ISO/IEC 27001:2022 Annex A · Control 8.14
Redundancy of Information Processing Facilities: A Practical Implementation Guide
Design and test redundancy so critical services tolerate component and location failures.
This control concerns implementing sufficient redundancy in information-processing facilities to meet availability requirements.
What should the control achieve?
- Redundancy requirements follow availability objectives.
- Components are separated across realistic failure domains.
- Failover capacity and data consistency are sufficient.
- Tests demonstrate service continuity.
Step-by-step implementation
Define availability needs
Use business impact, RTO, tolerated interruption and transaction integrity.
Map failure domains
Consider power, rack, network, zone, region, provider and administration.
Design redundancy
Choose active-active, active-passive, clustering, replication or alternate providers.
Manage consistency
Define replication lag, split-brain and recovery behavior.
Monitor readiness
Track health, capacity, synchronization and standby configuration.
Test failover and failback
Exercise realistic failures and restoration.
What this could look like in practice
An online service runs across two availability zones with independent power and network paths. Automated failover is tested quarterly, and capacity planning confirms one zone can carry essential load.
| Activity | Practical implementation | Evidence |
|---|---|---|
| Component failure | Cluster continues service after node loss. | Test log |
| Zone failure | Traffic moves to alternate zone. | Exercise report |
| Replication | Lag and integrity thresholds are monitored. | Dashboard |
| Failback | Controlled return avoids data conflict. | Change record |
Implementation evidence
- Availability requirements
- Failure-domain map
- Architecture design
- Capacity analysis
- Replication monitoring
- Failover tests
- Failback procedures
- Test actions
Useful metrics
- Failover tests passed
- Redundant capacity available
- Replication threshold breaches
- Single points of failure
Common mistakes
- Placing redundant systems on one power source.
- Assuming cloud zones are independent without design review.
- Testing failover but not failback.
- Insufficient standby capacity.
- Replicating corruption instantly.
Questions an auditor may ask
- Which failures must the service tolerate?
- How are failure domains separated?
- Show a failover test.
- How is data consistency protected?
Continue through Annex A
Explore the growing library of practical guides for all 93 Annex A controls.
Open the ISO 27001 Annex A Control LibraryThis independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.