Downtime
What is Downtime?
A period when a system, service, or network is unavailable or not functioning, potentially impacting business operations.
Terms that appear alongside downtime
Each of these is named in at least one of the same controls as downtime. The number is how many controls name both.
- nist 4 shared controls
- disruption 3 shared controls
- disaster recovery 3 shared controls
- iso 22301 3 shared controls
- crisis management 3 shared controls
- business impact analysis 3 shared controls
- redundancy 3 shared controls
- business continuity 3 shared controls
Frameworks that govern downtime
What the standards actually require on downtime
Requirements naming downtime across 6 standards, quoted from the control text.
Test restore procedures at least annually so that adherence to contractual agreements and to the defined maximum tolerable downtime and maximum permissible data loss can be assessed, and report any deviation to responsible personnel for prompt action.
C5-OPS-08 · Data Backup and Recovery - Regular Testing →Requires validation of information systems, documented downtime procedures, and oversight of off-site data providers.
ISO-15189-7.6 · Data and information management →Security Dimension 7 Availability per X.805 Clause 6.7: Availability ensures that there is no denial of authorized access to network elements + stored information + information flows + services and applications due to events impacting the network.
X805-Dim7-Availability-Network-Resources-Information-Authorized-Access-No-Service-Denial · ITU-T X.805 Security Dimension 7 - Availability + Network Resources + Information Accessible to Authorized Users + Denial-of-Service Prevention + Resilience + Redundancy + Disaster Recovery + Business Continuity + DDoS Mitigation →Continuous Monitoring + Lifecycle Management is essential to ongoing trustworthy AI per Japan AI Guidelines for Business + integrates Safety + Accountability + Transparency Principles + addresses post-deployment risks.
JP-AIG-Continuous-Monitoring-Lifecycle-Model-Evaluation-Performance-Drift-Post-Deployment · Japan AI Guidelines Continuous Monitoring + AI System Lifecycle Management + Model Evaluation + Performance Drift + Concept Drift + Post-Deployment + Retraining Triggers + Safe Update + Decommissioning + Model Card Versioning →Vulnerability Management is a core technical control area per FSA Cybersecurity Guidelines. (1) Vulnerability Discovery: (a) Authenticated and Unauthenticated Scanning - Nessus + Qualys + Rapid7 + open source; (b) DAST Dynamic Application Security Testing;
JP-FSA-CYB-Vulnerability-Management-Patching-CVE-Risk-Based-Prioritisation-Penetration-Testing-Red-Team · Japan FSA Cybersecurity Vulnerability Management + Patching + CVE Tracking + Risk-Based Prioritisation + Penetration Testing + Red-Team + Bug Bounty + Coordinated Vulnerability Disclosure + Zero-Day Response →Kuwait NCF Respond and Recover functions. Incident Response and Reporting: documented Incident Response Plan + Computer Security Incident Response Team (CSIRT) + 24/7 incident hotline + Incident classification (severity + impact + urgency) + Triage + Containme...
KNCF-Respond-Incident-Response-Reporting-Recover-Business-Continuity-Cyber-Resilience-NCSC-Notification · Kuwait NCF Respond + Incident Response + Reporting + Recover + BC + Cyber Resilience + NCSC →Questions people ask about downtime
What is Downtime?
Why is Downtime important for compliance?
Which compliance frameworks address Downtime?
Where can I learn more about Downtime?
See how Downtime applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.