Infrastructure Security · IS-Q22B

Bonus Question: Are data center and network environments protected by redundant connectivity and failover mechanisms?

Why This Matters

Resilient connectivity ensures uptime and prevents single-point failures. Redundancy in circuits, routing, and power maintains service continuity during disruptions.

Maturity

0 — Unaware
Single ISP or circuit; no redundancy.
1 — Ad Hoc
Manual switch-over between links.
2 — Defined
Redundant links configured; partial routing failover.
3 — Managed
Automated routing (BGP/HSRP) tested quarterly.
4 — Integrated
Full dual-ISP design with monitored failover alerts.
5 — Optimized
Self-healing network with predictive failure analytics.

How to Level Up

| From → To | Actions | |—|—| | 0 → 1 |Procure secondary circuits.|
| 1 → 2 |Configure dual routing paths.|
| 2 → 3 |Enable automatic failover protocols.|
| 3 → 4 |Monitor failover events and alert SOC.|
| 4 → 5 |Adopt analytics for proactive rerouting. |

Enablers

Evidence

KPIs

Low-Cost / Open-Source Options (MSME)

| Purpose | Tool | Notes | |—|—|—| | Monitoring | Zabbix / LibreNMS | Track link status |
| Simulation | GNS3 / EVE-NG | Test failover logic |
| Analytics | Prometheus + Grafana | Visualize uptime trends |

Common Pitfalls

Compliance Mapping

| Standard | Clauses / Notes | |—|—| | ISO/IEC 27001 | A.5.30 / A.8.17 | | ISO 22301 | 8.4 / 8.5 | | NIST CSF 2.0 | PR.PT / RS.RP | | NIRMATA Mapping | IS-Q22B integrates network resiliency within Infrastructure Security. |