Principle of Availability
The principle of availability holds that information and the systems that hold it should be accessible to authorized people when they need them. It is one of the three widely cited pillars of information security, alongside confidentiality and integrity. In practice, it means that access to information is timely and reliable, and not disrupted or interrupted.
Availability is the security property ensuring timely and reliable access to and use of information by authorized parties. As articulated in security frameworks such as the CIA triad and in definitions like that in FISMA, it addresses the accessibility and functional continuity of information, systems, resources, or services for authorized users when required. It should be distinguished from confidentiality and integrity, the other components of the triad; availability specifically concerns uninterrupted, dependable access rather than restricting disclosure or preserving accuracy. Note that this security-oriented sense of availability differs from any recordkeeping usage of the same term, and the definitions cited here derive from information security sources rather than records management standards.
Why it matters
Availability is one of the three widely cited pillars of information security, sitting alongside confidentiality and integrity in what is commonly known as the CIA triad. Its significance lies in a straightforward but consequential proposition: information that cannot be reached when it is needed provides little value, regardless of how well it is protected against unauthorized disclosure or how accurate it remains. For organizations that depend on records and information to conduct business, meet obligations, and support decisions, disruptions to timely and reliable access can carry operational, legal, and reputational costs.
Because availability concerns dependable, uninterrupted access rather than restricting who may see information, it can pull in a different direction from confidentiality. Controls that lock information down tightly to prevent disclosure may, if poorly designed, impede legitimate access by authorized users. A balanced security posture typically requires organizations to weigh availability against confidentiality and integrity rather than optimizing for any single property in isolation. The appropriate balance often depends on the sensitivity of the information, the criticality of the systems involved, and the organization's tolerance for interruption.
It is worth noting that this security-oriented sense of availability is distinct from any recordkeeping usage of the same word. Records and information governance professionals should be careful not to conflate the security property described here with concepts drawn from records management standards; the definitions in circulation derive from information security sources such as the CIA triad and statutory frameworks rather than from records management guidance.
Who it's relevant to
Inside Principle of Availability
Common questions
Answers to the questions practitioners most commonly ask about Principle of Availability.