Skip to main content
Review and revision metadata
Review Date: 2026-06-16
Reviewer: Solution Architect

previous version on gdrive

N.4.06 Redundancy of infrastructure

Control Overview

This control mandates that the organization designs, implements, and maintains redundant configurations for its critical ICT infrastructure nodes. Aligned with the overarching business continuity objectives established in Control 1.23, the organization must systematically eliminate Single Points of Failure (SPOFs). Technical mechanisms—such as multi-region data replication, load balancing, and automated system failovers—must be deployed to guarantee that essential services survive hardware, network, or localized cloud zone disruptions. Furthermore, these redundancy paths must be monitored continuously and tested through structured simulation exercises.

note

Applicability Note: This control is fully applicable to the anDREa platform and directly shapes the high-availability clustering and geo-resilience patterns of the production environment.

Compliance & Strategic Approach

Our approach satisfying this NIS 2 requirement operates within our ISO/IEC 27001-based ISMS, mapping systemic availability requirements directly to cloud-native architectural patterns.

anDREa's redundancy strategy is driven by our *A.08.14 - Redundancy of information processing facilities framework, which identifies which component stacks require hot or warm standbys to prevent cascading downtime. Because we deliver our SaaS platform via Microsoft Azure, our primary high-availability architecture is deeply tied to Azure’s region-wide infrastructure resilience (such as Availability Zones, redundant load-balancer pools, and geo-replicated storage arrays).

To manage our exposure under the cloud Shared Responsibility Model, we maintain a secondary tier of defense via the Baseline Recovery of myDRE Service. This playbook defines the specific, automated switchover rules and recovery configurations needed to restore services during anomalous edge cases where native Azure platform layers suffer multi-zone degradations.


Control Mappings & Evidence

Framework / Document ReferenceElement & IdentifierDescription / Relationship to NIS 2
ISO/IEC 27001A.08.14 - Redundancy of information processing facilitiesMandates that information processing facilities are implemented with redundancy sufficient to meet availability requirements.
Resiliency BlueprintService Level AgreementThe foundational document establishing the precise uptime thresholds and component clustering levels across the platform.
Failover RunbooksBaseline Recovery of myDRE ServiceTechnical procedure manual governing service restoration and workload re-routing during extensive out-of-band infrastructure failures.
Validation FrameworkDisaster Recovery Plan, Testing Schedule`Documented calendar and results of annual simulation drills proving that infrastructure traffic can be shifted dynamically without loss of application state.

Audit Summary

  • Compliance Status: Fully Compliant
  • Gaps Identified: None. Architecture-level hardware clustering, hot-path cloud storage redundancy, defined failover metrics, and recurring failover simulation validation are fully integrated and functional.