Information Security Policy StatementAvya Technologies (Private) Limited provides services involving design, development, testing, deployment, maintenance and support of software products and services, together with the provisioning, configuration, administration, monitoring and patching of supporting cloud infrastructure used to deliver those services. This Information Security Policy is established to support the purpose and strategic direction of Avya Technologies by protecting company and client information, supporting secure and reliable service delivery, managing information security risks, and meeting applicable information security requirements.

Within the approved ISMS scope, Avya Technologies shall:

  • Protect the confidentiality, integrity and availability of company and client information and associated assets, based on their classification, business value and information security risks.
  • Establish, implement, maintain and continually improve an Information Security Management System appropriate to Avya Technologies’ purpose, activities and operating environment, in accordance with SLS ISO/IEC 27001:2022.
  • Integrate information security requirements into in-scope business and operational activities, including software development and support, supporting cloud infrastructure management, HR, administrative, financial and supplier-management activities.
  • Identify, assess and treat information security risks affecting in-scope personnel, information, systems, services and relevant external interfaces and dependencies.
  • Establish and monitor measurable information security objectives consistent with this Policy, applicable requirements and information security risks.
  • Satisfy applicable legal, statutory, regulatory, contractual, client and other information security requirements.
  • Ensure that personnel understand and fulfil their information security responsibilities through appropriate communication, awareness, education and training.
  • Ensure that remote working and remote access are included only when pre-approved and performed in accordance with the Remote Working and Remote Access Policy.
  • Protect information when Avya personnel access or process client-owned systems or information, while ownership and control of those systems remain with the respective client.
  • Manage information security risks and dependencies arising from cloud providers, external service providers and suppliers through appropriate supplier-management arrangements and applicable shared-responsibility models.
  • Provide appropriate resources and management support for the effective operation of the ISMS.
  • Continually improve the suitability, adequacy and effectiveness of the ISMS and its information security controls.