Redundancy
What is Redundancy?
The duplication of critical components or functions of a system with the intention of increasing reliability. In security, redundancy ensures that the failure of one component does not result in a complete system failure.
Terms that appear alongside redundancy
Each of these is named in at least one of the same controls as redundancy. The number is how many controls name both.
- availability 9 shared controls
- nist 7 shared controls
- iso 22301 5 shared controls
- business continuity 5 shared controls
- resilience 5 shared controls
- impact analysis 5 shared controls
- access control 4 shared controls
- disaster recovery 4 shared controls
Frameworks that govern redundancy
What the standards actually require on redundancy
Requirements naming redundancy across 6 standards, quoted from the control text.
Security Dimension 7 Availability per X.805 Clause 6.7: Availability ensures that there is no denial of authorized access to network elements + stored information + information flows + services and applications due to events impacting the network.
X805-Dim7-Availability-Network-Resources-Information-Authorized-Access-No-Service-Denial · ITU-T X.805 Security Dimension 7 - Availability + Network Resources + Information Accessible to Authorized Users + Denial-of-Service Prevention + Resilience + Redundancy + Disaster Recovery + Business Continuity + DDoS Mitigation →Deliver the cloud service from two mutually redundant sites that both satisfy the provider's physical security requirements, sit far enough apart to give operational redundancy meeting agreed availability levels, and test that redundancy at least yearly.
C5-PS-02 · Redundancy model →Provide redundant units of business-critical equipment, sited far enough apart that one local event cannot take out both, using the separation industry standards call for.
CCM-BCR-11 · Equipment Redundancy →Build enough redundancy into processing facilities to meet availability requirements.
iso-27001-2022::8.14 · Redundancy of information processing facilities →Requires information processing facilities to be implemented with redundancy sufficient to meet the availability requirements placed on them.
iso-27002-2022::8.14 · Redundancy of information processing facilities →Develop people resilience through succession planning, wellbeing support, and skills redundancy across critical roles.
BS65000-8.3 · People Resilience →Questions people ask about redundancy
What is Redundancy?
Why is Redundancy important for compliance?
Which compliance frameworks address Redundancy?
Where can I learn more about Redundancy?
See how Redundancy applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.