Skip to content

Redundancy

What is Redundancy?

The duplication of critical components or functions of a system with the intention of increasing reliability. In security, redundancy ensures that the failure of one component does not result in a complete system failure.

Information Security

Each of these is named in at least one of the same controls as redundancy. The number is how many controls name both.

What the standards actually require on redundancy

Requirements naming redundancy across 6 standards, quoted from the control text.

C5 (Germany)1 control

Deliver the cloud service from two mutually redundant sites that both satisfy the provider's physical security requirements, sit far enough apart to give operational redundancy meeting agreed availability levels, and test that redundancy at least yearly.

C5-PS-02 · Redundancy model

Provide redundant units of business-critical equipment, sited far enough apart that one local event cannot take out both, using the separation industry standards call for.

CCM-BCR-11 · Equipment Redundancy

Build enough redundancy into processing facilities to meet availability requirements.

iso-27001-2022::8.14 · Redundancy of information processing facilities

Requires information processing facilities to be implemented with redundancy sufficient to meet the availability requirements placed on them.

iso-27002-2022::8.14 · Redundancy of information processing facilities

Develop people resilience through succession planning, wellbeing support, and skills redundancy across critical roles.

BS65000-8.3 · People Resilience

Questions people ask about redundancy

What is Redundancy?
The duplication of critical components or functions of a system with the intention of increasing reliability. In security, redundancy ensures that the failure of one component does not result in a complete system failure.
Why is Redundancy important for compliance?
Redundancy is a key concept in Information Security. Understanding redundancy helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Redundancy?
Redundancy appears in the requirement text of ITU-T X.805 - Security Architecture for End-to-End Communications, C5 (Germany), Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1, ISO 27001:2022, ISO 27002:2022. Across these standards we have identified 9 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Redundancy?
Explore our compliance framework pages to see how redundancy applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Redundancy applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.