View Categories

A8.14 Redundancy of information processing facilities

4 min read

ISO 27001 A8.14 Redundancy of information processing facilities focuses on maintaining service continuity through resilient system design. The objective is to minimize downtime and data loss during incidents such as hardware failures, power outages, or natural disasters. Redundancy supports high availability (HA), disaster recovery (DR), and business continuity planning.

Redundancy ensures the continued availability of critical systems and services by deploying alternate or duplicate components that can take over in the event of a failure. This includes hardware, network connections, power supplies, data storage, and entire processing environments.

Implementation Guide #

Step 1: Identify Critical Systems and Services

  • Conduct a business impact analysis to determine which systems require redundancy.
  • Prioritize systems supporting financial, operational, customer-facing, and compliance-critical functions.

→ Tool Recommendation: ServiceNow BIA Module, Fusion Risk Management

Step 2: Design Redundant Architectures

  • Implement failover clusters and load balancers for applications and databases.
  • Use redundant power supplies (UPS and generators), network paths, and cooling systems in data centers.

→ Tool Recommendation:

  • Failover and Load Balancing: HAProxy, NGINX, Microsoft Failover Clustering
  • Virtualization HA: VMware vSphere HA, Hyper-V Replica
  • Cloud Redundancy: AWS Elastic Load Balancing, Azure Availability Zones, Google Cloud Regions

Step 3: Implement Geographic Redundancy (If Required)

  • Deploy redundant data centers or cloud regions for DR.
  • Use replication across regions to ensure data and services are available even if one site fails.

→ Tool Recommendation: AWS Multi-AZ RDS, Azure Site Recovery, Zerto, Veeam Replication

Step 4: Test Failover and Recovery Procedures

  • Regularly test failover mechanisms to ensure seamless switching.
  • Document test outcomes and improve procedures based on results.

→ Tool Recommendation: Chaos Monkey (Netflix OSS) for fault injection, Rubrik or Commvault for DR testing

Step 5: Monitor Redundant Systems

  • Continuously monitor the health and performance of primary and backup systems.
  • Configure alerts for failures, delays in replication, or failover readiness issues.

→ Tool Recommendation: Nagios, Zabbix, Datadog, PRTG Network Monitor

Step 6: Maintain Updated Documentation and SOPs

  • Document infrastructure diagrams, redundancy mechanisms, and failover procedures.
  • Keep operational playbooks up to date for IT teams and stakeholders.

Templates #

  • Redundancy and High Availability Policy
  • Disaster Recovery Infrastructure Diagram
  • Failover and Recovery Testing Checklist
  • System Dependency and Risk Assessment Sheet
  • Backup and Redundancy SOP (Standard Operating Procedures)

Example #

An e-commerce company deployed its web application across multiple AWS availability zones using Elastic Load Balancing and RDS Multi-AZ for its database. During a regional outage, the traffic was automatically redirected to a healthy zone with no downtime. This setup ensured business continuity and maintained customer trust.

Without redundancy, a single failure could have resulted in hours of downtime and loss of revenue.

How to Comply #

To comply with ISO 27001 A.8.14, organizations should:

  • Identify systems requiring high availability.
  • Design and implement redundancy in hardware, software, and network infrastructure.
  • Establish geographically diverse backup environments if needed.
  • Regularly test redundancy mechanisms and document the results.
  • Monitor redundant systems and resolve issues proactively.

How to Pass an Audit #

Key Documents to Prepare:

  • High Availability and Redundancy Policy
  • System Architecture and Redundancy Diagrams
  • Test Logs for Failover and Recovery Drills
  • Monitoring and Incident Reports for Redundant Systems
  • Risk Assessment Showing Criticality of Redundant Systems

What the Auditor Will Check:

  • Are redundancy measures in place for critical services?
  • Have failover mechanisms been tested and documented?
  • Is monitoring in place to detect redundancy-related failures?
  • Are recovery times aligned with business continuity objectives?

Top 3 Mistakes People Make #

  • Assuming cloud providers handle redundancy by default without configuring it properly.
  • Failing to test failover systems, leading to surprises during real incidents.
  • Not documenting or updating redundancy plans, leaving teams unprepared.

ISO 27001 Redundancy FAQ #

Q1: Is redundancy the same as backup?

No. Backup is about data recovery; redundancy is about service continuity. Redundant systems keep operations running without waiting for recovery.

Q2: Do all systems need redundancy?

Not necessarily. Only systems identified as critical through risk or impact analysis should have redundancy.

Q3: Can redundancy be achieved using cloud platforms?

Yes. Major cloud providers offer built-in tools for redundancy, but these must be explicitly configured (e.g., AWS Availability Zones, Azure Load Balancer).

ISO 27001 Controls and Attribute Values #

Control Attribute Value
A.8.14 Redundancy of Information Processing Facilities Preventive, Resilience-Oriented, Technical
Purpose Ensure uninterrupted operation of critical systems during failures.
Applicability Systems supporting high-availability and business-critical services.
ISO 27001 Domains Operations Security, Business Continuity, Information System Acquisition

Redundancy is a key component of a resilient IT environment. When designed and tested correctly, it protects organizations against operational disruptions, strengthens disaster recovery, and supports continuous business services.

Leave a Reply

Your email address will not be published. Required fields are marked *

Log in

You dont have an account yet? Register Now