ISO 27001 Annex A 8.14Redundancy of Information Processing Facilities
Official control statement
Information processing facilities shall be implemented with redundancy sufficient to meet availability requirements.
Quoted as published. Everything else on this page is written by Control Stack.
In plain English
Ensure systems have backups to avoid downtime and data loss.
What this means in practice
This control ensures that your computer systems have backups or duplicates, so they keep running even if something fails. Without this, a single failure could stop your business operations and result in lost data, hurting your ability to serve customers and keep your business running smoothly.
Framework
ISO/IEC 27001:2022
Control effect (Control Stack)
Preventative
ISO 27001 domain
Technological controls
Classifications
N/A
Official last update
24 Oct 2022
Control Stack last updated
29 Sept 2026
Why it matters
A lack of redundancy can lead to extended downtimes, resulting in lost revenue and diminished trust from customers relying on your services.
Operational notes
Redundancy systems need regular testing and updates to adapt to changing business needs and infrastructure updates.
Implementation tips
- IT Manager should assess availability requirements for critical systems. This means identifying what systems need to be operational continuously and determine the acceptable downtime for each system. Use Australian regulations for guidance on critical infrastructure.
- Procurement should partner with multiple reliable network suppliers. This reduces risk by ensuring you have backup internet and communication lines from different providers in case one fails.
- IT Staff should establish redundant systems in separate locations. Set up a second data centre that automatically mirrors the main one, ensuring data is available even if one facility encounters an issue.
- IT Support should configure systems with duplicate critical hardware components. This includes setting up servers with multiple power supplies and hard drives, so if one part fails, the other can keep things running.
- IT Manager should implement monitoring and alert systems. Use software to detect failures quickly and trigger alerts to IT staff, ensuring they can respond and prevent downtime before it affects business functions.
Audit / evidence tips
- AskAsk for the disaster recovery plan and the redundancy strategy documentation.Look atCheck for a clear outline of the redundancy measures in place for critical systems and components.GoodThe documentation specifies each system's redundancy requirements and how those requirements have been implemented.
- AskRequest a list of IT assets and their configurations from the IT department.Look atLook at the systems identified as having redundant processes and check that duplicated components are actually present.GoodMajor systems have redundancies that are geographically and physically separate.
- AskAsk for reports from backup and failover tests.Look atVerify the tests are scheduled and conducted regularly, and that the reports record both successful and unsuccessful results.GoodSuccessful test results demonstrate that redundant systems function as required to meet availability needs.
- AskRequest contracts with network providers that cover redundancy agreements.Look atCheck that the contracts specify clear service level agreements (SLAs) for failover capabilities and secondary connections.GoodContracts include provisions for redundancy that ensure continuous service.
- AskAsk for monitoring system logs that track the health and failures of system components.Look atReview the alerts and the corresponding incident responses to confirm system issues are handled in a timely way.GoodLogs show prompt detection and resolution of issues, preventing downtime.
Cross-framework mappings
How Annex A 8.14 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ASD ISM
| Control | Notes | Details |
|---|---|---|
open_in_fullBroader than(3)expand_less | ||
| ISM-1438 | Annex A 8.14 requires information processing facilities to be implemented with redundancy sufficient to meet availability requirements | |
| ISM-1580 | Annex A 8.14 requires information processing facilities to be implemented with redundancy sufficient to meet availability requirements | |
| ISM-1789 | Annex A 8.14 requires information processing facilities to be implemented with redundancy sufficient to meet availability requirements | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ISO 27001 controls in Technological controls
See all Technological controls controls, or browse the full ISO 27001 library. You can also track all 93 controls with the free ISO 27001 Annex A checklist.
Want to implement this control?
Mindset Cyber runs PECB-accredited ISO/IEC 27001 training that maps directly to the controls in this library.