In this guide you will learn how to implement ISO 27001 Annex A 7.13 and pass your audit from ISO 27001 Lead Auditor Stuart Barker – author of the ultimate ISO 27001 Toolkit.
ISO 27001 Annex A 7.13 Equipment Maintenance is an ISO 27001 control that looks to make sure you maintain your equipment in line with guidance so it keeps working and protects the confidentiality, integrity and availability of data.
Table of contents
Purpose & Definition
The purpose of ISO 27001 Equipment Maintenance is to prevent loss, damage, theft or compromise of information and other associated assets and interruption to the organisations operations caused by lack of maintenance.
The ISO 27001 standard defines ISO 27001 Annex A 7.13 as:
Equipment should be maintained correctly to ensure availability, integrity and confidentiality of information.
ISO 27001:2022 Annex A 7.13 Equipment Maintenance
White Label
ISO 27001 for Consultants
Custom-brandable ISO 27001 documentation for consultants. Easily rebrand, reduce project time, and deliver professional, high-value security systems. Focus on delivery, not drafting.
FREE ISO 27001 Annex A 7.13 Training Video
In this free training video you will learn How to implement ISO 27001 Equipment Maintenance (Annex A 7.13) and Pass Your Audit.
Implementation Guide
Maintain Equipment
Equipment that is used will need to be maintained so that it keeps operating. If you do not maintain equipment then the risk of the device failing or being compromised is going to increase. For this control it is as simple as following the manufactures guidelines for maintenance for your equipment.
To some extent this control is outside of your gift to control but there are some considerations that you can put in place and evidence.
Manufacturers Guidelines
To meet the control you would, as with everything, operate any equipment and maintain it in line with the manufacturers guidelines. This usually means appropriate professional maintenance. The professional maintenance would include testing and inspection although we would expect this to be a legal and regulatory requirement anyway, usually around health and safety.
Use Professionals
The advice here is, if you have a server room or information processing facility to bring in professional third parties to advise and maintain equipment. This is not something you will undertake yourself and there are many laws that govern this that are outside your capability.
Providing Access
The things that you can do and consider include access. We cover this in access control but looking at how people are allowed on site or remotely connect and how you supervise the activity are in your control. Monitoring for faults and having a process to record and respond to incidents is a simple step you can implement.
Fire Safety Equipment
There are some things that you might not have thought about that can catch you out. These include maintaining all your fire safety equipment such as extinguishers and alarms.
How to implement ISO 27001 Annex A 7.13
Implementing ISO 27001 Annex A 7.13 requires a proactive strategy to ensure hardware reliability and security.
1. Formalise the Equipment Maintenance Schedule
Develop a structured maintenance plan based on manufacturer specifications and the criticality of the asset to ensure continued availability and integrity.
- Review manufacturer service intervals for all critical infrastructure hardware.
- Identify high-priority assets within the Asset Register that require more frequent inspections.
- Document the planned maintenance dates to avoid operational downtime during peak hours.
- Assign clear ownership for maintenance tasks to specific facilities or IT teams.
2. Authenticate and Supervise Maintenance Personnel
Ensure that only vetted and authorised technicians have physical or logical access to organisational equipment to mitigate the risk of tampering or data theft.
- Verify the credentials of third-party engineers before granting site access.
- Enforce strict supervision requirements for any maintenance performed in secure areas like server rooms.
- Provision temporary access badges that are logged and revoked immediately upon completion of the work.
- Ensure that all maintenance staff have signed a Non-Disclosure Agreement (NDA) or similar confidentiality contract.
3. Provision Secure Off-Site Repair Protocols
Establish strict security measures for equipment that must be removed from the secure perimeter for technical repairs or servicing.
- Mandate full-disk encryption (FDE) for any portable device or storage media leaving the premises.
- Remove highly sensitive storage components or securely wipe data before transport if repairs do not require data access.
- Formalise a secure chain of custody using tracked couriers or internal logistics.
- Inspect the equipment upon return to verify that no unauthorised hardware modifications have occurred.
4. Restrict and Monitor Remote Maintenance Access
Apply technical barriers to remote diagnostic connections to prevent external providers from gaining persistent or unauthorised network access.
- Disable remote maintenance ports by default and only activate them for the duration of the service.
- Enforce Multi-Factor Authentication (MFA) for any remote connection made by a service provider.
- Apply granular IAM roles and Least Privilege access to ensure the technician only reaches the specific system being maintained.
- Monitor and log all remote sessions in real time for audit purposes.
5. Maintain the Formal Maintenance Log
Record every maintenance action to provide a verifiable audit trail that demonstrates compliance with ISO 27001 requirements.
- Update the maintenance log with the specific date, time, and nature of the repair.
- Document any hardware components that were replaced or upgraded.
- Include a formal sign-off from the internal asset owner confirming the device is back in a secure operating state.
- Review logs during internal ISMS audits to identify recurring hardware failures that may indicate a security risk.
How to comply
To comply with ISO 27001 Annex A 7.13 Equipment Maintenance you are going to
- Get the help of professional third parties to put in place controls around maintenance where required.
- Have policies and procedures in place
- Assess your equipment and perform a risk assessment
- Implement controls proportionate to the risk posed
- Keep maintenance records
- Test the controls that you have to make sure they are working
Top 3 mistakes and how to avoid them
The top 3 mistakes people make for ISO 27001 Annex A 7.13 Equipment Maintenance are
- You have no records of maintenance: Keep records that show that things have been maintained and that it has followed the guidance of the manufacturer. Record keeping!
- You forgot about fire extinguishers: Proper left field this one but they do check and they can fail you on it. Check!
- Your document and version control is wrong: Keeping your document version control up to date, making sure that version numbers match where used, having a review evidenced in the last 12 months, having documents that have no comments in are all good practices.
ISO 27001 Annex A 7.13 FAQ
Yes, maintaining a detailed maintenance log is mandatory under ISO 27001 as it serves as primary evidence during an audit that hardware is being managed in accordance with security requirements.
Logs should include the date and time of maintenance.
A description of the work performed and the parts replaced.
Information on whether the service was routine or corrective.
Confirmation of the technician’s identity and authorisation.
Securing equipment for off-site maintenance involves implementing strict data protection controls and physical security measures before the hardware leaves the organization’s secure perimeter.
Enable full-disk encryption to prevent unauthorized data access.
Remove or securely wipe sensitive storage media if the repair does not require it.
Ensure a Non-Disclosure Agreement (NDA) is in place with the service provider.
Use secure, tracked transport to move assets between locations.
Third-party maintenance providers must be vetted and managed under supplier security requirements to ensure they do not compromise the organization’s security posture.
Contractual clauses must define security responsibilities and data handling.
Technicians should be supervised while in secure areas.
Remote maintenance access must be granted only when needed and logged.
Providers must demonstrate their own security credentials or compliance.
Poor equipment maintenance leads to critical security vulnerabilities, primarily affecting the availability and integrity of sensitive organizational data.
Unexpected hardware failure causing significant operational downtime.
Data corruption due to malfunctioning storage or processing components.
Exploitable physical vulnerabilities in aging or unpatched hardware.
Unauthorised physical access if maintenance bypasses standard security protocols.
Primary responsibility for Annex A 7.13 usually falls to the Facilities Management or IT Operations team, under the oversight of the Chief Information Security Officer (CISO).
IT Operations manage the scheduling of hardware servicing.
The Asset Owner ensures the equipment is functioning as required.
The CISO ensures maintenance activities align with the broader ISMS.
Internal Auditors verify that maintenance logs are complete and accurate.
Related ISO 27001 Controls
Controls and Attribute Values
| Control type | Information security properties | Cybersecurity concepts | Operational capabilities | Security domains |
|---|---|---|---|---|
| Preventive | Confidentiality | Protect | Physical Security | Protection |
| Integrity | Detect | Asset Management | Resilience | |
| Availability |
Stuart Barker
I am the ISO 27001 Ninja.
I help tech companies, start-ups, and small businesses implement information security management systems without the corporate bloat or massive consultant fees.
If you want to pass your audit the first time, book a call.


