Availability
What is Availability?
The property of being accessible and usable upon demand by authorized users, one of the three pillars of information security along with confidentiality and integrity.
Terms that appear alongside availability
Each of these is named in at least one of the same controls as availability. The number is how many controls name both.
- integrity 106 shared controls
- confidentiality 86 shared controls
- nist 36 shared controls
- cybersecurity 29 shared controls
- resilience 29 shared controls
- encryption 27 shared controls
- incident response 21 shared controls
- audit 21 shared controls
Frameworks that govern availability
What the standards actually require on availability
Requirements naming availability across 6 standards, quoted from the control text.
Continuous real-time monitoring of the capacity and availability of online services is performed.
ISM-1581 · Continuous real-time monitoring of the capacity and availability of online services is per →Security Dimension 7 Availability per X.805 Clause 6.7: Availability ensures that there is no denial of authorized access to network elements + stored information + information flows + services and applications due to events impacting the network.
X805-Dim7-Availability-Network-Resources-Information-Authorized-Access-No-Service-Denial · ITU-T X.805 Security Dimension 7 - Availability + Network Resources + Information Accessible to Authorized Users + Denial-of-Service Prevention + Resilience + Redundancy + Disaster Recovery + Business Continuity + DDoS Mitigation →Monitor the system components used for logging and monitoring themselves, and report their failures automatically and promptly to the responsible departments so the loss of visibility is assessed and the required action taken.
C5-OPS-17 · Logging and Monitoring - Availability of the Monitoring Software →Capacity and availability management. Control from ITIL 4 framework, domain: ITIL 4: Service Strategy & Design.
ITIL4-03 · Capacity and availability management →Maintain availability of information in event of loss of cryptographic keys via key escrow or recovery; HIGH only.
SC-12(1) · Availability →Adequate resource capacity to ensure availability is maintained. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect.
NIST-CSF-PR.IR-04 · Adequate resource capacity to ensure availability is maintained →Questions people ask about availability
What is Availability?
Why is Availability important for compliance?
Which compliance frameworks address Availability?
Where can I learn more about Availability?
See how Availability applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.