Redundancy of Information Processing Facilities
This is an ISO 27001 reference control that asks an organization to build backup or duplicate IT systems so that critical operations can keep running if a component fails. The goal is to reduce downtime and support business continuity by having spare capacity available when it is needed. It is one of the reference controls an organization may select based on its own risk assessment and availability needs.
Redundancy of Information Processing Facilities is Annex A Control 8.14 in the ISO/IEC 27001:2022 revision, one of the reference controls organized under that edition's four themes. It requires that information processing facilities be implemented with redundancy sufficient to meet the organization's availability requirements, typically through duplicated or additional components in critical operations to support continuous operation and business continuity. As an Annex A control, its applicability is not automatically mandatory; it is selected via the Statement of Applicability and informed by the organization's risk assessment, and the specific level and design of redundancy depends on the defined availability requirements and scope of the ISMS. It is a reference control rather than a certifiable ISMS requirement (which reside in clauses 4 through 10), and implementing it addresses availability but does not by itself guarantee freedom from outages or breaches.
Why it matters
Availability failures are among the most visible and disruptive risks an organization faces. When a critical information processing facility, a server, a data center, a network path, or a supporting utility, fails without any backup in place, operations can halt, customer-facing services can go dark, and recovery can take far longer than the business can tolerate. Annex A Control 8.14 addresses this by asking organizations to build in redundancy sufficient to meet their defined availability requirements, so that a single component failure does not translate directly into a service outage.
Redundancy also supports the broader business continuity objective that runs through an ISMS. Rather than treating outages purely as an incident-response problem after the fact, this control encourages designing spare or duplicated capacity into critical operations in advance, minimizing downtime and mitigating the risk of disruption. Because availability is one of the concerns organizations typically weigh when scoping their controls, 8.14 is often relevant where uptime commitments, whether contractual, regulatory, or operational, are significant.
It is important to keep the boundaries of this control in view. Implementing redundancy addresses availability, but it does not by itself guarantee freedom from outages or breaches; poorly configured or untested redundant systems can still fail, and redundancy does nothing to address confidentiality or integrity concerns on its own. As an Annex A reference control, 8.14 is selected based on the organization's own risk assessment and availability needs rather than being universally mandatory, so the appropriate level and design of redundancy varies from one organization to another.
Who it's relevant to
Inside Redundancy of Information Processing Facilities
Common questions
Answers to the questions practitioners most commonly ask about Redundancy of Information Processing Facilities.