A.8.14 Redundancies of Information Processing Facilities
Control Objective
Information processing facilities shall be implemented with redundancy sufficient to meet availability requirements.
Policy Statement
anDREa implements technical and architectural redundancy across its information processing facilities to guarantee high availability, platform resilience, and continuous service delivery for the myDRE ecosystem.
Architectural Redundancy Framework
Our high-availability strategy partitions operational assets into distinct infrastructure layers:
1. SaaS & Cloud Infrastructure Resilience
- Hyperscale Redundancy: Core enterprise and development operations run on the local multi-facility redundancy of Microsoft Azure's West Europe Region.
- Locally Redundant Storage (LRS): Keeps 3 copies of your data within a single physical facility.
- Region Paired: West Europe is officially paired with the North Europe region (located in Ireland). Services utilizing Geo-Redundant Storage (GRS) automatically copy data asynchronously from West Europe to North Europe.
- Availability Zone enabled: Azure’s West Europe region is fully Availability Zone (AZ) enabled as a physically separate, independent data center facility.
- Supplier Governance: Supplier obligations, failover mechanisms, and backup frequencies are verified and cataloged within the Record of Processing Activities.
- Disaster Isolation: Core platform architectural recovery steps and emergency system configurations are systematically formalized in the Disaster Recovery Plan.
2. Core anDREa-Managed Redundant Assets
Beyond standard cloud provider replicas, anDREa actively enforces independent, verifiable redundancies for its two most critical proprietary assets:
- myDRE Source Code: The core application logic and platform infrastructure code are version-controlled across active repositories and backed up via independent, off-site storage configurations (see A.08.04 - Access to source code).
- myDRE Knowledge Base: Educational materials, operational procedures, and customer support documentation are backed up into secondary cloud nodes to ensure continuity of service and helpdesk channels during a primary provider disruption.
Monitoring & Continuity Validation
To prevent silent failures in our fallback environments, the Management Team maintains strict, continuous oversight of our redundant pipelines:
- Verification Tickets: The automated compilation, packaging, and transmission of independent backups to secondary environments trigger tracking tickets. The Management Team manually validates and signs off on the receiving party's confirmation receipt.
- Operational Control Audits: Continuous health monitoring and consistency checks for these redundant data streams are tracked inside the Periodic Security Controls audit logs.