Skip to content
compliancebase
ISO 27001A.8 — Redundancy of information processing facilities

A.8.14

Redundancy of information processing facilities

ISO 27001 · ISO/IEC 27001:2022 · Last verified August 2026

Objective

Implement sufficient redundancy for information processing facilities to meet availability requirements.

Points of focus

  • Define availability requirements
  • Architect redundancy
  • Test failover
  • Document dependencies

Implementation notes

Match redundancy to customer SLAs. Prefer multi-AZ for stateful stores. Run periodic failover drills. Track third-party SPOFs in the risk register. Assign a named owner in the SoA, tie operating evidence to architecture diagram with redundancy, and sample the control during internal audit before Stage 2 fieldwork.

Audit tip: Walk through architecture and show a failover test or postmortem proving redundancy worked.

Evidence auditors typically request:

  • Architecture diagram with redundancy
  • Failover/runbook
  • Game day or failover test results
  • Customer SLA mapping

Common gaps

  • Single-AZ production
  • DNS failover never tested
  • Hidden SPOF in third-party auth

Cross-Framework Mapping

FrameworkRequirementImplementation note
ISO 27001A.8.14This control
SOC 2A1.1, A1.2Related SOC 2 themes (A1.1, A1.2) — map in your crosswalk; not identical requirements.

Primary sources

Frequently Asked Questions

Only if availability requirements and risk say so — many B2B SaaS start with multi-AZ.

Capacity is about sizing; redundancy is about surviving component loss.

Backups (A.8.13) help recovery; redundancy aims to keep processing running.

Even without owned data centers, redundancy of information processing facilities still applies to how you operate endpoints, IdP, cloud consoles, and vendor services in scope. Exclude controls in the SoA only with a documented, risk-based rationale.

Start with architecture diagram with redundancy, assign a named control owner, and retain dated samples from your ticketing or GRC system — not one-off screenshots assembled before audit fieldwork.

Framework versions referenced in this page:

  • ISO/IEC 27001ISO/IEC 27001:2022

Last verified: August 2026 · Primary sources linked above