Availability is one of the three pillars of the CIA Triad (alongside Confidentiality and Integrity) and ensures that information, systems and services are accessible to authorised users whenever they are needed. It is maintained through redundancy, resilient architecture, capacity planning, backups, disaster recovery and protection against disruptions such as hardware failure, outages and denial-of-service attacks.
A loss of availability — an outage, a ransomware lockout or an overloaded service — can halt operations, breach contractual SLAs and cause direct financial and reputational harm. ISO 27001 addresses availability through Annex A controls covering business continuity, redundancy, backup and capacity management. Organisations typically set measurable availability targets and track them through uptime metrics and recovery objectives (RTO/RPO).