="journal">ISO/IEC. (2019). ISO/IEC 22301: Business Continuity Management Systems – Requirements. ISO.</mixed-citation>
                    </ref>
                                    <ref id="ref12">
                        <label>12</label>
                        <mixed-citation publication-type="journal">ISO/IEC. (2013). ISO/IEC 27001: Information Security Management Systems – Requirements.</mixed-citation>
                    </ref>
                                    <ref id="ref13">
                        <label>13</label>
                        <mixed-citation publication-type="journal">National Institute of Standards and Technology (NIST). (2018). Framework for Improving Critical Infrastructure Cybersecurity. NIST.</mixed-citation>
                    </ref>
                                    <ref id="ref14">
                        <label>14</label>
                        <mixed-citation publication-type="journal">Schneier, B. (2015). Data and Goliath: The Hidden Battles to Collect Your Data and Control Your World. W.W. Norton &amp; Company.</mixed-citation>
                    </ref>
                                    <ref id="ref15">
                        <label>15</label>
                        <mixed-citation publication-type="journal">Stallings, W. (2017). Network Security Essentials: Applications and Standards. Pearson.
Şahin, E., &amp; Yıldırım, E. (2020). Türkiye&#039;de Siber Güvenlik Politikaları: UYAP Örneği. Güvenlik Stratejileri Dergisi, 16(32), 79-102.</mixed-citation>
                    </ref>
                                    <ref id="ref16">
                        <label>16</label>
                        <mixed-citation publication-type="journal">United Nations Conference on Trade and Development (UNCTAD). (2016). Data Protection and Privacy Legislation Worldwide. UNCTAD.</mixed-citation>
                    </ref>
                                    <ref id="ref17">
                        <label>17</label>
                        <mixed-citation publication-type="journal">Whitman, M. E., &amp; Mattord, H. J. (2018). Principles of Information Security. Cengage Learning.</mixed-citation>
                    </ref>
                                    <ref id="ref18">
                        <label>18</label>
                        <mixed-citation publication-type="journal">İnternet Kaynakları</mixed-citation>
                    </ref>
                                    <ref id="ref19">
                        <label>19</label>
                        <mixed-citation publication-type="journal">Adalet Bakanlığı. (nd). UYAP İstatistikleri. Erişim tarihi: 01.05.2024. Erişim adresi: https://istatistikler.uyap.gov.tr/
Bundesbeauftragter für den Datenschutz und die Informationsfreiheit (BfDI). (nd). Erişim tarihi: 05.05.2024. Erişim adresi: https://www.bfdi.bund.de</mixed-citation>
                    </ref>
                                    <ref id="ref20">
                        <label>20</label>
                        <mixed-citation publication-type="journal">Cybersecurity and Infrastructure Security Agency (CISA). (nd). Erişim tarihi: 10.05.2024. Erişim adresi: https://www.cisa.gov/</mixed-citation>
                    </ref>
                                    <ref id="ref21">
                        <label>21</label>
                        <mixed-citation publication-type="journal">Information Commissioner&#039;s Office (ICO). (nd). Erişim tarihi: 12.05.2024. Erişim adresi: https://ico.org.uk/
Nüfus ve Vatandaşlık İşleri Genel Müdürlüğü (NVİ). (nd). Erişim tarihi: 15.05.2024. Erişim adresi: https://www.nvi.gov.tr/</mixed-citation>
                    </ref>
                                    <ref id="ref22">
                        <label>22</label>
                        <mixed-citation publication-type="journal">Sosyal Güvenlik Kurumu (SGK). (nd). Erişim tarihi: 20.05.2024. Erişim adresi: https://www.sgk.gov.tr/</mixed-citation>
                    </ref>
                                    <ref id="ref23">
                        <label>23</label>
                        <mixed-citation publication-type="journal">Türkiye Barolar Birliği. (nd). Erişim tarihi: 25.05.2024. Erişim adresi: https://www.barobirlik.org.tr/</mixed-citation>
                    </ref>
                            </ref-list>
                    </back>
    </article>
