ISO 27001 Annex A 8.6 Audit Checklist

The ultimate audit guide to ISO 27001 Annex A 8.6 Capacity Management

1. Capacity Requirements Baseline Verified

Verification Criteria: Documented performance baselines and future capacity requirements exist for all critical information systems and infrastructure.

Required Evidence: Capacity Plan or System Design documents specifying CPU, RAM, storage, and network bandwidth thresholds.

Pass/Fail Test: If the organisation cannot produce defined capacity limits for production environments, mark as Non-Compliant.

2. Real-Time Resource Monitoring Confirmed

Verification Criteria: Technical monitoring tools are active and configured to track resource utilisation against established baselines.

Required Evidence: Live dashboard access or historical reports from monitoring software (e.g., Datadog, Nagios, Zabbix, or CloudWatch).

Pass/Fail Test: If critical servers or cloud instances are not being actively monitored for resource consumption, mark as Non-Compliant.

3. Capacity Threshold Alerting Validation

Verification Criteria: Automated alerts are configured to trigger when resource utilisation approaches or exceeds defined capacity limits (e.g., 80% disk usage).

Required Evidence: Configuration screenshots showing alert triggers and corresponding notification logs (email, SMS, or Slack).

Pass/Fail Test: If monitoring exists but lacks automated alerting for near-exhaustion of resources, mark as Non-Compliant.

4. Cloud Auto-Scaling Policies Validated

Verification Criteria: For cloud-native environments, auto-scaling policies are defined and tested to handle traffic spikes without manual intervention.

Required Evidence: Cloud console configuration (AWS Auto Scaling, Azure VM Scale Sets) showing ‘Max’ and ‘Min’ instance limits.

Pass/Fail Test: If the organisation relies on manual scaling for production workloads prone to volatility, mark as Non-Compliant.

5. Capacity Trend Analysis Records Identified

Verification Criteria: Periodic analysis of historical performance data is conducted to identify growth trends and forecast future resource needs.

Required Evidence: Quarterly Capacity Review reports or Management Information (MI) packs showing trend lines and forecasting logic.

Pass/Fail Test: If the organisation only reacts to outages rather than analysing trends to predict future capacity shortages, mark as Non-Compliant.

6. Network Bandwidth Sufficiency Confirmed

Verification Criteria: Network throughput and latency are monitored to ensure adequate bandwidth for both internal operations and external service delivery.

Required Evidence: Network traffic logs or ISP utilisation reports showing peak-load performance metrics.

Pass/Fail Test: If network bottlenecks consistently degrade security monitoring or data backup processes, mark as Non-Compliant.

7. Physical Facility Capacity Verification (On-Premise)

Verification Criteria: Physical infrastructure (UPS load, HVAC cooling, floor space) is monitored to ensure it supports the current hardware footprint.

Required Evidence: Facilities management logs or power consumption reports for the server room/data centre.

Pass/Fail Test: If the UPS or HVAC systems are operating at 100% capacity with no room for failover or growth, mark as Non-Compliant.

8. Data Storage Lifecycle and Purging Validated

Verification Criteria: Procedures exist for the regular removal or archiving of redundant data to reclaim storage capacity.

Required Evidence: Data Retention Policy and logs showing the execution of automated or manual data purging scripts.

Pass/Fail Test: If storage is managed solely by adding more hardware without a defined data deletion/archiving schedule, mark as Non-Compliant.

9. Capacity Incident Linkage Verified

Verification Criteria: System outages caused by capacity exhaustion are formally recorded and investigated as information security incidents.

Required Evidence: Cross-reference between monitoring alerts and the Information Security Incident Register.

Pass/Fail Test: If a disk-full or CPU-exhaustion crash occurred but was not raised as an incident for root cause analysis, mark as Non-Compliant.

10. Management Review of Capacity Strategy Recorded

Verification Criteria: Senior management reviews capacity metrics and approves budget for future infrastructure expansion based on verified data.

Required Evidence: Management Review Meeting (MRM) minutes or approved budgetary requests for capacity upgrades.

Pass/Fail Test: If there is no evidence that leadership is briefed on capacity risks or future infrastructure requirements, mark as Non-Compliant.

About the author

Stuart Barker
🎓 MSc Security 🛡️ Lead Auditor 30+ Years Exp 🏢 Ex-GE Leader

Stuart Barker

ISO 27001 Ninja

Stuart Barker is a veteran practitioner with over 30 years of experience in systems security and risk management. Holding an MSc in Software and Systems Security, he combines academic rigor with extensive operational experience, including a decade leading Data Governance for General Electric (GE).

As a qualified ISO 27001 Lead Auditor, Stuart possesses distinct insight into the specific evidence standards required by certification bodies. His toolkits represent an auditor-verified methodology designed to minimise operational friction while guaranteeing compliance.

Shopping Basket
Scroll to Top