Information Availability: An Insight into the Most Important Attribute of Information Security
- 1 Department of Computer Sciences, University of Kashmir, Srinagar, India
- 2 Department of Computer Sciences, University of Kashmir, Srinagar, India
Abstract
This paper presents an in-depth understanding of Availability, which is one of the important pillars of Information Security and yet is not taken too seriously while talking about the security of an information system. The paper highlights the importance of Availability w.r.t. Security of information and the other attributes of security and also gives a realistic shape to the existing CIA triad security model. An in-depth understanding of the various factors that can impact the Availability of an information system (Software, Hardware and Network) is given. The paper also gives a categorization of the type of Availability that a system can have. The paper also explains the relation between Availability and other security attributes and also explains through what issues an information system may go while providing Availability.
- Guttman, B. and Roback, E. (1995) An Introduction to Computer security: The NIST Handbook. DIANE Publishing. http://dx.doi.org/10.6028/NIST.SP.800-12
- Whitman, M.E. (2003) Enemy at the Gate: Threats to Information Security. Communications of the ACM, 46, 91-95. http://dx.doi.org/10.1145/859670.859675
- Khazanchi, D. and Martin, A.P. (2008) Information Availability. Handbook of Research on Information Security and Assurance. http://dx.doi.org/10.4018/978-1-59904-855-0.ch019
- Information Security (2001) Wikipedia, the Free Encyclopaedia. http://en.wikipedia.org/wiki/Information_security
- Andress, J. (2014) The Basics of Information Security: Understanding the Fundamentals of InfoSec in Theory and Practice. Syngress.
- Chivers, H. (2004) Security and Systems Engineering. Report-University of York Department of Computer Science Ycs.
- Latham, D.C. (1986) Department of Defense Trusted Computer System Evaluation Criteria. Department of Defense.
- DARPA (2008) Wikipedia, the Free Encyclopaedia. http://en.wikipedia.org/wiki/DARPA
- Gligor, V.D. (1986) On Denial-of-Service in Computer Networks. Proceedings of the 2nd International Conference on Data Engineering, Los Angeles, 5-7 February 1986, 608-617. http://dx.doi.org/10.1109/icde.1986.7266268
- Information Technology Security Evaluation Criteria (ITSEC), Provisional Harmonized Criteria (1991) Luxembourg: Office for Official Publications of the European Communities, 1991 ISBN 92-826-3004-8, Catalogue Number: CD-71-91-502-EN-C©ECSC-EEC-EAEC, Brussels• Luxembourg.
- Trusted Network Interpretation of the TCSEC (“The Red Book”) (1987) US Department of Defence, NCSC-TG-005. http://csrc.nist.gov/publications/secpubs/rainbow/tg005.txt
- Millen, J.K. (1995) Denial of Service: A Perspective. In: Cristian, F., Le Lann, G. and Lunt, T., Eds., Dependable Computing for Critical Applications 4, Springer, Vienna, 93-108. http://dx.doi.org/10.1007/978-3-7091-9396-9_10
- National Information Systems Security (InfoSec) Glossary (2000) National Security Telecommunications and Information Systems Security Committee. National Security Agency US.
- Pfleeger, C.P. (1997) Security in Computing. Second Edition, Prentice Hall, Upper Saddle River.
- Parker, D.B. (1991) Restating the Foundation of Information Security. Computer Audit Update, 1991, 2-15. http://dx.doi.org/10.1016/0960-2593(91)90013-Y