Skip to main content

Proof of competence

ISO/IEC 27001:2022 Annex A · Control 8.6

Capacity Management: A Practical Implementation Guide

Monitor and plan resources so systems remain secure and available under expected and exceptional demand.

This control concerns monitoring resource use and adjusting capacity to current and expected needs.

Practical interpretation: Capacity shortage can become a security incident by disabling logging, backups, processing or customer service. Planning must cover technical and supplier limits.

What should the control achieve?

  • Critical capacity resources are identified.
  • Thresholds and forecasts support timely action.
  • Security services retain adequate capacity.
  • Scaling and exhaustion scenarios are tested.

Step-by-step implementation

1

Identify resources

Include compute, memory, storage, network, licenses, queues, connections and people.

2

Set thresholds

Define normal, warning, critical and hard limits with owners.

3

Monitor trends

Use telemetry, business forecasts, projects and supplier quotas.

4

Plan headroom

Account for peaks, failover, attacks, maintenance and growth.

5

Automate safely

Use controlled scaling, rate limits and cost safeguards.

6

Test exhaustion

Exercise volume, failover and denial-of-service scenarios.

What this could look like in practice

A SaaS platform monitors storage, database connections and queue depth. Forecasting includes customer growth and failover capacity. Log storage alerts well before retention is threatened.

ActivityPractical implementationEvidence
MonitoringDashboards track resource and security-service health.Capacity dashboard
ForecastBusiness growth translates into resource plan.Forecast
ThresholdWarning creates owned scaling ticket.Alert and ticket
Stress testLoad test verifies scaling and rate limits.Test report

Implementation evidence

  • Capacity policy
  • Resource inventory
  • Thresholds
  • Dashboards
  • Forecasts
  • Scaling plans
  • Load tests
  • Capacity incidents

Useful metrics

  • Threshold breaches
  • Forecast accuracy
  • Capacity actions overdue
  • Security data lost through exhaustion

Common mistakes

  • Monitoring averages instead of peaks.
  • Ignoring logging and backup capacity.
  • Assuming cloud capacity is unlimited.
  • Failing to include supplier quotas.
  • Scaling without cost and abuse limits.

Questions an auditor may ask

  • Which resources can constrain critical services?
  • How much headroom is required?
  • Show a forecast and action.
  • How is exhaustion tested?
Implementation test: Simulate a realistic demand spike and confirm monitoring, scaling, rate limits, security telemetry and business service remain effective.

Continue through Annex A

Explore the growing library of practical guides for all 93 Annex A controls.

Open the ISO 27001 Annex A Control Library

This independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.