Cyber Resilience

← ISO 27001 Annex A

A.8.14 Technological

Redundancy of information processing facilities

AttributesPreventiveAProtectContinuityAsset managementProtectionResilience

Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?

The implementation guidance for this control is published in ISO/IEC 27002:2022 and is not reproduced here. The structured attributes and the cross-walk rationales below are derived facts and our own AI-authored analysis.

Mapped NIST 800-53 r5 controls (23)

Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Aligned NIST CSF 2.0 outcomes (14)

NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Related weaknesses / CWE (15)

Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Mitigated MITRE ATT&CK techniques (325)

Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

T1001←MT1001.003←MT1003.003→PT1006←MT1008←MT1011←MT1011.001←MT1014←MT1027.001←MT1027.002←MT1027.006←MT1027.011←MT1027.014←MT1030←PT1036←MT1036.003←MT1036.005←MT1036.008←MT1036.009←MT1055←MT1055.001←MT1055.002←MT1055.003←MT1055.004←MT1055.005←MT1055.008←MT1055.009←MT1055.011←MT1055.012←MT1055.013←MT1055.014←MT1055.015←MT1070←MT1070.010←MT1071←MT1071.001←MT1071.002←MT1071.003←MT1071.004←MT1074.002→PT1078←PT1078.004←MT1090←MT1090.001←MT1090.002←MT1090.003←MT1090.004←MT1091←MT1095←MT1098.005←MT1102←MT1102.001←MT1102.002←MT1102.003←MT1104←MT1111←MT1114.001→MT1127←MT1127.001←MT1133←MT1134←MT1134.004←MT1185←MT1189←MT1190←PT1195←MT1195.003←PT1200←MT1205←MT1207←MT1210←MT1211←PT1216←MT1218←MT1218.005←MT1218.007←MT1218.008←MT1218.010←MT1218.013←MT1219.003←MT1221←MT1222←PT1480.001←MT1484←MT1484.002←PT1485←M →MT1485.001←P →MT1486←M →MT1489←M →MT1490←M →MT1491.001→PT1491.002→MT1495←M →MT1496←M →MT1496.001←M →MT1496.002←M →MT1496.003←P →PT1496.004←PT1497←MT1497.002←MT1498→PT1498.001←M →PT1498.002←M →MT1499←M →PT1499.001←M →MT1499.002←M →PT1499.003←M →PT1499.004←M →PT1529←M →MT1531←P →MT1535←MT1537←MT1539←MT1542←MT1542.002←MT1542.003←MT1546.012←PT1548.006←MT1550←MT1550.001←MT1550.002←FT1550.003←MT1550.004←FT1553.003←MT1553.004←PT1553.005←MT1553.006←MT1554←PT1556←MT1556.001←MT1556.003←MT1556.006←MT1556.007←MT1556.009←MT1557←P →MT1557.002←PT1557.003←PT1557.004←MT1561←M →PT1561.001←M →PT1561.002←M →PT1563.001←MT1565.001→MT1565.002←PT1568←MT1568.001←MT1568.002←MT1568.003←MT1571←MT1572←MT1574←MT1574.001←MT1574.010←PT1574.013←MT1578←MT1578.001←MT1578.002←MT1578.003←M →MT1578.004←M →PT1578.005←MT1583.005←MT1583.007←MT1584←MT1584.001←MT1584.003←MT1584.005←MT1584.008←PT1599←MT1599.001←MT1600←PT1601←PT1601.001←P →PT1601.002←MT1606←MT1606.001←MT1606.002←MT1610←PT1611←MT1612←MT1620←MT1621←MT1622←MT1647←PT1653←PT1657→PT1665←PT1666←MT1667←P →MT1677←PT1678←MT1679←PT1685←M →PT1685.002←MT1685.003←MT1685.004←MT1685.005←MT1685.006→PT1686←MT1686.001←MT1686.002←MT1686.003←MT1687←MT1688←MT1689←MT1690←F
Why these map — AI rationale (under review)

Prevented OWASP Web Top 10 (2025) risks (4)

OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.