SOC 2
A - Availability

SOC 2 SOC2-A1.1: A1.1 Managing processing capacity

Current processing capacity and the use of infrastructure, data and software are maintained, monitored and evaluated so capacity demand can be managed and extra capacity added in time to meet objectives. Points of focus: usage is measured to set a capacity baseline and judge the risk of impaired availability; average and peak demand are forecast against capacity and tolerances, including capacity lost when components fail; and change management is triggered when forecasts exceed tolerances.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 117 controls across 47 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 7 controls

FedRAMP High · 6 controls

  • AU-4 Audit Log Storage Capacity
  • CP-7(2) Alternate Processing Site | Accessibility (CP-7(2))
  • CP-8(1) Telecommunications Services | Priority of Service Provisions (CP-8(1))
  • MA-6 Timely Maintenance (MA-6)
  • SC-22 Architecture and Provisioning for Name/Address Resolution Service
  • SC-5 Denial-of-Service Protection

FedRAMP Moderate · 6 controls

  • AU-4 Audit Log Storage Capacity
  • CP-7(2) Alternate Processing Site | Accessibility (CP-7(2))
  • CP-8(1) Telecommunications Services | Priority of Service Provisions (CP-8(1))
  • MA-6 Timely Maintenance (MA-6)
  • SC-22 Architecture and Provisioning for Name/Address Resolution Service
  • SC-5 Denial-of-Service Protection

C5 (Germany) · 4 controls

  • C5-OPS-01 Capacity Management - Planning
  • C5-OPS-02 Capacity Management - Monitoring
  • C5-OPS-03 Capacity Management - Controlling of Resources
  • C5-OPS-17 Logging and Monitoring - Availability of the Monitoring Software

ISO 22301:2019 · 4 controls

  • 8.2.2 Business impact analysis
  • 8.3.4 Resource requirements
  • 8.3.5 Implementation of solutions
  • 9.1 Monitoring, measurement, analysis and evaluation
  • NIST-CSF-GV.OC-05 Outcomes, capabilities, and services that the organization depends on are understood and communicated
  • NIST-CSF-PR.DS-10 The confidentiality, integrity, and availability of data-in-use are protected
  • NIST-CSF-PR.IR-03 Mechanisms are implemented to achieve resilience requirements in normal and adverse situations
  • NIST-CSF-PR.IR-04 Adequate resource capacity to ensure availability is maintained
  • 4.3.2 Legal and Other Requirements
  • 4.4.1 Resources, Roles, Responsibility, and Authority
  • 4.4.2 Competence, Training, and Awareness
  • FFIEC-11 Business continuity planning and testing
  • FFIEC-12 Disaster recovery procedures
  • FFIEC-14 Critical service identification

ISO 27002:2022 · 3 controls

  • 5.30 ICT readiness for business continuity
  • 8.14 Redundancy of information processing facilities
  • 8.6 Capacity management

PCI P2PE · 3 controls

  • PCI-P2PE-11 Business continuity planning and testing
  • PCI-P2PE-12 Disaster recovery procedures
  • PCI-P2PE-14 Critical service identification

PCI PIN Security · 3 controls

  • PCI-PIN-13 Third-party dependency management
  • PCI-PIN-14 Critical service identification
  • PCI-PIN-15 Communication and escalation procedures

PCI SSF · 3 controls

  • PCI-SSF-12 Disaster recovery procedures
  • PCI-SSF-14 Critical service identification
  • PCI-SSF-15 Communication and escalation procedures
  • IM8-DAT.2 Data Protection
  • IM8-DSS.2 Service Reliability Standards
  • IM8-RES.4 Resilience Testing
  • CPS230-19 Tolerance Levels for Each Critical Operation
  • CPS230-P25 Information and Technology Capability and Asset Health

APRA CPS 234 · 2 controls

  • CPS234-14 Definition of Information Security Roles and Responsibilities
  • CPS234-15 Information Security Capability
  • CFTC-SS-12 Capacity and Performance Planning Category
  • CFTC-SS-23 Resources Sufficient to Fulfil Obligations

CIS Controls v8 · 2 controls

  • CIS-12.2 Establish and Maintain a Secure Network Architecture
  • CIS-8.3 Ensure Adequate Audit Log Storage
  • 62351-12 Resilience and security recommendations for DER
  • 62351-13 Cyber-physical generation and storage resilience

ISO 27001:2022 · 2 controls

  • 8.14 Redundancy of information processing facilities
  • 8.6 Capacity management

ISO/IEC 27031:2011 · 2 controls

  • 27031-8.1 Exercising and Testing
  • 27031-B High availability embedded systems

ISO/IEC 42001:2023 · 2 controls

  • A.4 Resources for AI systems
  • A.4.5 System and computing resources
  • SOCI-S30BC Notification of critical cyber security incidents (12 hours)
  • SOCI-S30BD Notification of other cyber security incidents (72 hours)
  • OB-API.4 MI Reporting Specification
  • OB-OPS.1 API Availability Requirements
  • SEMD-CS-3 Cyber Resilience
  • SEMD-ER-1 Emergency Exercise and Testing

AICPA SOC 3 · 1 control

  • SOC3-AVAILABILITY Availability Criteria
  • ASD37-20 Multi-factor authentication (Essential)
  • BS65000-RM-03 Leadership and Culture

COBIT 2019 · 1 control

  • COBIT-BAI04 Managed availability and capacity
  • RMD-1 Reference Data Management

DORA · 1 control

EU AI Act · 1 control

  • CAT-D5-4 Resilience planning and testing

ISO 27701:2019 · 1 control

  • 6.9.1 Operational procedures and responsibilities
  • ISO20000-03 Capacity and availability management
  • ISO-25012-4.13 Availability

ISO/IEC 27007:2020 · 1 control

  • 27007-5.4 Establishing the Programme Resources

ITIL 4 · 1 control

  • ITIL4-03 Capacity and availability management

NIS2 Directive · 1 control

  • Art.21.2.c Business continuity, backup management, disaster recovery and crisis management

PCI DSS 4.0 · 1 control

  • 12.1.3 12.1.3 Security roles defined and acknowledged by all personnel

SASB Standards · 1 control

  • SASB-BMI-2 Business Model Resilience
  • SOC-CY-A1 Availability Commitments
  • SSAE18-A1.1 A1.1 - Availability Commitments and Requirements
  • UKAI-3 Bias Detection, Fairness, Validation
  • UKOPRES-5 Third-Party Risk, Concentration Risk
  • CERT-1 RRA Certification to EPA

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in A - Availability

You are reading one control. How much of SOC 2 have you already done?

SOC 2 SOC2-A1.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 117 it maps to, and the evidence behind each claim, over MCP and REST.