Availability Services

Availability services provide another source for security process data which allows the organization to determine the effectiveness of its controls. The performance of availability services directly affects whether an organization can meet its commitments to its customers and its compliance obligations.

4 slides · 2 min read · Domain 6

Slide 1

Availability data is routinely subject to assessment and audit, and careful planning is necessary to ensure the organization can demonstrate its compliance to controls assessors.

Backups

System and data backups take a wide variety of forms and support an equally diverse range of purposes. While the mechanisms for performing backup and restoration activities are discussed later, planning for availability services and collecting security process data related to the organization's backup and restoration processes is an essential part of virtually every security controls and compliance framework.

Roles and Responsibilities

The development of an organizational availability program is an extension of the organization's risk management practice. While the execution of the majority of the backup processes would likely be the responsibility of the information technology organization, the work would be directed by the risks of data loss or system failure.

Compliance Requirements

ISO 27001, Annex A: 12.3 Backup, is the principal control addressing backup, but the need for backup services is addressed in a variety of different controls in the standard. Similarly, the FIPS 200 Control Families of Contingency Planning (CP) and Media Protection (MP) address aspects of backup for US government agencies information systems.

Other compliance frameworks also require backup and availability services. The Health Insurance and Portability and Accountability Act (HIPAA) requires organizations to have both a data backup plan and a business contingency plan, while the Trust Services Criteria (TSP) for Availability places similar expectations on organizations being audited for System Organization Control (SOC) 2 reports.

Roles and Responsibilities

The development of an organizational availability program is an extension of the organization's risk management practice. While the execution of the majority of the backup processes would likely be the responsibility of the information technology organization, the work would be directed by the risks of data loss or system failure.

Other compliance frameworks also require backup and availability services. The Health Insurance and Portability and Accountability Act (HIPAA) requires organizations to have both a data backup plan and a business contingency plan, while the Trust Services Criteria (TSP) for Availability places similar expectations on organizations being audited for System Organization Control (SOC) 2 reports.

Test this domain