ISO/IEC 27001:2022 Annex A · Control 7.13
Equipment Maintenance: A Practical Implementation Guide
Maintain equipment reliably without exposing information or introducing unauthorized changes.
This control concerns maintaining equipment correctly to preserve availability, integrity and confidentiality.
What should the control achieve?
- Maintenance follows manufacturer and risk requirements.
- Only authorized competent personnel perform work.
- Information is protected during repair and servicing.
- Equipment is verified before return to operation.
Step-by-step implementation
Inventory maintenance needs
Record equipment, owner, schedule, warranty, provider and criticality.
Plan and authorize work
Use maintenance windows, work orders, backups and rollback.
Control technicians
Verify identity, access scope, tools and supervision.
Protect information
Remove or encrypt media, restrict diagnostic copies and use confidentiality terms.
Record changes and parts
Document work, firmware, configuration, replaced components and custody.
Validate service
Test security settings, function, logs and asset records before closure.
What this could look like in practice
Before a printer with stored jobs leaves site for repair, IT removes its drive where possible or uses an approved provider under custody and confidentiality terms. Returned equipment is inspected, reset to baseline and tested.
| Activity | Practical implementation | Evidence |
|---|---|---|
| Preventive maintenance | Schedule follows criticality and manufacturer guidance. | Maintenance calendar |
| On-site repair | Technician is authorized and supervised. | Visitor and work record |
| Off-site repair | Data risk and chain of custody are controlled. | Repair transfer |
| Return to service | Configuration and security checks are completed. | Acceptance checklist |
Implementation evidence
- Maintenance inventory
- Schedules
- Work orders
- Technician authorization
- Custody records
- Confidentiality terms
- Configuration checks
- Asset updates
Useful metrics
- Critical maintenance overdue
- Unplanned failures linked to maintenance
- Repairs with complete custody
- Post-maintenance security failures
Common mistakes
- Sending equipment with readable storage to unknown repairers.
- Allowing technicians unrestricted facility access.
- Updating firmware without change control.
- Failing to inspect replacement parts.
- Closing work without security validation.
Questions an auditor may ask
- How are maintenance schedules set?
- How is data protected during repair?
- Show technician authorization and custody.
- What checks occur before return to service?
Continue through Annex A
Explore the growing library of practical guides for all 93 Annex A controls.
Open the ISO 27001 Annex A Control LibraryThis independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.