ISO 27001 Annex A 8.6 Capacity Management Explained

Stuart And Fay High Table

ISO 27001 Capacity Management

ISO 27001 Annex A 8.6 Capacity Management is an ISO 27001 control that looks to make sure you have the resources you need to the things that you need to do.

Key Takeaways

ISO 27001 Annex A 8.6 requires organizations to monitor and adjust the use of resources to ensure they meet current and future capacity requirements. Often mistaken for a simple “IT performance” task, this control is actually about Availability, ensuring your systems don’t crash because they ran out of disk space, memory, or even human staff. It moves the organization from being reactive (“The system is down!”) to being proactive (“We need to upgrade in three months”).

Purpose

The purpose of ISO 27001 Annex A 8.6 Capacity Management is to ensure the required capacity of information processing facilities, human resources, offices and other facilities.

Definition

The ISO 27001 standard defines ISO 27001 Annex A 8.6 as:

The use of resources should be monitored and adjusted in line with current and expected capacity requirements.

ISO 27001:2022 Annex A 8.6 Capacity Management

Explanation

ISO 27001 Annex A 8.6 Capacity Management is a security control that ensures organizations monitor and adjust resource usage to prevent system failures. It requires the monitoring of information processing facilities to maintain availability. The primary benefit is transforming reactive “fire-fighting” into proactive planning for future capacity requirements, ensuring business continuity.

Requirement

  • Identify Critical Resources: You must define what “capacity” means for your business. This typically includes technical resources (CPU, disk space, bandwidth), human resources (staff levels), and physical facilities (office space, power).
  • Monitoring & Thresholds: You shouldn’t wait for a failure. You must implement tools to monitor usage and set “triggers” or alerts (e.g., an alert when a database is 80% full).
  • Trend Analysis: Compliance requires looking forward. You should analyze usage patterns to predict when you will run out of resources, allowing time for procurement and implementation.
  • Tuning and Adjustment: When a threshold is hit, you must have a plan to respond, whether that’s deleting old data, auto-scaling in the cloud, or hiring additional contractors.

Audit Focus

  1. Proof of Monitoring: “Show me the dashboard where you track server CPU or cloud storage usage.”
  2. The Trigger: “Show me an example of an alert that fired recently. How did you respond to it?”
  3. Future Planning: “Show me your last capacity review meeting notes or report. How are you planning for growth next year?”

FREE Training Video

Guidance

With capacity management we are looking to make sure that we have enough resources to perform and deliver our products and services. There are varying degrees and levels of management depending on how complex you are, how complex your setup is, the organisation and your risk.

Resources to manage

The kinds of traditional capacity management and resources we would consider are things like storage space, disk space, CPU usage, memory usage, network bandwidth. You also have capacity in your staffing and also in your connected utilities.

Basically anything you use will have a capacity and a limit.

The 4 Stage Implementation Process

You are going to identify the resources that you need and use and are important to you. For those you perform a risk assessment and build controls based on risk. Upper limits need to be defined and thresholds set that trigger alerts with action plans that are activated when the threshold is triggered.

The four stages of implementation are:

  1. Identify and Assess: identify critical resources and conduct a risk assessment of capacity requirements
  2. Define and Plan: Develop a capacity management plan and define upper limits and action thresholds
  3. Monitor and Alert: Implement continuous monitoring of resource use against defined thresholds and trigger automated alerts
  4. Adjust and Respond: Execute pre defined action plans when thresholds are reached and document all adjustments
CEO at High Table: The Compliance Agency

How to implement it

Effective capacity management is essential for maintaining the availability and performance of information processing facilities. By following these technical implementation steps, your organisation can proactively scale resources, mitigate the risk of system outages, and satisfy the requirements of ISO 27001 Annex A 8.6.

1. Formalise Capacity Requirements and Performance Baselines

  • Identify critical business applications and document their technical requirements for CPU, memory, storage, and network bandwidth.
  • Establish a “Rules of Engagement” (ROE) document that defines acceptable performance thresholds and the triggers for capacity expansion.
  • Result: A documented performance baseline that ensures technical resource planning is aligned with organisational service level agreements (SLAs).

2. Provision Automated Monitoring and Telemetry Tools

  • Deploy infrastructure monitoring solutions to capture real-time telemetry from on-premises servers, cloud instances, and network appliances.
  • Configure granular dashboards to visualise resource utilisation trends and identify potential bottlenecks before they impact operational availability.
  • Result: Continuous visibility into system health, allowing for data-driven decisions regarding resource allocation and scaling.

3. Execute Trend Analysis and Forecasting Exercises

  • Perform periodic reviews of historical monitoring data to identify seasonal peaks, growth patterns, and long-term capacity trajectories.
  • Utilise predictive analytics or stress-testing tools to simulate high-load scenarios and verify that current infrastructure can handle future demand.
  • Result: Proactive capacity planning that prevents emergency provisioning and reduces the risk of unplanned downtime during peak periods.

4. Implement Automated Scaling and Resource Quotas

  • Provision auto-scaling groups within cloud environments to dynamically adjust compute resources based on real-time demand metrics.
  • Enforce hard resource quotas and limits at the container or virtual machine level to prevent “noisy neighbour” effects and ensure fair resource distribution.
  • Result: Technical resilience and cost optimisation through the efficient, automated management of shared processing facilities.

5. Restrict Capacity Management via IAM and MFA

  • Apply the Principle of Least Privilege by assigning specific Identity and Access Management (IAM) roles to personnel authorised to modify resource limits.
  • Mandate Multi-Factor Authentication (MFA) for any administrative actions that involve de-provisioning or significantly altering infrastructure capacity.
  • Result: Protection against unauthorised or accidental resource changes that could lead to service degradation or excessive operational costs.

6. Perform Periodic Capacity Audits and Baseline Reviews

  • Conduct quarterly technical audits to verify that current capacity remains sufficient for the evolving risk and demand profile of the organisation.
  • Revoke or adjust resource allocations for decommissioned projects and “orphan” assets to maintain environment hygiene and technical efficiency.
  • Result: Sustained compliance with ISO 27001 standards and the continuous optimisation of the information processing environment.

Capacity Monitoring Strategy Example

ResourceReactive (Bad)Proactive (Good / ISO Compliant)
Disk Space“The server stopped because the disk is full.”“Alert when disk is 80% full.”
CPU Load“The app is slow right now.”“Trend analysis shows we need a CPU upgrade in 3 months.”
Cloud Costs“Why is the AWS bill so high?”“Auto-scaling limits set to prevent cost spikes.”
Bandwidth“The internet is lagging.”“Traffic shaping prioritizes Zoom calls over downloads.”

How to pass the audit

Time needed: 1 day.

How to comply with ISO 27001 Annex A 8.6

  1. Have procedures in place

    Write, approve, implement and communicate the documentation required for capacity management.

  2. Assess your capacity requirements and perform a risk assessment

    Conduct a risk assessment and work out what your capacity requirements are.

  3. Implement controls proportionate to the risk posed

    Based on the risk and requirements implement the controls that are proportionate. Set upper limits for capacity, implement triggers and put in places processes to respond to those triggers and alerts.

  4. Keep records

    For audit purposes you will keep records. Examples of the records to keep include changes, updates, monitoring, review and audits.

  5. Test the controls that you have to make sure they are working

    Perform internal audits that include the testing of the controls to ensure that they are working.

Top 3 mistakes and how to avoid them

The top 3 mistakes people make for ISO 27001 Annex A 8.6 are

  • You have no capacity management plan: This usual things here that go wrong are when people don’t actually know what resources they need or what they are using or what they have. Identify your resource requirements, record what you are using, what you need, what the trigger thresholds are to take action.
  • You have not acted on plan: Having a plan and not using it is worse than no plan at all. Be sure to follow the plan and be able to evidence that you are reviewing and acting on capacity reports.
  • Your document and version control is wrong: Keeping your document version control up to date, making sure that version numbers match where used, having a review evidenced in the last 12 months, having documents that have no comments in are all good practices.

Applicability across different business models

Business TypeApplicabilityExamples of Control Implementation
Small BusinessesFocuses on ensuring that basic office resources like disk space, cloud storage limits, and internet bandwidth are sufficient for daily operations. The goal is to prevent sudden outages caused by running out of capacity.
  • Setting up automated email alerts when the company’s cloud storage (e.g., Google Drive or OneDrive) reaches 80% capacity.
  • Implementing “Traffic Shaping” on the office router to prioritize video conferencing (Zoom/Teams) over non-essential downloads.
  • Conducting a quarterly review of staff workloads to identify the need for additional part-time or contract support during peak seasons.
Tech StartupsEssential for maintaining the availability of customer-facing applications. Compliance involves automating resource scaling in the cloud and proactively managing costs to prevent service disruptions.
  • Configuring “Auto-Scaling Groups” in AWS/Azure to dynamically add or remove server instances based on real-time traffic demand.
  • Implementing “Cloud Cost Alerts” to notify the engineering team of unexpected spikes in compute or database usage.
  • Using stress-testing tools (e.g., JMeter or K6) to simulate high-load scenarios and verify that the infrastructure can handle future user growth.
AI CompaniesCritical for managing high-performance computing (HPC) resources, such as GPU clusters and massive training datasets. Focus is on efficient resource allocation and forecasting for long-running training jobs.
  • Implementing “Hard Resource Quotas” at the container level to prevent a single training job from consuming all available GPU memory.
  • Developing a capacity forecast based on the scheduled model training pipeline to ensure additional compute power is provisioned in advance.
  • Monitoring data ingestion pipelines to identify potential bottlenecks that could slow down real-time inference responses.

FAQ

Which specific resources must be monitored for Annex A 8.6 compliance?

Compliance requires monitoring a broad spectrum of resources, extending beyond just server hardware to include human and physical assets. Organizations must identify and track any resource whose depletion could disrupt information security or business operations. Mandatory categories typically include:
IT Infrastructure: CPU usage, RAM, disk storage, network bandwidth, and IP address pools.
Human Resources: Staff availability, workload capacity, and key personnel dependencies.
Physical Facilities: Office desk space, meeting room availability, power supply capacity, and secure storage (filing cabinets).
Cloud Quotas: API rate limits, licensed user counts, and cloud storage tiers.

What is the difference between reactive and proactive capacity management?

Proactive management anticipates resource exhaustion through forecasting, whereas reactive management only addresses issues after a failure has occurred. For ISO 27001 certification, a purely reactive approach (e.g., buying a new hard drive only after the server crashes) is often a major non-conformity. The distinction involves:
Reactive (Audit Risk): Responding to “disk full” errors, scrambling for new hires during burnout, or investigating high AWS bills after they arrive.
Proactive (Audit Success): Setting alerts at 80% utilization, analyzing 6-month growth trends, and configuring auto-scaling to handle traffic spikes automatically.

Does ISO 27001 capacity management apply to human resources?

Yes, human resource capacity is a critical component of Annex A 8.6 and is frequently scrutinized by auditors. You must demonstrate that you have sufficient staff to maintain security controls and operations without compromising integrity or availability. Evidence includes:
Utilization Reports: Tracking team workload to prevent burnout and error rates.
Succession Planning: Ensuring no single point of failure exists if a key administrator leaves.
Recruitment Forecasting: Aligning hiring plans with projected business growth to ensure security teams are not understaffed.

How should organizations handle cloud scaling under this control?

Cloud environments satisfy this control through “elasticity,” but organizations must configure specific constraints and alerts to remain compliant. While the cloud offers infinite theoretical capacity, your budget and configuration do not. Best practices include:
Auto-Scaling Groups: Configuring servers to automatically spin up during high-traffic events to maintain availability.
Cost/Usage Alerts: Setting budget alarms to detect runaway processes or denial-of-service attacks that consume resources.
Quota Monitoring: Tracking soft and hard limits imposed by the cloud provider (e.g., maximum number of vCPUs per region).

How often should capacity projections and trend analysis be performed?

Capacity reviews should be performed at planned intervals, typically quarterly or semi-annually, or triggered by significant operational changes. The frequency depends on the volatility of your environment. Recommended review triggers include:
Periodic Reviews: A formal quarterly meeting to analyze growth trends (e.g., “Data storage is growing 10% month-over-month”).
Project Launches: Assessing capacity impact before deploying a new resource-intensive application.
Major Acquisitions: Re-evaluating licensing and infrastructure needs immediately following a merger or bulk hiring event.

Further Reading

ISO 27001 Controls and Attribute Values

Control typeInformation
security properties
Cybersecurity
concepts
Operational
capabilities
Security domains
PreventiveAvailabilityProtectContinuityProtection
DetectiveIntegrityGovernance and Ecosystem

Strategic Briefing Slides

ISO 27001 Annex A 8.6 Capacity Management - why it is important
ISO 27001 Annex A 8.6 Capacity Management – why it is important
ISO 27001 Annex A 8.6 Capacity Management - Control Objective
ISO 27001 Annex A 8.6 Capacity Management – Control Objective
ISO 27001 Annex A 8.6 Capacity Management - Examples
ISO 27001 Annex A 8.6 Capacity Management – Examples
ISO 27001 Annex A 8.6 Capacity Management - Implementation Framework
ISO 27001 Annex A 8.6 Capacity Management – Implementation Framework
ISO 27001 Annex A 8.6 Capacity Management - Assessment and Planning
ISO 27001 Annex A 8.6 Capacity Management – Assessment and Planning
ISO 27001 Annex A 8.6 Capacity Management - Monitoring and Response
ISO 27001 Annex A 8.6 Capacity Management – Monitoring and Response
ISO 27001 Annex A 8.6 Capacity Management - Audit Checklist
ISO 27001 Annex A 8.6 Capacity Management – Audit Checklist
ISO 27001 Annex A 8.6 Capacity Management - Mistakes and How to Avoid Them
ISO 27001 Annex A 8.6 Capacity Management – Mistakes and How to Avoid Them
ISO 27001 Annex A 8.6 Capacity Management - Related ISO 27001 Controls
ISO 27001 Annex A 8.6 Capacity Management – Related ISO 27001 Controls
ISO 27001 Annex A 8.6 Capacity Management - Summary
ISO 27001 Annex A 8.6 Capacity Management – Summary

About the author

Stuart Barker
🎓 MSc Security 🛡️ Lead Auditor 30+ Years Exp 🏢 Ex-GE Leader

Stuart Barker

ISO 27001 Ninja

Stuart Barker is a veteran practitioner with over 30 years of experience in systems security and risk management. Holding an MSc in Software and Systems Security, he combines academic rigor with extensive operational experience, including a decade leading Data Governance for General Electric (GE).

As a qualified ISO 27001 Lead Auditor, Stuart possesses distinct insight into the specific evidence standards required by certification bodies. His toolkits represent an auditor-verified methodology designed to minimise operational friction while guaranteeing compliance.

ISO 27001 Annex A 8.6 Capacity Management
Shopping Basket
Scroll to Top