Compliance
Avaya is committed to securing the data we process on behalf of our customers. We comply with laws, regulations, policies, and customer commitments.
Structured for success
Avaya’s Certifications Team oversees the engagement of independent third-party assessors to review the security of our cloud offerings. The team is strategically placed under the Ethics & Integrity umbrella to ensure independence and proper oversight. The current status of third-party certifications for our offers is below.
Security
Avaya maintains two security teams.
The Corporate Security team oversees the protection of people and assets and manages business continuity and crisis management planning initiatives to ensure the safety of our employees and operations.
The Information Security team ensures the protection and availability of Avaya’s information assets, which include information entrusted to us by our customers. We understand that threats to our network and information come from many different vectors and are extremely fluid. We approach security by:
- Security operations and best practices
- Platform and network security
- Availability and continuity incident response
- Continuous assessment and improvement
ISO 9001
Learn more
ISO 9001
For a quality management system (QMS). This applies to Avaya’s design, development, sales, delivery, implementation, and services of our communication solutions. View or download the certification and scope at Certification by Schellman.
ISO 27001
To support customers, Avaya protects the confidentiality, integrity, and availability of sensitive data through a systematic Information Security Management System (ISMS) Information Security Standard for the following Avaya Offers:
- Avaya Infinity with Media Processing Core (MPC), including ISO 27017 and ISO 27018
- Avaya Experience Platform Private Cloud with Avaya Aura Private Cloud, including ISO 27017 and ISO 27018
- Avaya Managed Services Platform (AMSP)
View or download the ISO 27001 certificates, including scope, at: Schellman Certificate Directory
HIPAA Compliance
To support customers in the health care industry, Avaya has implemented the appropriate security controls to issue a Business Associate Agreement for the following Avaya offers as required by the US HIPAA regulation.
- Avaya Infinity
- Avaya Media Processing Core (MPC)
- Avaya Experience Platform Private Cloud with Avaya Aura Private Cloud
- Avaya Managed Services Platform (AMSP)
PCI compliance
To support customers that process credit card data, Avaya has implemented appropriate security controls for the following Avaya Offers in accordance with PCI DSS (Payment Card Industry Data Security Standard):
- Avaya Infinity
- Avaya Media Processing Core (MPC)
- Avaya Experience Platform Private Cloud with Avaya Aura Private Cloud
- Avaya OneCloud Private
FedRAMP compliance
To support U.S. Government customers, Avaya has implemented appropriate security controls on Avaya Government Cloud.
ISO 27001
Learn more
ISO 9001
For a quality management system (QMS). This applies to Avaya’s design, development, sales, delivery, implementation, and services of our communication solutions. View or download the certification and scope at Certification by Schellman.
ISO 27001
To support customers, Avaya protects the confidentiality, integrity, and availability of sensitive data through a systematic Information Security Management System (ISMS) Information Security Standard for the following Avaya Offers:
- Avaya Infinity with Media Processing Core (MPC), including ISO 27017 and ISO 27018
- Avaya Experience Platform Private Cloud with Avaya Aura Private Cloud, including ISO 27017 and ISO 27018
- Avaya Managed Services Platform (AMSP)
View or download the ISO 27001 certificates, including scope, at: Schellman Certificate Directory
HIPAA Compliance
To support customers in the health care industry, Avaya has implemented the appropriate security controls to issue a Business Associate Agreement for the following Avaya offers as required by the US HIPAA regulation.
- Avaya Infinity
- Avaya Media Processing Core (MPC)
- Avaya Experience Platform Private Cloud with Avaya Aura Private Cloud
- Avaya Managed Services Platform (AMSP)
PCI compliance
To support customers that process credit card data, Avaya has implemented appropriate security controls for the following Avaya Offers in accordance with PCI DSS (Payment Card Industry Data Security Standard):
- Avaya Infinity
- Avaya Media Processing Core (MPC)
- Avaya Experience Platform Private Cloud with Avaya Aura Private Cloud
- Avaya OneCloud Private
FedRAMP compliance
To support U.S. Government customers, Avaya has implemented appropriate security controls on Avaya Government Cloud.
HIPAA Compliance
Learn more
ISO 9001
For a quality management system (QMS). This applies to Avaya’s design, development, sales, delivery, implementation, and services of our communication solutions. View or download the certification and scope at Certification by Schellman.
ISO 27001
To support customers, Avaya protects the confidentiality, integrity, and availability of sensitive data through a systematic Information Security Management System (ISMS) Information Security Standard for the following Avaya Offers:
- Avaya Infinity with Media Processing Core (MPC), including ISO 27017 and ISO 27018
- Avaya Experience Platform Private Cloud with Avaya Aura Private Cloud, including ISO 27017 and ISO 27018
- Avaya Managed Services Platform (AMSP)
View or download the ISO 27001 certificates, including scope, at: Schellman Certificate Directory
HIPAA Compliance
To support customers in the health care industry, Avaya has implemented the appropriate security controls to issue a Business Associate Agreement for the following Avaya offers as required by the US HIPAA regulation.
- Avaya Infinity
- Avaya Media Processing Core (MPC)
- Avaya Experience Platform Private Cloud with Avaya Aura Private Cloud
- Avaya Managed Services Platform (AMSP)
PCI compliance
To support customers that process credit card data, Avaya has implemented appropriate security controls for the following Avaya Offers in accordance with PCI DSS (Payment Card Industry Data Security Standard):
- Avaya Infinity
- Avaya Media Processing Core (MPC)
- Avaya Experience Platform Private Cloud with Avaya Aura Private Cloud
- Avaya OneCloud Private
FedRAMP compliance
To support U.S. Government customers, Avaya has implemented appropriate security controls on Avaya Government Cloud.
PCI compliance
Learn more
ISO 9001
For a quality management system (QMS). This applies to Avaya’s design, development, sales, delivery, implementation, and services of our communication solutions. View or download the certification and scope at Certification by Schellman.
ISO 27001
To support customers, Avaya protects the confidentiality, integrity, and availability of sensitive data through a systematic Information Security Management System (ISMS) Information Security Standard for the following Avaya Offers:
- Avaya Infinity with Media Processing Core (MPC), including ISO 27017 and ISO 27018
- Avaya Experience Platform Private Cloud with Avaya Aura Private Cloud, including ISO 27017 and ISO 27018
- Avaya Managed Services Platform (AMSP)
View or download the ISO 27001 certificates, including scope, at: Schellman Certificate Directory
HIPAA Compliance
To support customers in the health care industry, Avaya has implemented the appropriate security controls to issue a Business Associate Agreement for the following Avaya offers as required by the US HIPAA regulation.
- Avaya Infinity
- Avaya Media Processing Core (MPC)
- Avaya Experience Platform Private Cloud with Avaya Aura Private Cloud
- Avaya Managed Services Platform (AMSP)
PCI compliance
To support customers that process credit card data, Avaya has implemented appropriate security controls for the following Avaya Offers in accordance with PCI DSS (Payment Card Industry Data Security Standard):
- Avaya Infinity
- Avaya Media Processing Core (MPC)
- Avaya Experience Platform Private Cloud with Avaya Aura Private Cloud
- Avaya OneCloud Private
FedRAMP compliance
To support U.S. Government customers, Avaya has implemented appropriate security controls on Avaya Government Cloud.
FedRAMP compliance
Learn more
ISO 9001
For a quality management system (QMS). This applies to Avaya’s design, development, sales, delivery, implementation, and services of our communication solutions. View or download the certification and scope at Certification by Schellman.
ISO 27001
To support customers, Avaya protects the confidentiality, integrity, and availability of sensitive data through a systematic Information Security Management System (ISMS) Information Security Standard for the following Avaya Offers:
- Avaya Infinity with Media Processing Core (MPC), including ISO 27017 and ISO 27018
- Avaya Experience Platform Private Cloud with Avaya Aura Private Cloud, including ISO 27017 and ISO 27018
- Avaya Managed Services Platform (AMSP)
View or download the ISO 27001 certificates, including scope, at: Schellman Certificate Directory
HIPAA Compliance
To support customers in the health care industry, Avaya has implemented the appropriate security controls to issue a Business Associate Agreement for the following Avaya offers as required by the US HIPAA regulation.
- Avaya Infinity
- Avaya Media Processing Core (MPC)
- Avaya Experience Platform Private Cloud with Avaya Aura Private Cloud
- Avaya Managed Services Platform (AMSP)
PCI compliance
To support customers that process credit card data, Avaya has implemented appropriate security controls for the following Avaya Offers in accordance with PCI DSS (Payment Card Industry Data Security Standard):
- Avaya Infinity
- Avaya Media Processing Core (MPC)
- Avaya Experience Platform Private Cloud with Avaya Aura Private Cloud
- Avaya OneCloud Private
FedRAMP compliance
To support U.S. Government customers, Avaya has implemented appropriate security controls on Avaya Government Cloud.
Digital Operational Resilience Act (DORA)
The Digital Operational Resilience Act (DORA) is an EU regulation that aims to enhance financial entities' IT security and operational resilience, including banks, insurance companies, and investment firms. DORA mandates stringent requirements for ICT risk management, incident reporting, operational resilience testing, third-party risk management, and information sharing.
Sustainability and other disclosures