Availability
Availability → measure of how consistently systems and services are accessible when needed, focusing on uptime and minimizing disruptions to users.
Resilience
Resilience → ability of infrastructure to withstand failures or attacks and continue operating or quickly recover without major service impact.
MTTR
Mean time to recovery (MTTR) → average amount of time required to restore a system or service after a failure, used to measure operational effectiveness.
Responsiveness
Responsiveness → how quickly systems react to user requests or changes in demand, directly affecting performance and user experience.
Scalability
Scalability → ability of infrastructure to handle increased workload by adding resources, either vertically or horizontally, without redesigning the system.
Elasticity
Elasticity → ability to automatically scale resources up or down in real time based on demand, commonly associated with cloud environments.
Ease of Deployment
Ease of deployment → how quickly and reliably systems, updates, or applications can be deployed, impacting agility and operational efficiency.
Risk Transferance
Risk transference → strategy where financial risk is shifted to a third party, commonly through cybersecurity insurance, without eliminating the underlying threat.
Ease of Recovery
Ease of recovery → how quickly and reliably systems can be restored after an incident using backups, snapshots, or disaster recovery processes.
Patch Availability
Patch availability → whether vendors provide timely security updates to fix known vulnerabilities, directly affecting long-term system security.
Inability of Patch
Inability to patch → situation where systems cannot be updated due to legacy software, operational constraints, or vendor limitations, increasing security risk.
Power
Power → infrastructure consideration involving reliable electrical supply, backup generators, and uninterruptible power systems to maintain availability.
Compute
Compute → processing capacity of systems, including central processing unit and memory resources, which determines performance and workload handling.
Security Zones
Security zones → segmented areas of infrastructure grouped by trust level to limit access and reduce lateral movement during an attack.
Attack Surface
Attack surface → total number of exposed entry points, services, interfaces, and vulnerabilities that attackers could potentially exploit.