A.8.14 Technological
Redundancy of information processing facilities
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (23)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CP-10mostlyaligns with — Both controls require duplicating processing capabilities and establishing activation procedures so that operations can continue after primary-component failure.
- CP-2mostlycovers — A.8.14's redundancy mechanisms (e.g., failover sites, mirrored processing) directly implement the bulk of CP-2's recovery objectives, priorities, metrics, and continuity-of-essential-functions requirements, but a residual of CP-2 (e.g., explicit plan documentation, role assignments, testing, and full incident handling) sits outside pure redundancy.
- CP-7mostlyaligns with — Both controls mandate geographically or physically separate alternate processing sites that mirror primary systems to sustain availability.
- CP-7mostlycovers — A.8.14's requirement for redundancy of processing facilities (to ensure continuous operation) directly accounts for the core of CP-7's alternate-site mandate, but leaves a residual of formal agreements, specific RTO parameters, and explicit equipment/supply provisioning that sit outside A.8.14's scope.
- CP-2partialaligns with — Both controls require organizations to plan and document how redundant resources will be activated to meet availability objectives.
- CP-4partialaligns with — Both controls stress testing failover mechanisms to verify that redundant components function as intended.
- SC-24partialaligns with — Both controls emphasize designing systems to transition into a known, secure operational state when a component fails.
- CP-10covers — A.8.14's narrow focus on redundant facilities (hardware, sites, networks) for continuity addresses only a slice of CP-10's broader recovery/reconstitution requirements (backups, known-state restoration, procedures, timelines after any disruption).
- CP-4covers — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- SC-24covers — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
Aligned NIST CSF 2.0 outcomes (14)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PR.IR-03fullcovers — The ISO control's mandate to design and implement redundant architectures, failover procedures, and testing directly fulfills the CSF outcome of achieving resilience requirements in both normal and adverse situations.
- PR.IR-04mostlyaligns with — By requiring duplicated processing facilities and load-balancing mechanisms, the ISO control ensures adequate resource capacity to maintain availability during component failures.
- ID.AM-08partialaligns with — The control's emphasis on maintaining redundant systems throughout their life cycle supports the CSF outcome of managing assets across their entire operational lifespan.
- ID.IM-04partialaligns with — The requirement to test failover procedures and maintain redundant facilities aligns with the CSF outcome of establishing and maintaining incident response and operational continuity plans.
- ID.AM-08implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- ID.IM-04implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.IR-04implements — A.8.14's operational redundancy mechanisms give direct effect to maintaining adequate resource capacity for availability within PR.IR-04's domain, though the CSF outcome does not name redundancy specifically
Related weaknesses / CWE (15)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-1088nonemitigates — Redundancy and failover mechanisms can mitigate the impact of a hung synchronous call but do not enforce timeouts.
- CWE-1334nonemitigates — Redundancy of information processing facilities directly addresses the loss of hardware redundancy that CWE-1334 exploits.
- CWE-1050mitigates — Redundancy can absorb some resource spikes but does not prevent the loop defect.
- CWE-1251mitigates — Redundancy mechanisms can reduce the impact of mirrored-region divergence but do not guarantee ongoing synchronization.
- CWE-400mitigates — By duplicating processing facilities and load-balancing across instances, the control reduces the likelihood that a single resource-exhaustion attack will render the service unavailable.
- CWE-407mitigates — Redundancy of processing facilities can absorb resource exhaustion from inefficient algorithms.
- CWE-409mitigates — Redundancy helps availability but does not address the root cause of the weakness.
- CWE-410mitigates — Redundancy of processing facilities mitigates resource exhaustion by providing failover capacity.
- CWE-770mitigates — Architectural redundancy and automatic failover limit the impact of an attacker who forces excessive allocations, because spare capacity can absorb the load until the primary instance recovers.
Mitigated MITRE ATT&CK techniques (325)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- T1003.003recovers — A.8.14 designs in redundant facilities and failover procedures that restore availability of processing after a compromise or failure that took out the primary (including one that used T1003.003 to exfiltrate credentials), but does not restore the stolen credential material itself or undo the breach that already succeeded.
- T1074.002recovers — A.8.14's purpose and mechanisms (redundant facilities, failover activation, alerts, mirrored data centres, duplicated components, tested failover) directly enable recovery of availability and continued operation after an adversary's staging activity disrupts or occupies primary processing resources.
- T1114.001recovers — A.8.14's purpose and mechanisms (redundant facilities, mirrored systems, failover, backups implied by continuous availability and repair/replacement) directly enable recovery of email data after local collection by an adversary, with the named remainder being the window of new/changed data since the last sync or backup.
- T1485prevents — Redundancy of processing facilities (duplicated systems, mirrored data centres, load-balanced instances, failover procedures) ensures continued availability of services even after data destruction on primary components, directly preventing the adversary's goal of sustained availability interruption.
- T1485recovers — A.8.14 designs and tests redundant facilities plus failover procedures that restore availability of processing after destruction of primary data/systems, exactly as cp-9 recovers from T1486; the named remainder is data already irrecoverably overwritten before failover to the redundant copy.
- T1485.001recovers — A.8.14 designs/implements redundant facilities (e.g. mirrored data centres, duplicated components, multiple instances with load balancing) and activation procedures that restore availability after lifecycle-triggered deletion destroys primary objects, with testing to ensure failover works; mostly because the control's remainder is data written after the last sync or in non-mirrored stores.
- T1486prevents — Redundancy of processing facilities (duplicated components, mirrored data centres, redundant networks/power, automatic failover, load-balanced instances) ensures business services and data remain available from the alternate path even after encryption of the primary copy, directly closing the availability interruption named by T1486; the bounded remainder is the window before failover completes or non-replicated data that was solely on the encrypted instance.
- T1486recovers — A.8.14 designs and tests redundant facilities (mirrored data centres, duplicated components, failover procedures) whose explicit purpose is to restore availability of processing and data after an encryption-induced outage, matching the recovers verb; mostly because the control restores from the redundant copy rather than decrypting the original impacted data, and the remainder (e.g. unmirrored files written after last sync) is named in the clause itself.
- T1486responds — A.8.14's alert mechanisms, failover activation procedures, and continued availability during repair directly enable containment/eradication once ransomware encryption is underway, with the named remainder being impact already realised on non-redundant data before activation.
- T1489detects — A.8.14 explicitly requires mechanisms to alert on any failure in information processing facilities, which surfaces service-stop events (especially those affecting availability/redundancy), but this is scoped only to the redundant/availability slice of T1489 rather than the full technique (e.g., silent stops for data destruction, cloud API disables, or non-redundant services).
- T1489prevents — A.8.14 designs redundancy and failover (duplicated components, mirrored datacenters, load-balanced instances, redundant networks/power) so that stopping/disabling a primary service or facility does not render the overall capability unavailable, directly preventing the availability impact of T1489; it is only partial because the control does not stop the adversary from successfully executing the stop/disable action itself on any given instance.
- T1489recovers — A.8.14 designs and tests redundant facilities (duplicated components, mirrored data centres, automatic failover, load balancing) whose explicit purpose is to keep services available after a stop/disable event, directly restoring operational state for the impacted information processing facilities.
- T1490recovers — A.8.14 designs/implements redundant facilities plus activation/failover procedures and alerts so that availability (and thus recovery) continues while primary facilities are repaired or replaced; this directly addresses the post-impact recovery state targeted by T1490, with the named remainder being online/connected backups the adversary can still reach and delete before failover.
- T1491.001recovers — redundancy and failover procedures restore availability of processing facilities after defacement has altered internal systems or content, but do not restore the defaced data/integrity itself
- T1491.002recovers — A.8.14's purpose is ensuring continuous operation via redundancy, failover activation, alerts, and testing; after external defacement (which alters public content/integrity), mirrored redundant systems or failover to clean instances enable restoration of availability and correct state.
- T1495recovers — A.8.14's purpose and mechanisms (redundant facilities, mirrored systems, automatic failover, alerts, and tested procedures) directly enable restoration of availability after firmware corruption renders primary components inoperable, with the named remainder being non-redundant firmware (e.g., unique BIOS on single devices) that cannot be failed over.
- T1496detects — A.8.14 requires mechanisms to alert on any failure in information processing facilities (including those caused by resource exhaustion from hijacking), but this is scoped only to availability/continuity monitoring of redundant systems rather than broadly detecting the adversary technique itself across all its forms.
- T1496recovers — A.8.14's purpose and mechanisms (redundant facilities, failover activation, alerts, mirrored data centres, load balancing, duplicated components) directly restore availability after resource hijacking has consumed or impacted primary processing capacity, matching the recovers verb; mostly because the control's own text notes that failover must be planned/tested and some residual impact can occur during switchover or if redundancy itself is co-opted.
- T1496.001detects — A.8.14 requires mechanisms to alert on any failure in information processing facilities (including resource exhaustion from hijacking) and to test failover, which surfaces availability-impacting compute abuse in redundant setups, but this is limited to monitored failover events rather than broadly detecting the mining technique itself across all platforms and deployment vectors.
- T1496.001prevents — A.8.14 designs in redundancy (spare components, mirrored datacenters, load-balanced instances, dual suppliers) so that hijacked compute on primary facilities can fail over without losing availability, directly stopping the technique's impact on system/service availability; it is only partial because the control does not stop initial compromise or resource consumption on any single instance and the guidance is explicitly about meeting defined availability requirements rather than universal coverage.
- T1496.001recovers — A.8.14 designs and activates redundant facilities (duplicated components, mirrored data centres, load-balanced instances, failover procedures) that restore availability after compute-hijacking has consumed primary resources, exactly matching the recovers verb; the named remainder is the window until failover completes and any unmirrored transient state.
- T1496.002detects — A.8.14 requires mechanisms to alert on any failure in information processing facilities (including bandwidth/network capacity exhaustion from hijacking), which surfaces the availability impact, but the control is scoped to failover readiness rather than broad detection of adversarial bandwidth consumption or proxyjacking behaviors.
- T1496.002recovers — A.8.14's purpose and mechanisms (redundant facilities, failover activation, alerts, mirrored data centres, load balancing) directly restore availability after bandwidth consumption disrupts service, matching the technique's impact on availability; mostly because some impacts (financial costs, reputational damage) sit outside recovery.
- T1496.003recovers — A.8.14 designs in redundancy (duplicated facilities, failover, mirrored systems, multiple instances with load balancing) that restores availability of overwhelmed messaging/comms channels once the pumping flood is contained or rate-limited, matching the recovers verb on the event-lane anchors for similar availability-impacting techniques such as T1486.
- T1498detects — A.8.14 requires mechanisms to alert on any failure in information processing facilities (including those caused by network bandwidth exhaustion), which surfaces the realized impact of T1498 but does not broadly instrument for the attack traffic, spoofing, or botnet behaviors themselves.
- T1498prevents — A.8.14 designs in redundancy (multiple ISPs, redundant networks, geo-separated mirrored DCs, load-balanced instances, duplicated components) that keeps services available when bandwidth to any single path is exhausted, directly stopping the availability loss named by T1498; it is only partial because the control is silent on volumetric scale (e.g. a multi-Tbps DDoS can still saturate even redundant links) and on the non-redundancy aspects (spoofing, botnet recruitment) also named in the technique.
- T1498recovers — A.8.14 designs/implements redundancy (mirrored datacenters, load-balanced instances, duplicated components, failover procedures) and explicitly tests failover so that availability of processing facilities can be restored after a network-bandwidth-exhausting DoS has occurred.
- T1498responds — A.8.14's alert mechanisms, activation procedures for redundant components, and continued availability during repair directly enable containment/eradication of an in-flight Network DoS once underway (e.g. via failover to mirrored systems or load-balanced instances), with the named remainder being impact already realized before activation.
- T1498.001detects — A.8.14 explicitly requires mechanisms to alert the organization to any failure in the information processing facilities, which would surface the availability impact of a direct network flood (DoS) once it exceeds capacity and triggers failover or outage, but the control is scoped to redundancy architecture and activation rather than broad traffic anomaly detection.
- T1498.001prevents — A.8.14 designs in redundancy (multiple instances, load balancing, separate data centres, redundant networks/power) so the service can continue operating when a direct network flood saturates one path or instance, thereby preventing the technique from fully denying availability; it is only partial because the control does not stop the flood packets from reaching and consuming resources on the primary path, nor does it address volumetric attacks that can overwhelm even redundant capacity.
- T1498.001recovers — A.8.14 designs/implements redundancy (mirrored datacenters, duplicated components, load-balanced instances, failover procedures) that restores availability of processing facilities after a direct network flood saturates the primary path, exactly as cp-9 recovers from T1486 encryption impact; mostly because the control's own text leaves a named remainder (unmirrored single points, untested failover, or floods that also exhaust the redundant capacity itself).
- T1498.001responds — A.8.14's alert mechanisms, activation procedures for redundant components, and tested failover directly enable containment/eradication of an in-progress network flood's impact on availability once underway.
- T1498.002detects — A.8.14 requires mechanisms to alert on any failure in information processing facilities (including redundant ones), which can surface availability-impacting DoS from reflection amplification once it manifests as overload or failover events, but does not require or address detection of the specific attack technique, spoofing, or amplification vectors themselves.
- T1498.002prevents — A.8.14 designs in redundancy (multiple instances, load balancing, separate data centres, redundant networks/power) so that reflected/amplified traffic can be absorbed or failed-over without full loss of availability; this stops the DoS outcome for the targeted service but does not stop the reflection packets from being generated or reaching the reflectors.
- T1498.002recovers — A.8.14's purpose and mechanisms (redundant facilities, failover activation, alerts, mirrored data centres, load-balanced instances, duplicated components) explicitly restore availability and continued operation after a DoS-induced outage or degradation, which is what T1498.002 realises; the named remainder is that pure traffic reflection may be absorbed upstream before it reaches the redundant boundary.
- T1499prevents — A.8.14 designs/implements redundancy, failover, and alerts to ensure continued availability despite resource exhaustion or crashes at the endpoint, directly stopping successful DoS impact in covered architectures, but leaves residual gaps for un-redundant single points, non-production-tested failover, and non-endpoint network saturation aspects of the class.
- T1499recovers — A.8.14 designs/implements redundancy plus activation procedures and failover testing so that when an Endpoint DoS has already succeeded in exhausting or crashing a primary facility, service is restored from the redundant copy, exactly as cp-9 recovers from T1486.
- T1499responds — A.8.14 designs/implements redundancy plus activation procedures and failure alerts that, once an Endpoint DoS has begun exhausting or crashing a primary facility, enable failover to the redundant instance so the service continues, which is the core of `responds` (containment/eradication of impact while the technique is underway); mostly because the control's own text limits activation to planned/emergency cases and some resource-exhaustion scenarios (e.g., unmirrored single-instance software) may still fully succeed before failover engages.
- T1499.001prevents — Redundancy of facilities (duplicated components, mirrored data centres, load-balanced instances, failover procedures) allows continued service availability when one instance is exhausted by the OS-level flood, but does not stop the technique from successfully exhausting the primary target's OS resources or limits.
- T1499.001recovers — A.8.14 designs in redundant facilities and failover procedures that restore service availability after an OS-exhaustion DoS has rendered the primary instance unresponsive, exactly matching the recovers verb; mostly because the control's own text limits its scope to planned redundancy (e.g., not every possible OS-level exhaustion vector is automatically covered by the listed mechanisms).
- T1499.002prevents — A.8.14 designs in redundancy (duplicated components, geo-separated DCs, load-balanced instances, failover) so that exhaustion of one service instance does not stop overall availability, directly preventing the DoS impact of T1499.002; it is only partial because the control does not stop the flood from reaching and exhausting any single instance, nor does it address all exhaustion vectors (e.g. protocol-level CPU costs before load-balancing engages).
- T1499.002recovers — A.8.14 designs/implements redundancy plus activation procedures and failover testing so that when a service-exhaustion flood has already succeeded against the primary facility, the mirrored/spare components restore availability of the business service.
- T1499.002responds — A.8.14's alert mechanisms, failover activation procedures, and continued availability during repair directly enable response actions that contain and bound a realized service-exhaustion flood once underway, but the clause is scoped to redundancy architecture rather than incident response or full eradication of the attacker's ongoing flood.
- T1499.003prevents — A.8.14 designs in redundancy (duplicated components, failover, multiple instances, separate data centres) so that exhausting one path or instance still leaves capacity available, directly stopping the availability loss named by the technique; it is only partial because the control does not stop the flood from reaching or consuming resources on the primary instance(s) and the guidance is silent on application-level resource throttling or request filtering.
- T1499.003recovers — A.8.14's purpose is continuous operation via redundancy, failover activation, alerts, and testing; this directly restores availability after an application-exhaustion flood has denied service, with the named remainder being the window until failover completes or non-redundant resources remain exhausted.
- T1499.003responds — A.8.14's alert mechanisms, failover activation procedures, and continued availability during repair directly respond to and contain an in-progress application-exhaustion DoS once underway, with the named remainder being the initial impact window before detection and switchover.
- T1499.004prevents — A.8.14 designs in redundancy, failover, and alerts so that an exploitation-induced crash of a primary component does not produce sustained unavailability, but the control does not stop the vulnerability from being exploited or the crash from occurring in the first place.
- T1499.004recovers — OWNER RULING 2026-09-10, regraded `mostly` -> `partial`. A.8.14 is a control that restores, but the technique is a denial of service and restoring an identical copy does not increase capacity, while a capacity-based vector is likely here. For a non-capacity vector such as ping-of-death the restoration is short-lived in many cases: a continuous attack takes the failover node down too.
- T1499.004responds — A.8.14's alert mechanisms, failover activation procedures, and continued availability during repair directly act on an in-progress exploitation-induced crash/DoS (the technique already running) to contain impact and restore service, but this is bounded to redundancy-triggered recovery rather than full incident response containment/eradication of the adversary.
- T1529detects — A.8.14 explicitly requires mechanisms to alert the organization to any failure in the information processing facilities, which directly surfaces a shutdown/reboot (whether malicious or not) across the covered redundant architecture.
- T1529prevents — Redundancy of processing facilities (duplicated components, mirrored data centres, load-balanced instances, failover procedures) ensures continued availability despite a shutdown/reboot on any single instance, so the technique cannot achieve its availability-destruction goal on the service as a whole; it is only a slice because the control does not stop the shutdown command itself from executing on an individual component.
- T1529recovers — OWNER RULING 2026-09-10, `mostly` CONFIRMED. Distinguished from A.8.14 -> T1499.004 because this technique presupposes some level of access; that access is by nature to a single system at a time, and we cannot infer that whoever gained it has or will gain access to the redundant devices. So failover genuinely restores here.
- T1531recovers — A.8.14's purpose and mechanisms (redundant facilities, failover activation, alerts, mirrored data centres, duplicated components) directly enable continued availability and restoration of processing after an adversary removes legitimate account access, with the named remainder being the initial window of disruption before failover completes.
- T1557recovers — A.8.14's redundant facilities, mirrored data centres, load balancing, failover procedures and alerts directly restore availability and continuity after an AiTM-induced denial, redirection or impairment of traffic flow, with the named remainder being non-availability impacts such as stolen credentials or modified data in transit.
- T1561prevents — Redundancy of processing facilities (duplicated components, mirrored data centres, failover procedures, multiple suppliers) ensures continued availability after a disk wipe occurs on primary systems, which directly prevents the technique from achieving its availability-interruption goal on the overall service; it does not stop the adversary from executing the wipe itself.
- T1561recovers — A.8.14 designs and tests redundant facilities plus failover procedures that restore availability after a disk-wipe event has destroyed primary data or systems, exactly as cp-9 recovers from T1486; the named remainder is data written after the last sync or backups not reachable from the redundant site.
- T1561responds — A.8.14's alert mechanisms, failover activation procedures and mirrored/redundant components enable containment of the immediate availability loss from a realized disk-wipe event and support continued operation while primary systems are repaired, which is the core of `responds`; it is only partial because the control addresses only the availability impact slice and does nothing about the wiping actor/foothold itself.
- T1561.001detects — A.8.14 requires mechanisms to alert on any failure in information processing facilities (including disk-level failures from content wipe) and to enable failover, which surfaces the destructive event; this is only a slice because the control is scoped to availability/redundancy requirements rather than broad detection of the adversary technique itself.
- T1561.001prevents — Redundancy of processing facilities (duplicated components, mirrored data centres, load-balanced instances, failover procedures) allows continued availability after a disk-wipe event on primary systems, thereby preventing the adversary's goal of sustained availability interruption; it does not stop the wipe technique itself from executing on any given system.
- T1561.001recovers — A.8.14 designs and tests redundant facilities (mirrored data centres, duplicated components, automatic failover, multiple suppliers) whose explicit purpose is to restore availability after a destructive availability event such as disk-content wipe has occurred.
- T1561.001responds — A.8.14's alert mechanisms, activation procedures for redundant components, and tested failover directly enable containment/eradication of an in-progress disk-wipe event by switching to mirrored unaffected facilities, bounding further availability loss (though the already-wiped data on primary systems remains impacted until separate recovery).
- T1561.002detects — A.8.14 requires mechanisms to alert on any failure in information processing facilities (including those from disk-structure corruption that prevents boot), which surfaces the realized technique after the fact, but only for the subset of failures that trigger the redundant/failover path rather than all instances or pre-execution indicators.
- T1561.002prevents — A.8.14 designs in redundant facilities (mirrored data centres, duplicated components, automatic failover, multiple suppliers) so that a wiped primary boot structure still leaves the system/network available via the redundant path, directly stopping the availability-loss goal of T1561.002; partial because the control is silent on preventing the wipe itself on any given component and the attacker can still destroy structures on non-redundant elements.
- T1561.002recovers — A.8.14 designs and tests redundant facilities plus failover procedures so that when T1561.002 renders a primary system unbootable the mirrored/spare instance can be activated to restore service availability, exactly the recover verb; mostly because the control's own text limits it to planned redundancy (e.g. not every endpoint, not every network device) and the impact window until activation remains.
- T1561.002responds — A.8.14's failover and tested redundancy can contain the blast radius of a realized disk-structure wipe on one node by restoring service from the surviving redundant instance, but the technique's mechanics (especially worm-like propagation across mirrored systems or shared networks) often take out both primary and redundant facilities before or during activation, leaving only a slice addressable by response.
- T1565.001recovers — A.8.14's purpose is continuous operation via redundancy, mirrored systems, failover activation, alerts, and testing; this directly restores availability and integrity of processing after stored-data manipulation by switching to an un-tampered redundant copy.
- T1578.003detects — A.8.14 requires mechanisms to alert on any failure in information processing facilities, which would surface the deletion of a cloud instance as an availability-impacting event (especially if it breaks redundancy or triggers failover), but this is scoped only to failure detection rather than the adversarial intent, evasion motive, or non-failure deletions described in T1578.003.
- T1578.003recovers — A.8.14 designs/implements redundancy, failover activation procedures, failure alerts and testing so that business operations and information processing can continue after an instance is deleted, restoring availability without the lost artifacts.
- T1578.004recovers — A.8.14's purpose and mechanisms (redundant facilities, failover activation, alerts, mirrored data centres, duplicated components, tested failover) directly enable restoration of availability and state after an adversary's revert/snapshot action has destroyed or altered the primary instance, matching the recovers verb on the event lane.
- T1601.001recovers — A.8.14's redundancy, mirrored systems, failover activation and continued availability while the primary is repaired/replaced directly restores operational state after a T1601.001 patch has altered the running or boot image; partial because the control restores service continuity but does not undo the adversary's modified image or added capabilities on the primary component itself.
- T1657recovers — A.8.14 designs in redundant facilities and failover procedures that restore availability of processing after a theft-induced loss (e.g., ransomware extortion or account-compromise drain), but only for the subset of financial-theft techniques that first destroy or disrupt availability; many T1657 vectors (pure BEC fraud, social-engineering wire transfers, cryptocurrency exploits) leave monetary resources unavailable with no restoration by redundancy.
- T1667recovers — A.8.14 designs in redundant facilities (mirrored datacenters, duplicated components, load-balanced instances, failover procedures) that restore availability of email processing after the inbox-flooding impact is realized, exactly as cp-9 recovers from T1486; the named remainder is that the already-buried legitimate messages themselves are not automatically un-buried.
- T1685recovers — A.8.14's redundancy and failover mechanisms (duplicated facilities, mirrored data centres, automatic load balancing, tested activation procedures) restore availability and defensive function after an adversary has disabled or degraded tools or logging infrastructure, matching the recovers verb on the event lane.
- T1685.006recovers — A.8.14's purpose and mechanisms (redundant facilities, failover, mirrored systems, alerts on failure) enable restoration of logging capability and continued availability of the information processing facilities after the clearing technique has run and destroyed primary logs, but only for the subset of redundant/architected logging paths rather than all cleared artifacts.
Prevented OWASP Web Top 10 (2025) risks (4)
OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- A10mitigates — redundancy mechanisms (failover, alerts, mirrored systems) bound the blast radius and availability impact of an inconsistent/fail-open error state without addressing the root cause of the mishandling itself
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.