N.4.06 Redundancy of infrastructure
Control Overview
This control mandates that the organization designs, implements, and maintains redundant configurations for its critical ICT infrastructure nodes. Aligned with the overarching business continuity objectives established in Control 1.23, the organization must systematically eliminate Single Points of Failure (SPOFs). Technical mechanisms—such as multi-region data replication, load balancing, and automated system failovers—must be deployed to guarantee that essential services survive hardware, network, or localized cloud zone disruptions. Furthermore, these redundancy paths must be monitored continuously and tested through structured simulation exercises.
Applicability Note: This control is fully applicable to the anDREa platform and directly shapes the high-availability clustering and geo-resilience patterns of the production environment.
Compliance & Strategic Approach
Our approach satisfying this NIS 2 requirement operates within our ISO/IEC 27001-based ISMS, mapping systemic availability requirements directly to cloud-native architectural patterns.
anDREa's redundancy strategy is driven by our *A.08.14 - Redundancy of information processing facilities framework, which identifies which component stacks require hot or warm standbys to prevent cascading downtime. Because we deliver our SaaS platform via Microsoft Azure, our primary high-availability architecture is deeply tied to Azure’s region-wide infrastructure resilience (such as Availability Zones, redundant load-balancer pools, and geo-replicated storage arrays).
To manage our exposure under the cloud Shared Responsibility Model, we maintain a secondary tier of defense via the Baseline Recovery of myDRE Service. This playbook defines the specific, automated switchover rules and recovery configurations needed to restore services during anomalous edge cases where native Azure platform layers suffer multi-zone degradations.
Control Mappings & Evidence
| Framework / Document Reference | Element & Identifier | Description / Relationship to NIS 2 |
|---|---|---|
| ISO/IEC 27001 | A.08.14 - Redundancy of information processing facilities | Mandates that information processing facilities are implemented with redundancy sufficient to meet availability requirements. |
| Resiliency Blueprint | Service Level Agreement | The foundational document establishing the precise uptime thresholds and component clustering levels across the platform. |
| Failover Runbooks | Baseline Recovery of myDRE Service | Technical procedure manual governing service restoration and workload re-routing during extensive out-of-band infrastructure failures. |
| Validation Framework | Disaster Recovery Plan, Testing Schedule` | Documented calendar and results of annual simulation drills proving that infrastructure traffic can be shifted dynamically without loss of application state. |
Audit Summary
- Compliance Status: Fully Compliant
- Gaps Identified: None. Architecture-level hardware clustering, hot-path cloud storage redundancy, defined failover metrics, and recurring failover simulation validation are fully integrated and functional.