ISO 27001:2022 Annex A 7.11 Supporting Utilities Explained

ISO 27001 Annex A 7.11 Supporting Utilities

In this guide you will learn how to implement ISO 27001 Annex A 7.11 and pass your audit from ISO 27001 Lead Auditor Stuart Barker – author of the ultimate ISO 27001 Toolkit.

ISO 27001 Annex A 7.11 Supporting Utilities is an ISO 27001 control that looks to make sure you have consider services such as power and internet connectivity and what you will do if they go down.

Purpose & Definition

The purpose of ISO 27001 Annex A 7.11 Supporting Utilities is to prevent loss, damage or compromise of information and other associated assets, or interruption to the organisations operations due to failure and disruption of supporting utilities.

The ISO 27001 standard defines Supporting Utilities as:

Information processing facilities should be protected from power failures and other disruptions caused by failures in supporting utilities.

ISO 27001:2022 Annex A 7.11 Supporting Utilities

FREE ISO 27001 Annex A 7.11 Training Video

In this free training video you will learn How to implement ISO 27001 Supporting Utilities (Annex A 7.11) and Pass Your Audit.

Implementation Guide

General Guidance

Supporting utilities are the utilities that a company provides as a service such as an electricity or gas supply. As a physical control this relates to information processing utilities such as data centres and server rooms but we can consider it in the context of end point user devices as well.

This control is really looking at availability, and the ability to continue to provide a service if the supply of power is interrupted.

To some extent this control is outside of your gift to control but there are some considerations that you can put in place and evidence.

The standard is a little overkill and for most small organisations elements of this will not apply.

Operate and Maintain Equipment

To meet the control you would, as with everything, operate any equipment that supports the utilities in line with the manufacturers guidelines. This usually means appropriate operation and professional maintenance. The professional maintenance would include testing and inspection although we would expect this to be a legal and regulatory requirement anyway, usually around health and safety.

Internet of Things (IOT)

The control raises an interesting point about not connecting support equipment to the internet if it isn’t necessary, which is a nod to the move to the internet of things (IOT).

Emergency Supporting Controls

Finally for this control is guidance on emergency supporting controls. What we mean here are things like emergency lighting, communications, cut off switches, emergency exits. As mentioned before this overkill for a small organisation and covered by your cloud provider where you have one.

The advice here is, if you have a server room or information processing facility to bring in professional third parties to advise and implement. This is not something you will undertake yourself and there are many laws that govern this that are outside your capability. Cover it in you business continuity plan on a practical side consider if you need to think about Uninterrupted Power Supplies (UPS) and alternatives for network connectivity.

How to implement ISO 27001 Annex A 7.11

Implementing ISO 27001 Annex A 7.11 requires a robust approach to physical infrastructure to ensure that information processing facilities are resilient against utility failures.

1. Identify and Map Critical Utility Dependencies

Perform a comprehensive audit of all utilities required for the continued operation of information processing facilities to identify potential single points of failure.

  • Document all primary and secondary power sources, including grid connections and on-site distribution boards.
  • Map telecommunications entry points and internal routing to ensure diverse paths for data connectivity.
  • Identify critical HVAC (Heating, Ventilation, and Air Conditioning) requirements for server rooms and data centres.
  • Verify the location of water and gas supply lines to ensure they do not pose a leak or fire risk to IT hardware.

2. Provision Redundant Power and Backup Systems

Install and configure backup power solutions to ensure that critical systems remain available during a primary utility failure or surge.

  • Deploy Uninterruptible Power Supply (UPS) systems capable of supporting the full load of critical hardware during a switchover.
  • Provision automated backup generators for long-term power during extended outages.
  • Enforce the use of dual power feeds (A and B feeds) for all critical rack-mounted equipment.
  • Implement automated surge protection and voltage regulation to prevent hardware damage from grid instability.

3. Formalise Utility Inspection and Maintenance Schedules

Establish a regular testing and maintenance regime to ensure that backup systems and utility infrastructure remain in an optimal operating state.

  • Schedule monthly UPS battery tests and quarterly load-bank testing for generators.
  • Conduct annual inspections of electrical distribution boards and telecommunications junction boxes.
  • Perform routine maintenance on HVAC systems to prevent climate-related hardware failures.
  • Document all maintenance activities in a central log to serve as evidence for ISO 27001 audits.

4. Secure Physical Access to Utility Infrastructure

Restrict access to utility entry points and distribution hardware to prevent unauthorised tampering or accidental damage.

  • Place power distribution panels and telecommunications frames within locked cabinets or secure rooms.
  • Ensure that external utility meters and valves are housed in tamper-proof enclosures.
  • Monitor building entry points for utility providers using CCTV or physical security patrols.
  • Revoke logical or physical access for utility contractors immediately upon completion of their work.

5. Implement Diverse Telecommunications Routing

Eliminate connectivity risks by ensuring that telecommunications services are delivered via redundant routes and diverse service providers.

  • Utilise two different Internet Service Providers (ISPs) that enter the building at physically separate points.
  • Enforce physical segregation of data cables from high-voltage power lines to prevent electromagnetic interference.
  • Configure automated failover protocols for critical network links to ensure near-zero downtime.
  • Regularly verify the status of redundant links as part of your business continuity testing.

How to comply

To comply with ISO 27001 Annex A 7.11 Supporting Utilities you are going to

  • Get the help of a professional third party to put in place controls around supporting utilities where required.
  • Have policies and procedures in place
  • Assess your assets and perform a risk assessment
  • Implement controls proportionate to the risk posed
  • Test the controls that you have to make sure they are working

Top 3 mistakes and how to avoid them

The top 3 mistakes people make for ISO 27001 Annex A 7.11 Supporting Utilities are

  • You have no processing facilities: If everything is in the cloud then this control is potentially irrelevant to you.
  • One or more members of your team haven’t done what they should have done: Prior to the audit check that all members of the team have done what they should have. Is it include in your business continuity plan if it is relevant and have you test the plan. Check!
  • Your document and version control is wrong: Keeping your document version control up to date, making sure that version numbers match where used, having a review evidenced in the last 12 months, having documents that have no comments in are all good practices.

ISO 27001 Annex A 7.11 FAQ

What are considered supporting utilities in ISO 27001?

Supporting utilities are the essential services required for information processing facilities to function effectively without interruption.
Electricity: Primary power supply and backup systems like UPS or generators.
Telecommunications: Internet and phone lines, including redundant data routes.
HVAC: Heating, ventilation, and air conditioning for server room climate control.
Water and Gas: Services required for site operation or fire suppression systems.

Is an Uninterruptible Power Supply (UPS) mandatory for ISO 27001?

Yes, if your risk assessment identifies power failure as a threat to availability, a UPS or backup generator is a mandatory requirement to ensure the “Availability” pillar of the CIA triad.
UPS systems provide immediate power to prevent hardware damage during a surge or drop.
Backup generators provide long-term power during extended utility outages.
Systems must be capable of supporting the full load of critical equipment.

How do you protect utility supply lines?

Utility supply lines should be physically protected from damage, tampering, or interception by ensuring they are not easily accessible to the public.
Data and power cables should be buried or placed in armoured conduits.
Entry points to the building should be secured and monitored.
Service pipes (water/gas) should be segregated from sensitive IT infrastructure.

How often should backup utilities be tested?

Backup utilities should be tested at regular intervals defined by manufacturer specifications and your organisation’s specific risk appetite.
UPS batteries should be tested monthly or quarterly.
Generators should be “load tested” at least annually.
Alternative telecommunications routes should be verified during business continuity exercises.

What is the redundancy requirement for Annex A 7.11?

Redundancy for supporting utilities involves eliminating single points of failure by providing multiple supply routes or diverse service providers.
Using two different internet service providers (ISPs) entering the building via separate points.
Implementing dual power feeds for critical server racks.
Ensuring HVAC systems have “N+1” redundancy to allow for maintenance or failure.

Controls and Attribute Values

Control typeInformation
security properties
Cybersecurity
concepts
Operational
capabilities
Security domains
PreventiveAvailabilityProtectPhysical SecurityProtection
IntegrityDetect

Stuart Barker

I am the ISO 27001 Ninja.

I help tech companies, start-ups, and small businesses implement information security management systems without the corporate bloat or massive consultant fees.

If you want to pass your audit the first time, book a call.

Shopping Basket
Scroll to Top