ISO 27002:2022
Technological controls – ISO 27002:2022

ISO 27002:2022 8.6: Capacity management

Resource use is to be monitored and adjusted to fit present and expected capacity needs. Purpose: have enough capacity in processing facilities, staff, offices and other facilities. Guidance: identify capacity requirements for processing facilities, staff, offices and other facilities in light of how critical the related systems and processes are; tune and monitor systems to secure and, where needed, improve availability and efficiency; stress-test systems and services to confirm there is enough capacity for peak demand; and put detective controls in place that flag problems early. Projections of future needs should take in upcoming business and system needs along with present and forecast trends in processing capability, with particular attention to resources that are costly or slow to procure, so managers and service or product owners monitor use of key resources. Managers use capacity information to spot and avoid resource limits and reliance on key individuals that could threaten security or services, and plan accordingly. Capacity can be met by adding supply (hiring staff, getting more space or facilities, buying more powerful processing, memory and storage, or using cloud computing whose elasticity allows fast scaling up and down) or by cutting demand (deleting obsolete data, disposing of paper records past retention, retiring applications, systems, databases or environments, optimizing batch jobs and schedules, tuning code or database queries, and restricting bandwidth for non-critical heavy services such as video streaming). For systems that are mission-critical, a written capacity plan is worth having. ISO/IEC TS 23167 explains cloud elasticity and scalability.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 30 controls across 20 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

C5 (Germany) · 3 controls

  • C5-OPS-01 Capacity Management - Planning
  • C5-OPS-02 Capacity Management - Monitoring
  • C5-OPS-03 Capacity Management - Controlling of Resources
  • ISM-1579 Verifying CSP dynamic scaling for demand spikes
  • ISM-1581 Real-time capacity and availability monitoring

FedRAMP High · 2 controls

  • AU-4 Audit Log Storage Capacity
  • SC-5 Denial-of-Service Protection

FedRAMP Moderate · 2 controls

  • AU-4 Audit Log Storage Capacity
  • SC-5 Denial-of-Service Protection

ISO 22301:2019 · 2 controls

  • 7.1 Resources
  • 8.3.4 Resource requirements

ISO/IEC 42001:2023 · 2 controls

  • 9.1 Monitoring, measurement, analysis and evaluation
  • A.4 Resources for AI systems

MTCS (Singapore) · 2 controls

  • 19.4 Capacity management
  • A.24 Disclosure: Capacity elasticity

NIST SP 800-53 Rev 5 · 2 controls

SOC 2 · 2 controls

  • ANSSI-HYG-35 Anticipate the End of Maintenance of Software and Systems
  • CPS230-P25 Information and Technology Capability and Asset Health
  • CFTC-SS-12 Capacity and Performance Planning Category

CIS Controls v8 · 1 control

  • CIS-8.3 Ensure Adequate Audit Log Storage

DORA · 1 control

ISO 27001:2022 · 1 control

  • 8.6 Capacity management

ISO 27018:2019 · 1 control

  • 12.1.3 Capacity management

PCI DSS 4.0 · 1 control

  • 12.1.3 12.1.3 Security roles defined and acknowledged by all personnel

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Technological controls – ISO 27002:2022

You are reading one control. How much of ISO 27002:2022 have you already done?

ISO 27002:2022 8.6 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 30 it maps to, and the evidence behind each claim, over MCP and REST.