Verizon Security Summary
Introduction
Verizon’s Corporate Information Security Program has implemented administrative, technical and physical safeguards that help to protect the confidentiality, integrity and availability of systems, networks, and information. Millions of customers depend on Verizon to keep our networks safe. We deliver the promise of the digital world to our customers by providing the most reliable network and the latest technology. Verizon invests in people, processes, and technology to protect our company and our customers. A successful security program requires a partnership between skilled security leadership and teams involved in day-to-day business decision making. Verizon employs hundreds of security professionals, some of whom work directly for the Chief Information Security Officer (CISO) on establishing and governing Verizon's information security strategy, policy, standards, architecture and risk management. Other security professionals support lines of business directly, partnering with Corporate Information Security (CIS) to facilitate information security and protect customer data.
Verizon’s substantial investment in the people, processes and tools necessary to secure the products and services that our customers trust and depend on, demonstrates our commitment to security excellence every day. Our continuous improvement strategy stays ahead of the curve by implementing forward thinking security controls and techniques to protect customer data and the Verizon Network.
Verizon scope for securing Internal Systems includes the following:
Maintaining an Information Security Policy (Governance)
Verizon scope for securing Internal Systems includes the following governance practices. Verizon's written information security policies and practices actively correlate to the National Institute of Standards and Technology Cybersecurity Framework (NIST-CSF 2.0).
- Maintain a Formal Policy: Verizon maintains a formal, documented information security policy, which is based on various recognized industry security standards and is fully informed by our risk management strategy and aligned to the modern NIST-CSF 2.0 standards. Defined policies outline the ownership of risk acceptance and/or mitigation decisions. Accepted risk must be visible and affirmed at both the Business Unit (BU) and CIS executive levels (NIST-CSF GV.PO, GV.RM).
- Enforcement Teams: Verizon maintains information security teams to promote and assist in the enforcement of Verizon’s information security policy and practices. Verizon's Business Information Security Officer (BISO) is responsible for implementing appropriate security processes within the specific business unit of responsibility, serving as the interface between the business and security governance executive committees (NIST-CSF GV.PO).
- Security Governance and AI Frameworks: In collaboration with the CISO, the security governance executive committees provide direction to protect the confidentiality, integrity, and availability of Verizon's information resources. Additionally, Verizon's governance framework addresses the evolving risks of Artificial Intelligence (AI) by adopting the NIST AI Risk Management Framework (NIST AI 100-1) as its model, requiring the secure, ethical, and responsible utilization of AI and GenAI technologies. For every new and existing AI model or usecase, policy requires defining its intended uses, potential benefits, data access, and documented likelihood/severity of impacts (NIST-CSF GV.RM, GV.PO).
- Cyber Security Awareness Program: Verizon has a formal Cyber Security Awareness Program to ensure Verizon personnel are provided with cybersecurity awareness education and are adequately trained to perform their information security-related duties and responsibilities consistent with policy and the underlying control framework. Annual training has been expanded to ensure employees utilizing or interacting with AI systems understand their duties related to AI risk management and secure handling of customer info (NIST-CSF PR.AT).
- Risk Aligned Strategy & Objectives: Verizon establishes mature governance by (1) Defining Business Objectives aligned to strategic priorities; (2) Identifying Critical Assets and Services in a comprehensive inventory; and (3) Performing regular Impact Analyses to understand negative compromise impacts. This process creates direct alignment between cybersecurity efforts and overarching business goals (NIST-CSF GV.OC).
- Governance Oversight: Verizon integrates insights derived from our cybersecurity risk management program into our strategic direction, utilizing performance metrics and data to drive Resource Allocation, Mitigation Prioritization, and Continuous Improvement (NIST-CSF GV.OV).
- System Development Lifecycle: Verizon develops and maintains systems designed to secure Customer Data through privacy and cybersecurity risk assessments. Verizon development teams are required to implement secure design and testing controls throughout the system development lifecycle and require the use of secure coding practices (NIST-CSF PR.PS).
- Compliance: Verizon complies with applicable privacy laws and regulations to which Verizon is subject. Verizon has established processes to identify, and track applicable legal and regulatory information security and privacy regulations as defined by external governing bodies (NIST-CSF GV.PO).
Building and Maintaining a Secure Network (Platform Security)
To protect our enterprise infrastructure, Verizon deploys multi-layered, automated safeguards.
- Network Defense: Verizon uses a variety of industry-recognized security practices to protect our internal networks, including appropriately configured firewalls, network segmentation and networking monitoring.
- Continuous Monitoring & Alerting: Verizon implements security continuous monitoring which includes logging and monitoring access to Verizon’s networks and assets. Hardware and software-based tools have been deployed throughout the Verizon network to provide real-time alerting from devices such as firewalls, intrusion detection systems, routers and switches. Critical assets are subject to monitoring via the Threat Management Center. Security event logs are protected from tampering, limited to authorized users, stored centrally, and reviewed on a scheduled basis (NIST-CSF DE.CM).
- Vulnerability Scans & SLAs: Verizon performs internal and external vulnerability scans on a periodic basis. System owners may schedule real-time vulnerability system scans as needed. Continuous static (SAST) and dynamic (DAST) security scans are performed on web applications and APIs, and Verizon enforces Service Level Agreements (SLAs) for the remediation of identified security risks (NIST-CSF PR.PS).
- System Defaults & Change Control: Formal change control procedures are implemented and maintained. Changes to networks, devices, and software configurations must be reviewed and approved according to authorized change control processes (NIST-CSF PR.PS).
- Regular Testing & Penetration Testing: Verizon regularly tests systems and processes utilized for network security to maximize operational capacity. Penetration testing is performed on Verizon internal and external environments based on risk. Identified vulnerabilities are assessed based on the risk of each platform and security maintenance is performed accordingly (NIST-CSF PR.PS).
Protecting Sensitive Information
- Employee Code of Conduct: Verizon maintains a Verizon Code of Conduct for Verizon employees (available to the public at verizon.com/about/our-company/code-conduct) which requires that they comply with information security policies and procedures.
- Supply Chain & Vendor Management: Verizon uses contractual and other measures to obtain third party suppliers’ compliance with appropriate information security requirements, by implementing a comprehensive Cybersecurity Supply Chain Risk Management (SCRM) program. Verizon conducts rigorous due diligence on security controls, and formal agreements mandate adherence to Verizon's stringent standards, explicitly including Data Protection safeguards, timely Incident Response protocols for reporting/remediation, and Verizon's right to conduct regular security audits (NIST-CSF GV.SC).
- Data Classification & Lifecycle: Verizon manages data protection in a systematic and structured manner to enforce confidentiality requirements throughout the data’s lifecycle of creation, transmission, storage, modification, retention and destruction. Based on risk, industry standard encryption is used to protect data-in-transit and data-at-rest. Verizon formally classifies data according to four major classes: public, private, confidential, and highly confidential. Data destruction after the specified retention period is performed in strict alignment with NIST 800-88 Guidelines for Media Sanitization, requiring overwriting or purging media prior to disposal or reuse (NIST-CSF ID.AM, PR.DS).
- Physical Facility Security: Verizon provides physical security controls for each computer room, data center, and similar facilities that may contain sensitive information. Physical access is restricted to authorized personnel using electronic card access readers, keys, security guards, or local company personnel. CCTV cameras are deployed at strategic locations, company ID badges are required at all times, and visitors must sign-in and display visitor badges while being escorted (NIST-CSF PR.AA).
Maintaining a Vulnerability Management Program (Adverse Event Analysis)
Verizon has transformed its vulnerability efforts from a standard check-up posture into a robust, continuous adverse event detection model.
- Antivirus Protection: Verizon uses anti-virus software on systems to address malware threats against its systems. Workstations and laptops run antivirus software with centrally controlled, automatically scheduled virus definition updates (NIST-CSF PR.PS).
- Patch Management: Verizon has an established patch management process for production hardware and software installed on the Verizon network. Vendor security patches are assessed initially to determine risk and deployment priority prior to testing and production deployment (NIST-CSF PR.PS).
- Change Tracking: Verizon schedules, monitors, controls, and tracks significant changes affecting Verizon Assets.
- Enterprise Vulnerability Management (EVM): Verizon has a comprehensive Enterprise Vulnerability Management (EVM) program (NIST-CSF DE.AE) anchored by a corporate policy defining cadence and personnel responsibilities. EVM incorporates:
- Multi-Layered Detection: Discovery of assets and vulnerabilities is performed utilizing network vulnerability scans on a scheduled basis.
- Static Application Security Testing (SAST): Performed to analyze application source code, byte code, and binaries for design and coding vulnerabilities.
- Dynamic Application Security Testing (DAST): Performed to detect vulnerabilities within applications in their active, running state.
- Risk Evaluation & Remediation: Vulnerabilities are scored using an industry standard model, and reported to owners for remediation per established policy timelines.
- Metrics & Executive Reporting: Performance metrics are collected to confirm remediation, trend threats, and plan strategic EVM program improvements.
Implementing Strong Access Control Measures
Logical access control is strictly managed using the principles of least privilege and comprehensive identity verification.
- Logical Access Controls: Logical access control policies are defined, documented and managed to ensure that only authorized personnel have access to critical business applications and systems based on position and job requirements.
- Multi-Factor Authentication (MFA): Access to Verizon Assets requires the use of multi-factor authentication. Furthermore, to help ensure the highest level of security, customers engaging in high-risk transactions (such as large transfers or sensitive account changes) are now able to utilize multi-factor authentication for an added layer of protection (NIST-CSF PR.AA).
- Unique User Accountability: Verizon assigns a unique ID, consistent with Verizon’s information security policies, for employees, agents, and contractors to use when accessing Verizon Assets. User credentials must uniquely identify an individual person, system, or service, and access is reviewed on a periodic basis to validate requirements (NIST-CSF PR.AA).
- Principle of Least Privilege: Verizon utilizes the Principle of Least Privilege to manage access for each of its systems. Privileged access for production network, system or application functions are controlled and restricted to as few personnel as operationally feasible and is authorized on a “need to know” or “event by event” basis. Authorization reviews and role change processes alert administrators to modify or revoke access rights when an employee no longer requires access or leaves the company (NIST-CSF PR.AA).
Technology Infrastructure Resilience
- Resilience Planning: Verizon maintains business continuity and disaster recovery protocols designed to enhance Verizon’s ability to respond to significant events that might disrupt Verizon’s networks and facilities or otherwise impair Verizon’s ability to provide service.
- Risk Mitigation & Backup: Verizon’s business continuity and disaster recovery practices identify potential recovery risks to Verizon Assets, and implement measures designed to help minimize and mitigate those risks using industry-accepted practices. This is achieved by aligning security architecture with the risk management strategy to safeguard data confidentiality, ensure data integrity/accuracy via robust backups, and maintain system availability via redundant infrastructure (NIST-CSF PR.IR).
- Ransomware & Live Recovery Testing: Beyond basic backup and redundancy, Verizon actively tests technology resilience against common threats like ransomware through the use of dedicated playbooks and live recovery exercises (NIST-CSF PR.IR).
- Recovery Plan Execution: Verizon maintains a comprehensive and formalized incident recovery plan for the timely restoration of critical systems. This plan encompasses: (1) System Reconstruction to a pre-incident state; (2) Data Restoration from secure backups; (3) Formal Incident Closure after threat neutralization; and (4) Security Enhancements to prevent recurrence (NIST-CSF RC.RP).
Incident Management & Respond Capabilities
- Threat Management Center & Scope: Verizon maintains a written, actionable incident response plan to ensure timely reaction to Security Events, Security Incidents and Data Breaches by the Verizon Threat Management Center. The dedicated incident response team has responsibility for managing incidents to minimize losses, securely recover systems, and ensure compliance with international laws (NIST-CSF RS.MA).
- Incident Analysis: Verizon addresses the identification, management, and resolution of security issues requiring attention. Verizon employs a meticulous incident analysis methodology (NIST-CSF RS.AN) that surpasses established standards.
- Incident Mitigation: Verizon utilizes proactive mitigation strategies (NIST-CSF RS.MI), including rapid containment strategies, the immediate application of security patches, and swift compromised account management (detection and resetting of credentials).
- Threat Intelligence & Training: Verizon shares incident-related intelligence with law enforcement, industry peers, and ISACs. The incident response team receives appropriate onboarding and regular advanced training, supported by periodic company-wide tabletop exercises (NIST-CSF RS.MA).
- Communication & Reporting: Verizon communicates, consistent with contractual and legal obligations, the status of material issues affecting the Customer.
Last update, August, 2026