From Secure Coding to Penetration Testing: How Is Data Security Ensured?


Barış Fındık, Chief Technology Officer at Pegasus Airlines, spoke about how to ensure data security—from secure coding to penetration testing. Fındık said the following:

Data security is of great value, importance, and significance to all of us—both for passengers and for the organization. The security of our customers’ data is very important to us, both from a regulatory standpoint and out of respect for our customers. This is certainly true for the aviation industry—and, of course, for many other industries as well—but data security is particularly valuable in the aviation industry. We are both making internal improvements and undertaking projects on our own, as well as collaborating with external partners and other stakeholders in the ecosystem to develop projects. Even before we begin a project, it is very important for us to categorize our services and risks from a security and risk perspective. Of course, there are risk catalogs published in this regard by both “IATA” and “EASA”—that is, by aviation regulatory bodies. In this regard, we adhere to universal standards regarding flight safety, passenger safety, and data security, and we conduct risk categorization by taking these criteria into account right from the start of the project. Within this risk categorization framework, we evaluate our projects and assign the relevant experts to each project. Not only do we make a significant investment in security starting from the coding phase through the testing process, but we also strive to ensure the security of the product and the data—and that we can provide reliable service to our customers—through processes such as penetration testing and load testing after the product goes live.

Share:

About the Wise

Similar Videos from this Wise