
Personal data at rest encryption controls
User data (in memory)
• Not encrypted by phone application except for passwords stored in memory. Passwords are
only decrypted temporarily during use.
User data (on flash)
• Not Encrypted
Call Logs (on flash)
• Not Encrypted
User Passwords (on flash)
• AES-256 encrypted
• There are no controls available for the type or strength of encryption
User data in logs (on flash)
• Not Encrypted
Personal data in transit encryption controls
User data (in memory)
• TLS 1.2 to send/receive data with servers
User data (on flash)
• TLS 1.2 (HTTPs) to send/receive data with servers
• SSH
Call Logs (on flash)
• TLS 1.2 (HTTPs) to receive data with servers
• Data is never transmitted out of the phone
User Passwords (on flash)
• TLS 1.2 to send/receive data with servers (only the encrypted form is transmitted)
User data in logs (on flash)
• TLS 1.2 (HTTPs) to send data with servers when it is being sent as a phone report
• SSH
Personal data at rest encryption controls
April 2020
Installing and Administering Avaya J100 series IP Phones in an Open SIP
environment
269