Denial of Service
What is Denial of Service?
An attack that disrupts normal functioning of a targeted server, service, or network by overwhelming it with a flood of traffic or requests.
Terms that appear alongside denial of service
Each of these is named in at least one of the same controls as denial of service. The number is how many controls name both.
- availability 8 shared controls
- access control 4 shared controls
- distributed denial of service 4 shared controls
- incident response 4 shared controls
- resilience 3 shared controls
- ransomware 3 shared controls
- policy 3 shared controls
- disruption 2 shared controls
Frameworks that govern denial of service
What the standards actually require on denial of service
Requirements naming denial of service across 6 standards, quoted from the control text.
A denial of service response plan for video conferencing and IP telephony services is developed, implemented and maintained.
ISM-1019 · A denial of service response plan for video conferencing and IP telephony services is deve →Components shall provide the capability to maintain essential functions under DoS conditions and recover automatically where feasible, particularly for embedded devices controlling physical processes.
62443-4-2-CR-7-1 · Component Denial-of-Service Protection →Security Dimension 7 Availability per X.805 Clause 6.7: Availability ensures that there is no denial of authorized access to network elements + stored information + information flows + services and applications due to events impacting the network.
X805-Dim7-Availability-Network-Resources-Information-Authorized-Access-No-Service-Denial · ITU-T X.805 Security Dimension 7 - Availability + Network Resources + Information Accessible to Authorized Users + Denial-of-Service Prevention + Resilience + Redundancy + Disaster Recovery + Business Continuity + DDoS Mitigation →Plan for denial of service conditions on signaling and user plane interfaces. Apply rate limiting on attach storms, dimension MME and SGW capacity headroom, and have a documented response for paging amplification attempts.
SP800-187-3.14 · Denial of Service Mitigation →Denial-of-service protection. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: System & Communications Protection.
BSI-09 · Denial-of-service protection →Denial-of-service protection. Implements CyFun PR.DS-4 / PR.PT-4: adequate capacity to ensure availability is maintained and communications networks are protected against denial-of-service.
BE-CF-09 · Denial-of-service protection →Questions people ask about denial of service
What is Denial of Service?
Why is Denial of Service important for compliance?
Which compliance frameworks address Denial of Service?
Where can I learn more about Denial of Service?
See how Denial of Service applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.