Skip to content
arrow_back
verifiedISO/IEC 27001:2022

ISO 27001 Annex A 8.14Redundancy of Information Processing Facilities

Official control statement

Information processing facilities shall be implemented with redundancy sufficient to meet availability requirements.
verifiedISO/IEC 27001:2022Annex A 8.14

Quoted as published. Everything else on this page is written by Control Stack.

In plain English

Ensure systems have backups to avoid downtime and data loss.

Technological controlsISO/IEC 27001:2022
record_voice_over

What this means in practice

This control ensures that your computer systems have backups or duplicates, so they keep running even if something fails. Without this, a single failure could stop your business operations and result in lost data, hurting your ability to serve customers and keep your business running smoothly.

Framework

ISO/IEC 27001:2022

Control effect (Control Stack)

Preventative

ISO 27001 domain

Technological controls

Classifications

N/A

Official last update

24 Oct 2022

Control Stack last updated

29 Sept 2026

priority_high

Why it matters

A lack of redundancy can lead to extended downtimes, resulting in lost revenue and diminished trust from customers relying on your services.

settings

Operational notes

Redundancy systems need regular testing and updates to adapt to changing business needs and infrastructure updates.

build

Implementation tips

  • IT Manager should assess availability requirements for critical systems. This means identifying what systems need to be operational continuously and determine the acceptable downtime for each system. Use Australian regulations for guidance on critical infrastructure.
  • Procurement should partner with multiple reliable network suppliers. This reduces risk by ensuring you have backup internet and communication lines from different providers in case one fails.
  • IT Staff should establish redundant systems in separate locations. Set up a second data centre that automatically mirrors the main one, ensuring data is available even if one facility encounters an issue.
  • IT Support should configure systems with duplicate critical hardware components. This includes setting up servers with multiple power supplies and hard drives, so if one part fails, the other can keep things running.
  • IT Manager should implement monitoring and alert systems. Use software to detect failures quickly and trigger alerts to IT staff, ensuring they can respond and prevent downtime before it affects business functions.
fact_check

Audit / evidence tips

  • AskAsk for the disaster recovery plan and the redundancy strategy documentation.Look atCheck for a clear outline of the redundancy measures in place for critical systems and components.GoodThe documentation specifies each system's redundancy requirements and how those requirements have been implemented.
  • AskRequest a list of IT assets and their configurations from the IT department.Look atLook at the systems identified as having redundant processes and check that duplicated components are actually present.GoodMajor systems have redundancies that are geographically and physically separate.
  • AskAsk for reports from backup and failover tests.Look atVerify the tests are scheduled and conducted regularly, and that the reports record both successful and unsuccessful results.GoodSuccessful test results demonstrate that redundant systems function as required to meet availability needs.
  • AskRequest contracts with network providers that cover redundancy agreements.Look atCheck that the contracts specify clear service level agreements (SLAs) for failover capabilities and secondary connections.GoodContracts include provisions for redundancy that ensure continuous service.
  • AskAsk for monitoring system logs that track the health and failures of system components.Look atReview the alerts and the corresponding incident responses to confirm system issues are handled in a timely way.GoodLogs show prompt detection and resolution of issues, preventing downtime.
link

Cross-framework mappings

How Annex A 8.14 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ASD ISM

ControlNotesDetails
open_in_fullBroader than(3)expand_less
ISM-1438Annex A 8.14 requires information processing facilities to be implemented with redundancy sufficient to meet availability requirements
ISM-1580Annex A 8.14 requires information processing facilities to be implemented with redundancy sufficient to meet availability requirements
ISM-1789Annex A 8.14 requires information processing facilities to be implemented with redundancy sufficient to meet availability requirements

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Technological controls controls, or browse the full ISO 27001 library. You can also track all 93 controls with the free ISO 27001 Annex A checklist.

school

Want to implement this control?

Mindset Cyber runs PECB-accredited ISO/IEC 27001 training that maps directly to the controls in this library.

Mapping detail

Mapping

Direction

Controls