Availability
Availability means that authorized users can access information and systems when they need them, without unreasonable delay or interruption. It is one of the core goals of information security, alongside confidentiality and integrity. In practice, it covers keeping data and services reliably reachable and usable rather than protecting them from being seen or altered.
Availability is a security objective concerned with ensuring timely and reliable access to and use of information and systems, as framed in the U.S. FISMA context. It forms one leg of the confidentiality, integrity, and availability (CIA) triad and is supported by controls such as redundancy, resilience, capacity planning, backup and recovery, and protection against denial-of-service conditions. Availability is a security property rather than a data governance concept; it addresses reliable access to information and does not, on its own, speak to data ownership, quality, lineage, or lawful processing. This entry defines the concept only and does not cover specific service-level targets, uptime metrics, or jurisdiction-specific regulatory obligations, which vary by framework and implementation.
Why it matters
Availability is one of the three core objectives of the CIA triad, and it addresses a failure mode that is distinct from the risks of unauthorized disclosure or unauthorized alteration. A system can be perfectly confidential and its data perfectly intact, yet still fail its users if it cannot be reached when needed. For organizations that depend on continuous access to information and services, an availability failure can halt operations, disrupt service to customers, and prevent authorized users from doing their work, even when no data has been exposed or corrupted.
Understanding availability as a security property helps teams avoid the common mistake of treating security purely as a matter of keeping data secret. Denial-of-service conditions, capacity exhaustion, and loss of resilience are security concerns precisely because they undermine the timely and reliable access that availability is meant to guarantee. Framing these risks under availability ensures they receive attention alongside confidentiality and integrity rather than being deferred as mere operational or infrastructure matters.
It is important to keep availability in its proper scope. Availability speaks to whether authorized users can access information and systems when they need them; it does not, on its own, address data ownership, quality, lineage, or the lawful basis for processing personal data. Those are governance and legal questions that a strong availability posture neither satisfies nor replaces. This entry defines the concept only and does not cover specific service-level targets, uptime metrics, or jurisdiction-specific regulatory obligations, which vary by framework and implementation.
Who it's relevant to
Inside Availability
Common questions
Answers to the questions practitioners most commonly ask about Availability.