In this guide you will learn how to implement ISO 27001 Annex A 8.6 Capacity Management and pass your audit from ISO 27001 Lead Auditor Stuart Barker – author of the ultimate ISO 27001 Toolkit.
ISO 27001 Annex A 8.6 Capacity Management is an ISO 27001 control that looks to make sure you have the resources you need to the things that you need to do.
Table of contents
- Key Takeaways
- Purpose & Definition
- FREE ISO 27001 Annex A 8.6 Training Video
- ISO 27001 Annex A 8.6 Requirements and Guidance
- How to implement ISO 27001 Annex A 8.6
- How to pass the ISO 27001 Annex A 8.6 audit
- ISO 27001 Annex A 8.6 FAQ
- Related ISO 27001 Controls
- Further Reading
- ISO 27001 Controls and Attribute Values
Key Takeaways
- ISO 27001 Annex A 8.6 requires organisations to monitor and adjust the use of resources to ensure they meet current and future capacity requirements.
- Often mistaken for a simple “IT performance” task, this control is actually about Availability, ensuring your systems don’t crash because they ran out of disk space, memory, or even human staff.
- It moves the organisation from being reactive (“The system is down!”) to being proactive (“We need to upgrade in three months”).
Purpose & Definition
The purpose of ISO 27001 Annex A 8.6 Capacity Management is to ensure the required capacity of information processing facilities, human resources, offices and other facilities.
The ISO 27001 standard defines ISO 27001 Annex A 8.6 as:
The use of resources should be monitored and adjusted in line with current and expected capacity requirements.
ISO 27001:2022 Annex A 8.6 Capacity Management
White Label
ISO 27001 for Consultants
Custom-brandable ISO 27001 documentation for consultants. Easily rebrand, reduce project time, and deliver professional, high-value security systems. Focus on delivery, not drafting.
FREE ISO 27001 Annex A 8.6 Training Video
In this free training video you will learn How to implement ISO 27001 Capacity Management (Annex A 8.6) and Pass Your Audit.
ISO 27001 Annex A 8.6 Requirements and Guidance
With capacity management we are looking to make sure that we have enough resources to perform and deliver our products and services. There are varying degrees and levels of management depending on how complex you are, how complex your setup is, the organisation and your risk.
Resources to manage
The kinds of traditional capacity management and resources we would consider are things like storage space, disk space, CPU usage, memory usage, network bandwidth. You also have capacity in your staffing and also in your connected utilities.
Basically anything you use will have a capacity and a limit.
The 4 Stage Implementation Process
You are going to identify the resources that you need and use and are important to you. For those you perform a risk assessment and build controls based on risk. Upper limits need to be defined and thresholds set that trigger alerts with action plans that are activated when the threshold is triggered.
The four stages of implementation are:
- Identify and Assess: identify critical resources and conduct a risk assessment of capacity requirements
- Define and Plan: Develop a capacity management plan and define upper limits and action thresholds
- Monitor and Alert: Implement continuous monitoring of resource use against defined thresholds and trigger automated alerts
- Adjust and Respond: Execute pre defined action plans when thresholds are reached and document all adjustments
Check Your Work?
You built it yourself. Maybe with AI. But will it pass the audit?
Don’t gamble – let an ISO 27001 Lead Auditor check your work.

How to implement ISO 27001 Annex A 8.6
Effective capacity management is essential for maintaining the availability and performance of information processing facilities. By following these technical implementation steps, your organisation can proactively scale resources, mitigate the risk of system outages, and satisfy the requirements of ISO 27001 Annex A 8.6.
1. Formalise Capacity Requirements and Performance Baselines
- Identify critical business applications and document their technical requirements for CPU, memory, storage, and network bandwidth.
- Establish a “Rules of Engagement” (ROE) document that defines acceptable performance thresholds and the triggers for capacity expansion.
- Result: A documented performance baseline that ensures technical resource planning is aligned with organisational service level agreements (SLAs).
2. Provision Automated Monitoring and Telemetry Tools
- Deploy infrastructure monitoring solutions to capture real-time telemetry from on-premises servers, cloud instances, and network appliances.
- Configure granular dashboards to visualise resource utilisation trends and identify potential bottlenecks before they impact operational availability.
- Result: Continuous visibility into system health, allowing for data-driven decisions regarding resource allocation and scaling.
3. Execute Trend Analysis and Forecasting Exercises
- Perform periodic reviews of historical monitoring data to identify seasonal peaks, growth patterns, and long-term capacity trajectories.
- Utilise predictive analytics or stress-testing tools to simulate high-load scenarios and verify that current infrastructure can handle future demand.
- Result: Proactive capacity planning that prevents emergency provisioning and reduces the risk of unplanned downtime during peak periods.
4. Implement Automated Scaling and Resource Quotas
- Provision auto-scaling groups within cloud environments to dynamically adjust compute resources based on real-time demand metrics.
- Enforce hard resource quotas and limits at the container or virtual machine level to prevent “noisy neighbour” effects and ensure fair resource distribution.
- Result: Technical resilience and cost optimisation through the efficient, automated management of shared processing facilities.
5. Restrict Capacity Management via IAM and MFA
- Apply the Principle of Least Privilege by assigning specific Identity and Access Management (IAM) roles to personnel authorised to modify resource limits.
- Mandate Multi-Factor Authentication (MFA) for any administrative actions that involve de-provisioning or significantly altering infrastructure capacity.
- Result: Protection against unauthorised or accidental resource changes that could lead to service degradation or excessive operational costs.
6. Perform Periodic Capacity Audits and Baseline Reviews
- Conduct quarterly technical audits to verify that current capacity remains sufficient for the evolving risk and demand profile of the organisation.
- Revoke or adjust resource allocations for decommissioned projects and “orphan” assets to maintain environment hygiene and technical efficiency.
- Result: Sustained compliance with ISO 27001 standards and the continuous optimisation of the information processing environment.
How to pass the ISO 27001 Annex A 8.6 audit
Time needed: 1 day.
How to comply with ISO 27001 Annex A 8.6
- Have procedures in place
Write, approve, implement and communicate the documentation required for capacity management.
- Assess your capacity requirements and perform a risk assessment
Conduct a risk assessment and work out what your capacity requirements are.
- Implement controls proportionate to the risk posed
Based on the risk and requirements implement the controls that are proportionate. Set upper limits for capacity, implement triggers and put in places processes to respond to those triggers and alerts.
- Keep records
For audit purposes you will keep records. Examples of the records to keep include changes, updates, monitoring, review and audits.
- Test the controls that you have to make sure they are working
Perform internal audits that include the testing of the controls to ensure that they are working.
Top 3 mistakes and how to avoid them
The top 3 mistakes people make for ISO 27001 Annex A 8.6 are
- You have no capacity management plan: This usual things here that go wrong are when people don’t actually know what resources they need or what they are using or what they have. Identify your resource requirements, record what you are using, what you need, what the trigger thresholds are to take action.
- You have not acted on plan: Having a plan and not using it is worse than no plan at all. Be sure to follow the plan and be able to evidence that you are reviewing and acting on capacity reports.
- Your document and version control is wrong: Keeping your document version control up to date, making sure that version numbers match where used, having a review evidenced in the last 12 months, having documents that have no comments in are all good practices.
ISO 27001 Annex A 8.6 FAQ
Compliance requires monitoring a broad spectrum of resources, extending beyond just server hardware to include human and physical assets. Organizations must identify and track any resource whose depletion could disrupt information security or business operations. Mandatory categories typically include:
IT Infrastructure: CPU usage, RAM, disk storage, network bandwidth, and IP address pools.
Human Resources: Staff availability, workload capacity, and key personnel dependencies.
Physical Facilities: Office desk space, meeting room availability, power supply capacity, and secure storage (filing cabinets).
Cloud Quotas: API rate limits, licensed user counts, and cloud storage tiers.
Proactive management anticipates resource exhaustion through forecasting, whereas reactive management only addresses issues after a failure has occurred. For ISO 27001 certification, a purely reactive approach (e.g., buying a new hard drive only after the server crashes) is often a major non-conformity. The distinction involves:
Reactive (Audit Risk): Responding to “disk full” errors, scrambling for new hires during burnout, or investigating high AWS bills after they arrive.
Proactive (Audit Success): Setting alerts at 80% utilization, analyzing 6-month growth trends, and configuring auto-scaling to handle traffic spikes automatically.
Yes, human resource capacity is a critical component of Annex A 8.6 and is frequently scrutinized by auditors. You must demonstrate that you have sufficient staff to maintain security controls and operations without compromising integrity or availability. Evidence includes:
Utilization Reports: Tracking team workload to prevent burnout and error rates.
Succession Planning: Ensuring no single point of failure exists if a key administrator leaves.
Recruitment Forecasting: Aligning hiring plans with projected business growth to ensure security teams are not understaffed.
Cloud environments satisfy this control through “elasticity,” but organizations must configure specific constraints and alerts to remain compliant. While the cloud offers infinite theoretical capacity, your budget and configuration do not. Best practices include:
Auto-Scaling Groups: Configuring servers to automatically spin up during high-traffic events to maintain availability.
Cost/Usage Alerts: Setting budget alarms to detect runaway processes or denial-of-service attacks that consume resources.
Quota Monitoring: Tracking soft and hard limits imposed by the cloud provider (e.g., maximum number of vCPUs per region).
Capacity reviews should be performed at planned intervals, typically quarterly or semi-annually, or triggered by significant operational changes. The frequency depends on the volatility of your environment. Recommended review triggers include:
Periodic Reviews: A formal quarterly meeting to analyze growth trends (e.g., “Data storage is growing 10% month-over-month”).
Project Launches: Assessing capacity impact before deploying a new resource-intensive application.
Major Acquisitions: Re-evaluating licensing and infrastructure needs immediately following a merger or bulk hiring event.
Related ISO 27001 Controls
- ISO 27001 Clause 9.1 Monitoring, Measurement, Analysis, Evaluation
- ISO 27001 Clause 7.1 Resources
- ISO 27001 Clause 6.1.1 Planning General
Further Reading
ISO 27001 Controls and Attribute Values
| Control type | Information security properties | Cybersecurity concepts | Operational capabilities | Security domains |
|---|---|---|---|---|
| Preventive | Availability | Protect | Continuity | Protection |
| Detective | Integrity | Governance and Ecosystem | ||
