In this guide you will learn how to implement ISO 27001 Annex A 7.11 and pass your audit from ISO 27001 Lead Auditor Stuart Barker – author of the ultimate ISO 27001 Toolkit.
ISO 27001 Annex A 7.11 Supporting Utilities is an ISO 27001 control that looks to make sure you have consider services such as power and internet connectivity and what you will do if they go down.
Table of contents
Purpose & Definition
The purpose of ISO 27001 Annex A 7.11 Supporting Utilities is to prevent loss, damage or compromise of information and other associated assets, or interruption to the organisations operations due to failure and disruption of supporting utilities.
The ISO 27001 standard defines Supporting Utilities as:
Information processing facilities should be protected from power failures and other disruptions caused by failures in supporting utilities.
ISO 27001:2022 Annex A 7.11 Supporting Utilities
White Label
ISO 27001 for Consultants
Custom-brandable ISO 27001 documentation for consultants. Easily rebrand, reduce project time, and deliver professional, high-value security systems. Focus on delivery, not drafting.
FREE ISO 27001 Annex A 7.11 Training Video
In this free training video you will learn How to implement ISO 27001 Supporting Utilities (Annex A 7.11) and Pass Your Audit.
Implementation Guide
General Guidance
Supporting utilities are the utilities that a company provides as a service such as an electricity or gas supply. As a physical control this relates to information processing utilities such as data centres and server rooms but we can consider it in the context of end point user devices as well.
This control is really looking at availability, and the ability to continue to provide a service if the supply of power is interrupted.
To some extent this control is outside of your gift to control but there are some considerations that you can put in place and evidence.
The standard is a little overkill and for most small organisations elements of this will not apply.
Operate and Maintain Equipment
To meet the control you would, as with everything, operate any equipment that supports the utilities in line with the manufacturers guidelines. This usually means appropriate operation and professional maintenance. The professional maintenance would include testing and inspection although we would expect this to be a legal and regulatory requirement anyway, usually around health and safety.
Internet of Things (IOT)
The control raises an interesting point about not connecting support equipment to the internet if it isn’t necessary, which is a nod to the move to the internet of things (IOT).
Emergency Supporting Controls
Finally for this control is guidance on emergency supporting controls. What we mean here are things like emergency lighting, communications, cut off switches, emergency exits. As mentioned before this overkill for a small organisation and covered by your cloud provider where you have one.
The advice here is, if you have a server room or information processing facility to bring in professional third parties to advise and implement. This is not something you will undertake yourself and there are many laws that govern this that are outside your capability. Cover it in you business continuity plan on a practical side consider if you need to think about Uninterrupted Power Supplies (UPS) and alternatives for network connectivity.
How to implement ISO 27001 Annex A 7.11
Implementing ISO 27001 Annex A 7.11 requires a robust approach to physical infrastructure to ensure that information processing facilities are resilient against utility failures.
1. Identify and Map Critical Utility Dependencies
Perform a comprehensive audit of all utilities required for the continued operation of information processing facilities to identify potential single points of failure.
- Document all primary and secondary power sources, including grid connections and on-site distribution boards.
- Map telecommunications entry points and internal routing to ensure diverse paths for data connectivity.
- Identify critical HVAC (Heating, Ventilation, and Air Conditioning) requirements for server rooms and data centres.
- Verify the location of water and gas supply lines to ensure they do not pose a leak or fire risk to IT hardware.
2. Provision Redundant Power and Backup Systems
Install and configure backup power solutions to ensure that critical systems remain available during a primary utility failure or surge.
- Deploy Uninterruptible Power Supply (UPS) systems capable of supporting the full load of critical hardware during a switchover.
- Provision automated backup generators for long-term power during extended outages.
- Enforce the use of dual power feeds (A and B feeds) for all critical rack-mounted equipment.
- Implement automated surge protection and voltage regulation to prevent hardware damage from grid instability.
3. Formalise Utility Inspection and Maintenance Schedules
Establish a regular testing and maintenance regime to ensure that backup systems and utility infrastructure remain in an optimal operating state.
- Schedule monthly UPS battery tests and quarterly load-bank testing for generators.
- Conduct annual inspections of electrical distribution boards and telecommunications junction boxes.
- Perform routine maintenance on HVAC systems to prevent climate-related hardware failures.
- Document all maintenance activities in a central log to serve as evidence for ISO 27001 audits.
4. Secure Physical Access to Utility Infrastructure
Restrict access to utility entry points and distribution hardware to prevent unauthorised tampering or accidental damage.
- Place power distribution panels and telecommunications frames within locked cabinets or secure rooms.
- Ensure that external utility meters and valves are housed in tamper-proof enclosures.
- Monitor building entry points for utility providers using CCTV or physical security patrols.
- Revoke logical or physical access for utility contractors immediately upon completion of their work.
5. Implement Diverse Telecommunications Routing
Eliminate connectivity risks by ensuring that telecommunications services are delivered via redundant routes and diverse service providers.
- Utilise two different Internet Service Providers (ISPs) that enter the building at physically separate points.
- Enforce physical segregation of data cables from high-voltage power lines to prevent electromagnetic interference.
- Configure automated failover protocols for critical network links to ensure near-zero downtime.
- Regularly verify the status of redundant links as part of your business continuity testing.
How to comply
To comply with ISO 27001 Annex A 7.11 Supporting Utilities you are going to
- Get the help of a professional third party to put in place controls around supporting utilities where required.
- Have policies and procedures in place
- Assess your assets and perform a risk assessment
- Implement controls proportionate to the risk posed
- Test the controls that you have to make sure they are working
Top 3 mistakes and how to avoid them
The top 3 mistakes people make for ISO 27001 Annex A 7.11 Supporting Utilities are
- You have no processing facilities: If everything is in the cloud then this control is potentially irrelevant to you.
- One or more members of your team haven’t done what they should have done: Prior to the audit check that all members of the team have done what they should have. Is it include in your business continuity plan if it is relevant and have you test the plan. Check!
- Your document and version control is wrong: Keeping your document version control up to date, making sure that version numbers match where used, having a review evidenced in the last 12 months, having documents that have no comments in are all good practices.
ISO 27001 Annex A 7.11 FAQ
Supporting utilities are the essential services required for information processing facilities to function effectively without interruption.
Electricity: Primary power supply and backup systems like UPS or generators.
Telecommunications: Internet and phone lines, including redundant data routes.
HVAC: Heating, ventilation, and air conditioning for server room climate control.
Water and Gas: Services required for site operation or fire suppression systems.
Yes, if your risk assessment identifies power failure as a threat to availability, a UPS or backup generator is a mandatory requirement to ensure the “Availability” pillar of the CIA triad.
UPS systems provide immediate power to prevent hardware damage during a surge or drop.
Backup generators provide long-term power during extended utility outages.
Systems must be capable of supporting the full load of critical equipment.
Utility supply lines should be physically protected from damage, tampering, or interception by ensuring they are not easily accessible to the public.
Data and power cables should be buried or placed in armoured conduits.
Entry points to the building should be secured and monitored.
Service pipes (water/gas) should be segregated from sensitive IT infrastructure.
Backup utilities should be tested at regular intervals defined by manufacturer specifications and your organisation’s specific risk appetite.
UPS batteries should be tested monthly or quarterly.
Generators should be “load tested” at least annually.
Alternative telecommunications routes should be verified during business continuity exercises.
Redundancy for supporting utilities involves eliminating single points of failure by providing multiple supply routes or diverse service providers.
Using two different internet service providers (ISPs) entering the building via separate points.
Implementing dual power feeds for critical server racks.
Ensuring HVAC systems have “N+1” redundancy to allow for maintenance or failure.
Related ISO 27001 Controls
- ISO 27001 Annex A 8.18 Use of Privileged Utility Programs
- ISO 27001 Annex A 7.8 Equipment Siting And Protection
- ISO 27001 Annex A 7.3 Securing Offices, Rooms And Facilities
- ISO 27001 Annex A 7.13 Equipment Maintenance
- ISO 27001 Annex A 5.37 Documented Operating Procedures
Controls and Attribute Values
| Control type | Information security properties | Cybersecurity concepts | Operational capabilities | Security domains |
|---|---|---|---|---|
| Preventive | Availability | Protect | Physical Security | Protection |
| Integrity | Detect | |||
Stuart Barker
I am the ISO 27001 Ninja.
I help tech companies, start-ups, and small businesses implement information security management systems without the corporate bloat or massive consultant fees.
If you want to pass your audit the first time, book a call.


