Resource use is to be monitored and adjusted to fit present and expected capacity needs. Purpose: have enough capacity in processing facilities, staff, offices and other facilities. Guidance: identify capacity requirements for processing facilities, staff, offices and other facilities in light of how critical the related systems and processes are; tune and monitor systems to secure and, where needed, improve availability and efficiency; stress-test systems and services to confirm there is enough capacity for peak demand; and put detective controls in place that flag problems early. Projections of future needs should take in upcoming business and system needs along with present and forecast trends in processing capability, with particular attention to resources that are costly or slow to procure, so managers and service or product owners monitor use of key resources. Managers use capacity information to spot and avoid resource limits and reliance on key individuals that could threaten security or services, and plan accordingly. Capacity can be met by adding supply (hiring staff, getting more space or facilities, buying more powerful processing, memory and storage, or using cloud computing whose elasticity allows fast scaling up and down) or by cutting demand (deleting obsolete data, disposing of paper records past retention, retiring applications, systems, databases or environments, optimizing batch jobs and schedules, tuning code or database queries, and restricting bandwidth for non-critical heavy services such as video streaming). For systems that are mission-critical, a written capacity plan is worth having. ISO/IEC TS 23167 explains cloud elasticity and scalability.
This control maps to 30 controls across 20 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
ISO 27002:2022 8.6 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.
The graph holds this control, the 30 it maps to, and the evidence behind each claim, over MCP and REST.