1
00:00:00,000 --> 00:00:00,870
In this lesson,

2
00:00:00,870 --> 00:00:02,880
we're going to cover availability.

3
00:00:02,880 --> 00:00:05,730
Now, availability in information security is used to ensure

4
00:00:05,730 --> 00:00:09,060
that information, systems and resources are accessible

5
00:00:09,060 --> 00:00:12,210
and operational when needed by authorized users.

6
00:00:12,210 --> 00:00:14,310
In simpler terms, availability is all

7
00:00:14,310 --> 00:00:16,200
about making sure that services, systems

8
00:00:16,200 --> 00:00:19,590
and data are always available when they're supposed to be.

9
00:00:19,590 --> 00:00:20,700
Let's pretend for a moment

10
00:00:20,700 --> 00:00:22,440
that you have an important online meeting scheduled

11
00:00:22,440 --> 00:00:25,050
for 10:00 AM tomorrow but just minutes before that,

12
00:00:25,050 --> 00:00:26,910
your internet connection goes down.

13
00:00:26,910 --> 00:00:28,740
This would be super frustrating for you

14
00:00:28,740 --> 00:00:29,640
and now you're not going to be able

15
00:00:29,640 --> 00:00:31,080
to attend the meeting, right?

16
00:00:31,080 --> 00:00:33,600
Well, this situation emphasizes the importance

17
00:00:33,600 --> 00:00:36,720
of availability in our increasingly connected world.

18
00:00:36,720 --> 00:00:39,210
Just as you'd want your internet to always be up and running

19
00:00:39,210 --> 00:00:42,090
especially during critical times, in that same vein,

20
00:00:42,090 --> 00:00:44,100
businesses need their systems and services

21
00:00:44,100 --> 00:00:45,750
to be available around the clock

22
00:00:45,750 --> 00:00:47,280
to meet their customer demands

23
00:00:47,280 --> 00:00:49,650
and to maintain their brand's reputation.

24
00:00:49,650 --> 00:00:51,030
When you're considering which system

25
00:00:51,030 --> 00:00:52,470
or service provider to use

26
00:00:52,470 --> 00:00:53,700
you're often going to hear them refer

27
00:00:53,700 --> 00:00:54,870
to their availability status

28
00:00:54,870 --> 00:00:57,390
by a number of nines that they can provide.

29
00:00:57,390 --> 00:00:58,830
For example, three nines

30
00:00:58,830 --> 00:01:02,400
of availability equates to 99.9% uptime.

31
00:01:02,400 --> 00:01:05,640
This means that in a standard calendar year with 365 days,

32
00:01:05,640 --> 00:01:08,430
we have 8,760 hours available.

33
00:01:08,430 --> 00:01:12,240
So a system with 99.9% uptime can be down

34
00:01:12,240 --> 00:01:15,030
for a maximum of 8.76 hours.

35
00:01:15,030 --> 00:01:16,830
If that's too much downtime for you though,

36
00:01:16,830 --> 00:01:18,300
you can actually go and find a provider

37
00:01:18,300 --> 00:01:20,520
who has more nines of availability.

38
00:01:20,520 --> 00:01:22,710
For example, I used to work for a service provider

39
00:01:22,710 --> 00:01:25,560
that had to maintain five nines of availability.

40
00:01:25,560 --> 00:01:28,140
Now, five nines is considered to be the gold standard

41
00:01:28,140 --> 00:01:30,270
and this means we have to achieve a system uptime

42
00:01:30,270 --> 00:01:33,210
of 99.999%.

43
00:01:33,210 --> 00:01:35,460
Now, if you translate this into minutes or hours

44
00:01:35,460 --> 00:01:37,920
this actually means that our system has to guarantee

45
00:01:37,920 --> 00:01:39,330
that we are going to have a downtime

46
00:01:39,330 --> 00:01:43,950
of no more than 5.26 minutes in any given calendar year.

47
00:01:43,950 --> 00:01:45,000
Achieving this gold standard

48
00:01:45,000 --> 00:01:46,800
of availability ensures that services

49
00:01:46,800 --> 00:01:48,750
and applications are virtually always going

50
00:01:48,750 --> 00:01:51,660
to be accessible to our users, and it minimizes disruptions

51
00:01:51,660 --> 00:01:53,820
and potential revenue loss events.

52
00:01:53,820 --> 00:01:55,200
To put this into perspective,

53
00:01:55,200 --> 00:01:57,690
while a 99% uptime may seem high,

54
00:01:57,690 --> 00:02:00,450
it still allows you to have over 3.5 days

55
00:02:00,450 --> 00:02:02,880
of downtime per year, whereas the five nines

56
00:02:02,880 --> 00:02:06,780
of availability slashes that down to a mere five minutes.

57
00:02:06,780 --> 00:02:08,910
This level of reliability means we're going to have

58
00:02:08,910 --> 00:02:11,370
to have a robust infrastructure, proactive monitoring,

59
00:02:11,370 --> 00:02:14,250
redundancy measures, and swift disaster recovery mechanisms

60
00:02:14,250 --> 00:02:17,100
in order to achieve five nines of availability.

61
00:02:17,100 --> 00:02:18,810
Now, as cybersecurity professionals,

62
00:02:18,810 --> 00:02:20,490
we do value availability

63
00:02:20,490 --> 00:02:22,650
because it helps us to ensure business continuity,

64
00:02:22,650 --> 00:02:23,880
to maintain our customer trust

65
00:02:23,880 --> 00:02:26,610
and to uphold our organization's reputation.

66
00:02:26,610 --> 00:02:27,810
Now, first, we need to talk

67
00:02:27,810 --> 00:02:29,850
about ensuring business continuity.

68
00:02:29,850 --> 00:02:31,440
Every minute your system is down

69
00:02:31,440 --> 00:02:34,260
your business might be facing significant losses.

70
00:02:34,260 --> 00:02:35,430
For an e-commerce site,

71
00:02:35,430 --> 00:02:37,170
this can mean a direct loss in sales.

72
00:02:37,170 --> 00:02:39,930
For a hospital, it can mean a life-threatening situation

73
00:02:39,930 --> 00:02:42,240
if a critical system isn't operational.

74
00:02:42,240 --> 00:02:44,970
For example, in the telecommunications industry,

75
00:02:44,970 --> 00:02:47,310
a single hour of downtime can cost them

76
00:02:47,310 --> 00:02:49,530
on average $2 million.

77
00:02:49,530 --> 00:02:51,570
That means that for every minute of downtime,

78
00:02:51,570 --> 00:02:55,170
they're losing about $33,000 per minute.

79
00:02:55,170 --> 00:02:57,900
Second, we have maintaining customer trust.

80
00:02:57,900 --> 00:02:59,910
Now, if customers can't access their accounts,

81
00:02:59,910 --> 00:03:01,800
purchase their products or use services

82
00:03:01,800 --> 00:03:03,690
because your system is down, their trust

83
00:03:03,690 --> 00:03:05,730
in your company is going to go down.

84
00:03:05,730 --> 00:03:08,250
If you suffer from a prolonged unavailability event,

85
00:03:08,250 --> 00:03:09,750
this can actually cause your customers to look

86
00:03:09,750 --> 00:03:12,390
for alternative solutions and purchase products or services

87
00:03:12,390 --> 00:03:15,450
from your competitors, causing you to lose revenue.

88
00:03:15,450 --> 00:03:16,320
Third and finally,

89
00:03:16,320 --> 00:03:19,020
we have upholding your organization's reputation.

90
00:03:19,020 --> 00:03:21,060
Now, if you have repeated downtime events,

91
00:03:21,060 --> 00:03:23,400
this is not only going to affect your business operations

92
00:03:23,400 --> 00:03:25,650
but also tarnishes your organization's image

93
00:03:25,650 --> 00:03:26,580
in the long run.

94
00:03:26,580 --> 00:03:27,870
And this will make it more challenging

95
00:03:27,870 --> 00:03:30,420
to regain those customers' confidence in your organizations

96
00:03:30,420 --> 00:03:32,490
if they leave you for another provider.

97
00:03:32,490 --> 00:03:34,650
Now, in order to overcome the challenges associated

98
00:03:34,650 --> 00:03:36,930
with maintaining high levels of availability,

99
00:03:36,930 --> 00:03:38,910
the best strategy is to use redundancy

100
00:03:38,910 --> 00:03:41,520
in all of your systems and network designs.

101
00:03:41,520 --> 00:03:43,170
Now, redundancy is the duplication

102
00:03:43,170 --> 00:03:44,760
of critical components or functions

103
00:03:44,760 --> 00:03:48,090
of a system with the intention of enhancing its reliability.

104
00:03:48,090 --> 00:03:50,700
In simple words, it's about having backup options

105
00:03:50,700 --> 00:03:52,530
to ensure uninterrupted service.

106
00:03:52,530 --> 00:03:53,970
If one of your systems fails,

107
00:03:53,970 --> 00:03:57,330
the backup should take over, ensuring constant availability.

108
00:03:57,330 --> 00:03:59,730
Think of it as having a spare tire in your car.

109
00:03:59,730 --> 00:04:02,130
If one tire gets punctured, you're able to go out

110
00:04:02,130 --> 00:04:03,660
and immediately replace it with your spare

111
00:04:03,660 --> 00:04:06,600
and continue your journey without a significant delay.

112
00:04:06,600 --> 00:04:09,450
For example, I used to live on the island of Puerto Rico

113
00:04:09,450 --> 00:04:11,370
and down there we often faced hurricanes

114
00:04:11,370 --> 00:04:12,840
and other natural disasters

115
00:04:12,840 --> 00:04:15,060
that could affect our business operations.

116
00:04:15,060 --> 00:04:17,670
Now, to overcome the threat of losing internet at my office

117
00:04:17,670 --> 00:04:19,950
I actually had three different internet connections.

118
00:04:19,950 --> 00:04:20,910
One was from a dedicated

119
00:04:20,910 --> 00:04:22,770
microwave wireless service provider,

120
00:04:22,770 --> 00:04:24,990
one was a connection from my local cable company

121
00:04:24,990 --> 00:04:27,300
and one was provided by a cellular modem.

122
00:04:27,300 --> 00:04:29,100
Now, if the microwave link went down,

123
00:04:29,100 --> 00:04:30,630
then our systems automatically switched over

124
00:04:30,630 --> 00:04:31,680
to the cable modem.

125
00:04:31,680 --> 00:04:33,330
If the cable modem also went down,

126
00:04:33,330 --> 00:04:35,220
we would switch over to the cellular modem.

127
00:04:35,220 --> 00:04:37,680
This way, regardless of what kind of outage occurred,

128
00:04:37,680 --> 00:04:38,940
we had redundancy in place

129
00:04:38,940 --> 00:04:41,610
to maintain the continuity of our operations.

130
00:04:41,610 --> 00:04:42,630
Now, there are various types

131
00:04:42,630 --> 00:04:44,010
of redundancy that you need to consider

132
00:04:44,010 --> 00:04:46,200
when you're designing your systems and your networks.

133
00:04:46,200 --> 00:04:48,930
This includes server redundancy, data redundancy,

134
00:04:48,930 --> 00:04:51,570
network redundancy, and power redundancy.

135
00:04:51,570 --> 00:04:53,730
First, we have server redundancy.

136
00:04:53,730 --> 00:04:56,010
Server redundancy involves using multiple servers

137
00:04:56,010 --> 00:04:59,070
in a load balance or failover configuration, so that if one

138
00:04:59,070 --> 00:05:01,680
of those is overloaded or fails, the other servers

139
00:05:01,680 --> 00:05:04,860
can take over the load and continue to support your users.

140
00:05:04,860 --> 00:05:07,080
Second, we have data redundancy.

141
00:05:07,080 --> 00:05:10,200
Data redundancy involves storing data in multiple places.

142
00:05:10,200 --> 00:05:12,300
This way, if one storage site fails,

143
00:05:12,300 --> 00:05:15,090
the data can still be accessed from another location.

144
00:05:15,090 --> 00:05:18,870
Often we achieve this locally using raids or using a hybrid

145
00:05:18,870 --> 00:05:21,810
of on-premise and cloud-based backup systems.

146
00:05:21,810 --> 00:05:23,910
Third, we have network redundancy.

147
00:05:23,910 --> 00:05:25,320
Now, network redundancy ensures

148
00:05:25,320 --> 00:05:26,730
that if one network path fails,

149
00:05:26,730 --> 00:05:29,130
the data can still travel through another route.

150
00:05:29,130 --> 00:05:31,710
This is how I set up my old offices in Puerto Rico so that

151
00:05:31,710 --> 00:05:34,290
if the microwave link went down, we switched over to cable.

152
00:05:34,290 --> 00:05:35,460
If the cable went down,

153
00:05:35,460 --> 00:05:37,590
we switched over to cellular, and this way we

154
00:05:37,590 --> 00:05:39,240
could continue providing network connectivity

155
00:05:39,240 --> 00:05:40,770
to all of our users.

156
00:05:40,770 --> 00:05:43,320
Fourth and finally, we have power redundancy.

157
00:05:43,320 --> 00:05:46,020
Power redundancy involves using backup power sources,

158
00:05:46,020 --> 00:05:48,960
like generators and uninterrupted power supply systems

159
00:05:48,960 --> 00:05:50,550
to ensure that your organization's systems

160
00:05:50,550 --> 00:05:53,370
remain operational even during periods of power disruption

161
00:05:53,370 --> 00:05:56,100
or outages within your local service area.

162
00:05:56,100 --> 00:05:59,430
So remember, availability is used to ensure that the data

163
00:05:59,430 --> 00:06:02,280
and systems are always ready for use when they're needed.

164
00:06:02,280 --> 00:06:04,530
The principle of redundancy plays a pivotal role

165
00:06:04,530 --> 00:06:06,390
in guaranteeing this uninterrupted service

166
00:06:06,390 --> 00:06:08,670
and achieving your higher levels of availability.

167
00:06:08,670 --> 00:06:10,680
So you should associate the term availability

168
00:06:10,680 --> 00:06:13,440
with redundancy because they go hand in hand.

169
00:06:13,440 --> 00:06:15,030
In a world where time is money

170
00:06:15,030 --> 00:06:16,590
and every second is going to count,

171
00:06:16,590 --> 00:06:18,240
ensuring the constant availability

172
00:06:18,240 --> 00:06:20,460
of your services is not just beneficial,

173
00:06:20,460 --> 00:06:23,220
it's imperative for your organization's continued success

174
00:06:23,220 --> 00:06:24,483
in this digital age.

