ISO 27001:2022 Annex A Control 8.6

Capacity Management

Book a demo

modern,architecture,bank,financial,office,tower,building

Purpose of ISO 27001:2022 Annex A 8.6

Capacity management in ICT is more than just making sure organisations have enough space for data access and Backup and Disaster Recovery (BUDR). It requires ensuring there is adequate computing power and resources to meet user demands. It also involves designing and managing networks, data centres, and other ICT infrastructure to meet the organisation’s needs.

Organisations must guarantee they can operate effectively with a set of resources that address a variety of business needs, including Human Resources, data handling, administration of physical offices and related amenities.

These functions can damage an organisation’s control over their information.

ISO 27001:2022 Annex A 8.6 is a combination of preventative and detective controls to maintain risk levels. This control ensures the organisation has sufficient capacity for processing information.

Ownership of Annex A 8.6

ISO 27001:2022 Annex A 8.6 addresses an organisation’s capability to remain a viable business in the long-term.

Ownership should lie with the Chief Operating Officer or equivalent, taking responsibility for keeping up the integrity and effectiveness of business operations daily.

General Guidance on ISO 27001:2022 Annex A 8.6

ISO 27001:2022 Annex A Control 8.6 provides 7 pieces of general advice:

  1. Organisations should regard business continuity as a foremost concern when putting in place capacity management controls, such as the full implementation of detective controls that identify possible issues before they arise.
  2. Capacity management should be based on the proactive functions of tuning and monitoring, working together to guarantee systems and business operations are not impaired.
  3. Organisations should execute regular stress tests to ascertain their ability to satisfy their overall business needs. These tests should be custom-made for each case and be germane to the area of operation for which they are intended.
  4. Capacity management should not just consider an organisation’s existing data and operational needs; they should also plan for potential commercial and technical growth (both physical and digital) to be future-proofed as much as possible.
  5. Organisations must take into account the varying lead times and costs when expanding resources. Resources that are expensive and challenging to increase should have more thorough assessment to ensure business operations continue.
  6. Senior Management should be aware of any risk of dependency on key personnel or individual resources, as any issues that arise from this can lead to complex problems.
  7. Construct a capacity planning strategy that specifically addresses key business systems and processes.

Guidance on Managing Demand

ISO 27001:2022 Annex A 8.6 encourages a two-pronged strategy for capacity management – either augmenting capacity or cutting demand for a given set of resources.

When aiming to boost capacity, organisations should:

  • Think about bringing on new personnel to perform a work duty.
  • Obtain new facilities or office space through purchase, lease, or rental.
  • Obtain extra processing, data storage, and RAM (on-site or cloud-based) either by purchase, lease, or rental.
  • Think about utilising ‘elastic’ and ‘scalable’ cloud resources that expand in accordance with the computative needs of the organisation, with hardly any involvement.

Organisations should strive to reduce demand by:

  • Eliminate out of date information to liberate storage capacity on servers and associated media.
  • Discard securely any hard copies of information that the organisation doesn’t need, and isn’t mandated to keep via legislation or regulation.
  • Retire any ICT resources, applications, or virtual settings that are not needed anymore.
  • Examine planned ICT activities (including accounts, automatic upkeep and batch activities) to maximise memory capabilities and decrease the area taken up by created data.
  • Maximise application code and database queries that occur frequently enough to impact the company’s operational capability.
  • Limit the amount of bandwidth allocated to non-essential activities on the company’s network. This can include restricting Internet access and blocking video/audio streaming from work devices.

Changes and Differences from ISO 27001:2013

ISO 27001:2022 Annex A 8.6 supersedes ISO 27001:2013 Annex A 12.1.3 (Capacity Management).

ISO 27001:2022 Annex A 8.6 provides a thorough set of instructions to organisations on how they can expand their capacity or decrease their demand.

In contrast to ISO 27001:2013 Annex A 12.1.3 there is no particular direction on how to increase capacity. However, ISO 27001:2022 Annex A 8.6 provides precise steps to create more operational room to manoeuvre.

ISO 27001:2013 Annex A 12.1.3 does not provide any instructions on how to evaluate operational capacity or audit an organisation’s ability to handle capacity in the long run, apart from recommending having a capacity management plan.

In line with the dramatic increase of cloud computing over the past ten years, ISO 27001:2022 Annex A 8.6 clearly states that organisations should use cloud-based resources that adjust to their business needs.

ISO 27001:2013 Annex A 12.1.3 does not refer to off-site storage or computing facilities.

Table of All ISO 27001:2022 Annex A Controls

In the table below you’ll find more information on each individual ISO 27001:2022 Annex A Control.

ISO 27001:2022 Organisational Controls

Annex A Control TypeISO/IEC 27001:2022 Annex A IdentifierISO/IEC 27001:2013 Annex A IdentifierAnnex A Name
Organisational ControlsAnnex A 5.1Annex A 5.1.1
Annex A 5.1.2
Policies for Information Security
Organisational ControlsAnnex A 5.2Annex A 6.1.1Information Security Roles and Responsibilities
Organisational ControlsAnnex A 5.3Annex A 6.1.2Segregation of Duties
Organisational ControlsAnnex A 5.4Annex A 7.2.1Management Responsibilities
Organisational ControlsAnnex A 5.5Annex A 6.1.3Contact With Authorities
Organisational ControlsAnnex A 5.6Annex A 6.1.4Contact With Special Interest Groups
Organisational ControlsAnnex A 5.7NEWThreat Intelligence
Organisational ControlsAnnex A 5.8Annex A 6.1.5
Annex A 14.1.1
Information Security in Project Management
Organisational ControlsAnnex A 5.9Annex A 8.1.1
Annex A 8.1.2
Inventory of Information and Other Associated Assets
Organisational ControlsAnnex A 5.10Annex A 8.1.3
Annex A 8.2.3
Acceptable Use of Information and Other Associated Assets
Organisational ControlsAnnex A 5.11Annex A 8.1.4Return of Assets
Organisational ControlsAnnex A 5.12Annex A 8.2.1Classification of Information
Organisational ControlsAnnex A 5.13Annex A 8.2.2Labelling of Information
Organisational ControlsAnnex A 5.14Annex A 13.2.1
Annex A 13.2.2
Annex A 13.2.3
Information Transfer
Organisational ControlsAnnex A 5.15Annex A 9.1.1
Annex A 9.1.2
Access Control
Organisational ControlsAnnex A 5.16Annex A 9.2.1Identity Management
Organisational ControlsAnnex A 5.17Annex A 9.2.4
Annex A 9.3.1
Annex A 9.4.3
Authentication Information
Organisational ControlsAnnex A 5.18Annex A 9.2.2
Annex A 9.2.5
Annex A 9.2.6
Access Rights
Organisational ControlsAnnex A 5.19Annex A 15.1.1Information Security in Supplier Relationships
Organisational ControlsAnnex A 5.20Annex A 15.1.2Addressing Information Security Within Supplier Agreements
Organisational ControlsAnnex A 5.21Annex A 15.1.3Managing Information Security in the ICT Supply Chain
Organisational ControlsAnnex A 5.22Annex A 15.2.1
Annex A 15.2.2
Monitoring, Review and Change Management of Supplier Services
Organisational ControlsAnnex A 5.23NEWInformation Security for Use of Cloud Services
Organisational ControlsAnnex A 5.24Annex A 16.1.1Information Security Incident Management Planning and Preparation
Organisational ControlsAnnex A 5.25Annex A 16.1.4Assessment and Decision on Information Security Events
Organisational ControlsAnnex A 5.26Annex A 16.1.5Response to Information Security Incidents
Organisational ControlsAnnex A 5.27Annex A 16.1.6Learning From Information Security Incidents
Organisational ControlsAnnex A 5.28Annex A 16.1.7Collection of Evidence
Organisational ControlsAnnex A 5.29Annex A 17.1.1
Annex A 17.1.2
Annex A 17.1.3
Information Security During Disruption
Organisational ControlsAnnex A 5.30NEWICT Readiness for Business Continuity
Organisational ControlsAnnex A 5.31Annex A 18.1.1
Annex A 18.1.5
Legal, Statutory, Regulatory and Contractual Requirements
Organisational ControlsAnnex A 5.32Annex A 18.1.2Intellectual Property Rights
Organisational ControlsAnnex A 5.33Annex A 18.1.3Protection of Records
Organisational ControlsAnnex A 5.34 Annex A 18.1.4Privacy and Protection of PII
Organisational ControlsAnnex A 5.35Annex A 18.2.1Independent Review of Information Security
Organisational ControlsAnnex A 5.36Annex A 18.2.2
Annex A 18.2.3
Compliance With Policies, Rules and Standards for Information Security
Organisational ControlsAnnex A 5.37Annex A 12.1.1Documented Operating Procedures

ISO 27001:2022 People Controls

Annex A Control TypeISO/IEC 27001:2022 Annex A IdentifierISO/IEC 27001:2013 Annex A IdentifierAnnex A Name
People ControlsAnnex A 6.1Annex A 7.1.1Screening
People ControlsAnnex A 6.2Annex A 7.1.2Terms and Conditions of Employment
People ControlsAnnex A 6.3Annex A 7.2.2Information Security Awareness, Education and Training
People ControlsAnnex A 6.4Annex A 7.2.3Disciplinary Process
People ControlsAnnex A 6.5Annex A 7.3.1Responsibilities After Termination or Change of Employment
People ControlsAnnex A 6.6Annex A 13.2.4Confidentiality or Non-Disclosure Agreements
People ControlsAnnex A 6.7Annex A 6.2.2Remote Working
People ControlsAnnex A 6.8Annex A 16.1.2
Annex A 16.1.3
Information Security Event Reporting

ISO 27001:2022 Physical Controls

Annex A Control TypeISO/IEC 27001:2022 Annex A IdentifierISO/IEC 27001:2013 Annex A IdentifierAnnex A Name
Physical ControlsAnnex A 7.1Annex A 11.1.1Physical Security Perimeters
Physical ControlsAnnex A 7.2Annex A 11.1.2
Annex A 11.1.6
Physical Entry
Physical ControlsAnnex A 7.3Annex A 11.1.3Securing Offices, Rooms and Facilities
Physical ControlsAnnex A 7.4NEWPhysical Security Monitoring
Physical ControlsAnnex A 7.5Annex A 11.1.4Protecting Against Physical and Environmental Threats
Physical ControlsAnnex A 7.6Annex A 11.1.5Working In Secure Areas
Physical ControlsAnnex A 7.7Annex A 11.2.9Clear Desk and Clear Screen
Physical ControlsAnnex A 7.8Annex A 11.2.1Equipment Siting and Protection
Physical ControlsAnnex A 7.9Annex A 11.2.6Security of Assets Off-Premises
Physical ControlsAnnex A 7.10Annex A 8.3.1
Annex A 8.3.2
Annex A 8.3.3
Annex A 11.2.5
Storage Media
Physical ControlsAnnex A 7.11Annex A 11.2.2Supporting Utilities
Physical ControlsAnnex A 7.12Annex A 11.2.3Cabling Security
Physical ControlsAnnex A 7.13Annex A 11.2.4Equipment Maintenance
Physical ControlsAnnex A 7.14Annex A 11.2.7Secure Disposal or Re-Use of Equipment

ISO 27001:2022 Technological Controls

Annex A Control TypeISO/IEC 27001:2022 Annex A IdentifierISO/IEC 27001:2013 Annex A IdentifierAnnex A Name
Technological ControlsAnnex A 8.1Annex A 6.2.1
Annex A 11.2.8
User Endpoint Devices
Technological ControlsAnnex A 8.2Annex A 9.2.3Privileged Access Rights
Technological ControlsAnnex A 8.3Annex A 9.4.1Information Access Restriction
Technological ControlsAnnex A 8.4Annex A 9.4.5Access to Source Code
Technological ControlsAnnex A 8.5Annex A 9.4.2Secure Authentication
Technological ControlsAnnex A 8.6Annex A 12.1.3Capacity Management
Technological ControlsAnnex A 8.7Annex A 12.2.1Protection Against Malware
Technological ControlsAnnex A 8.8Annex A 12.6.1
Annex A 18.2.3
Management of Technical Vulnerabilities
Technological ControlsAnnex A 8.9NEWConfiguration Management
Technological ControlsAnnex A 8.10NEWInformation Deletion
Technological ControlsAnnex A 8.11NEWData Masking
Technological ControlsAnnex A 8.12NEWData Leakage Prevention
Technological ControlsAnnex A 8.13Annex A 12.3.1Information Backup
Technological ControlsAnnex A 8.14Annex A 17.2.1Redundancy of Information Processing Facilities
Technological ControlsAnnex A 8.15Annex A 12.4.1
Annex A 12.4.2
Annex A 12.4.3
Logging
Technological ControlsAnnex A 8.16NEWMonitoring Activities
Technological ControlsAnnex A 8.17Annex A 12.4.4Clock Synchronization
Technological ControlsAnnex A 8.18Annex A 9.4.4Use of Privileged Utility Programs
Technological ControlsAnnex A 8.19Annex A 12.5.1
Annex A 12.6.2
Installation of Software on Operational Systems
Technological ControlsAnnex A 8.20Annex A 13.1.1Networks Security
Technological ControlsAnnex A 8.21Annex A 13.1.2Security of Network Services
Technological ControlsAnnex A 8.22Annex A 13.1.3Segregation of Networks
Technological ControlsAnnex A 8.23NEWWeb filtering
Technological ControlsAnnex A 8.24Annex A 10.1.1
Annex A 10.1.2
Use of Cryptography
Technological ControlsAnnex A 8.25Annex A 14.2.1Secure Development Life Cycle
Technological ControlsAnnex A 8.26Annex A 14.1.2
Annex A 14.1.3
Application Security Requirements
Technological ControlsAnnex A 8.27Annex A 14.2.5Secure System Architecture and Engineering Principles
Technological ControlsAnnex A 8.28NEWSecure Coding
Technological ControlsAnnex A 8.29Annex A 14.2.8
Annex A 14.2.9
Security Testing in Development and Acceptance
Technological ControlsAnnex A 8.30Annex A 14.2.7Outsourced Development
Technological ControlsAnnex A 8.31Annex A 12.1.4
Annex A 14.2.6
Separation of Development, Test and Production Environments
Technological ControlsAnnex A 8.32Annex A 12.1.2
Annex A 14.2.2
Annex A 14.2.3
Annex A 14.2.4
Change Management
Technological ControlsAnnex A 8.33Annex A 14.3.1Test Information
Technological ControlsAnnex A 8.34Annex A 12.7.1Protection of Information Systems During Audit Testing

How ISMS.online Help

Our checklist helps to simplify the implementation of ISO 27001:2022, guiding you through the entire process. Our comprehensive solution ensures your compliance with ISO/IEC 27001:2022.

Once you log in, you will make up to 81% progress.

A comprehensive, straightforward solution to full adherence is provided.

Contact us now to schedule a demonstration.

Discover our platform

Book a tailored hands-on session
based on your needs and goals
Book your demo

Trusted by companies everywhere
  • Simple and easy to use
  • Designed for ISO 27001 success
  • Saves you time and money
Book your demo
img

ISMS.online now supports ISO 42001 - the world's first AI Management System. Click to find out more