Skip to main content
Category: Information Governance Principles

Principle of Availability

Also known as: Availability
Simply put

The principle of availability holds that information and the systems that hold it should be accessible to authorized people when they need them. It is one of the three widely cited pillars of information security, alongside confidentiality and integrity. In practice, it means that access to information is timely and reliable, and not disrupted or interrupted.

Formal definition

Availability is the security property ensuring timely and reliable access to and use of information by authorized parties. As articulated in security frameworks such as the CIA triad and in definitions like that in FISMA, it addresses the accessibility and functional continuity of information, systems, resources, or services for authorized users when required. It should be distinguished from confidentiality and integrity, the other components of the triad; availability specifically concerns uninterrupted, dependable access rather than restricting disclosure or preserving accuracy. Note that this security-oriented sense of availability differs from any recordkeeping usage of the same term, and the definitions cited here derive from information security sources rather than records management standards.

Why it matters

Availability is one of the three widely cited pillars of information security, sitting alongside confidentiality and integrity in what is commonly known as the CIA triad. Its significance lies in a straightforward but consequential proposition: information that cannot be reached when it is needed provides little value, regardless of how well it is protected against unauthorized disclosure or how accurate it remains. For organizations that depend on records and information to conduct business, meet obligations, and support decisions, disruptions to timely and reliable access can carry operational, legal, and reputational costs.

Because availability concerns dependable, uninterrupted access rather than restricting who may see information, it can pull in a different direction from confidentiality. Controls that lock information down tightly to prevent disclosure may, if poorly designed, impede legitimate access by authorized users. A balanced security posture typically requires organizations to weigh availability against confidentiality and integrity rather than optimizing for any single property in isolation. The appropriate balance often depends on the sensitivity of the information, the criticality of the systems involved, and the organization's tolerance for interruption.

It is worth noting that this security-oriented sense of availability is distinct from any recordkeeping usage of the same word. Records and information governance professionals should be careful not to conflate the security property described here with concepts drawn from records management standards; the definitions in circulation derive from information security sources such as the CIA triad and statutory frameworks rather than from records management guidance.

Who it's relevant to

Information security and IT professionals
Those responsible for securing systems and information typically use the CIA triad, including availability, as a framework for identifying vulnerabilities and shaping protective measures. Availability is directly relevant to their work in ensuring that authorized users can reliably reach systems, resources, and services without interruption.
Information governance and records management practitioners
Governance and recordkeeping professionals benefit from understanding availability as a security property, particularly so they can distinguish it from any similarly named recordkeeping concepts. Because the definitions here derive from information security sources rather than records management standards, practitioners should apply the term with care and note the scope boundary when it arises in cross-disciplinary discussions.
Compliance and risk professionals
Those overseeing compliance and organizational risk may encounter availability as a component of statutory and framework-based security requirements, such as the definition associated with FISMA. For these professionals, availability is relevant to assessing whether authorized access to information is timely and reliable, and to weighing that objective against confidentiality and integrity.

Inside Principle of Availability

Timely retrieval
The Principle of Availability concerns an organization's capacity to locate and retrieve records within a reasonable timeframe and in a form suitable for the purpose at hand, whether operational, legal, or regulatory. The reasonable timeframe often depends on the nature of the request and applicable obligations.
Usability of retrieved records
Availability is not satisfied merely by a record existing somewhere; the record must be usable when produced, meaning it can be located, rendered, interpreted, and understood. This connects availability to related recordkeeping properties such as usability and integrity.
Relationship to the recordkeeping principles framework
Availability is typically presented as one of a set of principles within a recordkeeping accountability framework, such as the Generally Accepted Recordkeeping Principles. It is generally treated alongside, but distinct from, principles addressing integrity, protection, compliance, retention, and disposition.
Scope conditions and constraints
Availability operates within limits set by other obligations. Access may legitimately be restricted by privacy, security classification, confidentiality, or legal privilege, so availability means accessible to authorized users for authorized purposes rather than universally open.
Enabling infrastructure and practices
Effective availability depends on upstream practices such as accurate classification, indexing, metadata capture, and systems that support search and rendering over time, including as formats and technologies change.

Common questions

Answers to the questions practitioners most commonly ask about Principle of Availability.

Does the Principle of Availability mean an organization should keep all records accessible indefinitely?
No. Availability concerns ensuring that records can be located and retrieved in a timely and usable manner for as long as they are required, not that all records be retained or accessible indefinitely. The duration and level of accessibility are governed by retention schedules, business need, and applicable legal and regulatory requirements, which vary by jurisdiction and sector. Once a record reaches the end of its retention period and is subject to authorized disposition, continued availability is typically no longer expected and may in fact be undesirable.
Is availability the same as ensuring records are secure or protected from unauthorized access?
No, though the two are related and must be balanced. Availability addresses whether authorized users can find and retrieve records when needed. Security and access control address whether access is appropriately restricted to prevent unauthorized use. A record can be highly secure yet effectively unavailable if retrieval is impractical, and an available record must still be protected against improper access. In practice, availability is generally implemented alongside, and constrained by, security, privacy, and confidentiality obligations rather than in place of them.
How can an organization put the Principle of Availability into practice?
Organizations typically operationalize availability through consistent classification, indexing, and metadata capture that support search and retrieval, together with defined storage and format management so records remain locatable across their lifecycle. Documented procedures for who may retrieve records, and how, help ensure timely access for authorized users. The specific measures adopted often depend on organizational policy, the systems in use, and the nature and volume of the records concerned.
How does the Principle of Availability apply to records held in older or obsolete formats?
Availability can be threatened when records are stored in formats or on media that are no longer readily readable. Maintaining availability over time often involves format and media management strategies, such as migration or the maintenance of appropriate access tools, so that records remain usable for their full retention period. The appropriate approach depends on organizational policy, the anticipated retention duration, and the resources and technology available.
How should availability requirements be balanced against privacy and access restrictions?
Availability is generally applied within the boundaries set by privacy, confidentiality, and access-control obligations, which differ across jurisdictions and sectors. In practice this means ensuring records are retrievable by those authorized to access them, while restrictions prevent access by others. Organizations often reconcile these aims by defining access permissions tied to roles and by aligning retrieval procedures with applicable legal and policy requirements.
How can an organization demonstrate that it is meeting the Principle of Availability?
Demonstrating availability typically relies on evidence that records can be located and retrieved when required, such as functioning search and indexing capabilities, documented retrieval procedures, and records of how access requests are handled. The extent and formality of such evidence often depend on organizational policy and on any external requirements, for example those arising from audits, legal processes, or information-access obligations, which vary by jurisdiction.

Common misconceptions

Availability means all records should be openly accessible to everyone.
Availability typically refers to accessibility for authorized users and legitimate purposes. It coexists with, and is constrained by, obligations relating to privacy, security, confidentiality, and legal privilege, which vary by jurisdiction and sector. It does not imply unrestricted or public access.
If a record has been retained and stored, availability is automatically satisfied.
Retention and storage alone do not guarantee availability. A record must also be locatable and usable when needed, which depends on classification, indexing, metadata, and the continued ability to render it. Retention concerns keeping a record for a defined period, whereas availability concerns the ability to find and use it during that period.
Availability is the same as the technical concept of system uptime.
In recordkeeping, availability is broader than infrastructure uptime. It addresses whether authoritative records can be retrieved and understood in a usable form for a given purpose, which involves organization, description, and interpretability, not simply whether a system is operational.

Best practices

Establish and maintain consistent classification, indexing, and metadata practices at the point of capture so that records can be located and interpreted later.
Define reasonable retrieval expectations that reflect operational needs and applicable legal or regulatory obligations, recognizing that acceptable timeframes vary by request type and jurisdiction.
Balance availability against protection obligations by implementing access controls that permit authorized users and purposes while safeguarding privacy, security, and confidentiality.
Plan for long-term usability by monitoring format and technology obsolescence and taking steps to ensure records remain renderable and understandable over their retention periods.
Test retrieval capability periodically, for example through search and production exercises, to confirm that records can in practice be located and produced in a usable form rather than assuming availability from the fact of storage.
Coordinate availability practices with related principles such as integrity and retention, and document the controls and limitations so that the organization can demonstrate defensible, accountable recordkeeping.