Skip to main content

Proof of competence

ISO/IEC 27001:2022 Annex A · Control 7.13

Equipment Maintenance: A Practical Implementation Guide

Maintain equipment reliably without exposing information or introducing unauthorized changes.

This control concerns maintaining equipment correctly to preserve availability, integrity and confidentiality.

Practical interpretation: Maintenance creates privileged physical access and may expose stored data. Scheduling, authorization, supplier control, records and post-maintenance verification are essential.

What should the control achieve?

  • Maintenance follows manufacturer and risk requirements.
  • Only authorized competent personnel perform work.
  • Information is protected during repair and servicing.
  • Equipment is verified before return to operation.

Step-by-step implementation

1

Inventory maintenance needs

Record equipment, owner, schedule, warranty, provider and criticality.

2

Plan and authorize work

Use maintenance windows, work orders, backups and rollback.

3

Control technicians

Verify identity, access scope, tools and supervision.

4

Protect information

Remove or encrypt media, restrict diagnostic copies and use confidentiality terms.

5

Record changes and parts

Document work, firmware, configuration, replaced components and custody.

6

Validate service

Test security settings, function, logs and asset records before closure.

What this could look like in practice

Before a printer with stored jobs leaves site for repair, IT removes its drive where possible or uses an approved provider under custody and confidentiality terms. Returned equipment is inspected, reset to baseline and tested.

ActivityPractical implementationEvidence
Preventive maintenanceSchedule follows criticality and manufacturer guidance.Maintenance calendar
On-site repairTechnician is authorized and supervised.Visitor and work record
Off-site repairData risk and chain of custody are controlled.Repair transfer
Return to serviceConfiguration and security checks are completed.Acceptance checklist

Implementation evidence

  • Maintenance inventory
  • Schedules
  • Work orders
  • Technician authorization
  • Custody records
  • Confidentiality terms
  • Configuration checks
  • Asset updates

Useful metrics

  • Critical maintenance overdue
  • Unplanned failures linked to maintenance
  • Repairs with complete custody
  • Post-maintenance security failures

Common mistakes

  • Sending equipment with readable storage to unknown repairers.
  • Allowing technicians unrestricted facility access.
  • Updating firmware without change control.
  • Failing to inspect replacement parts.
  • Closing work without security validation.

Questions an auditor may ask

  • How are maintenance schedules set?
  • How is data protected during repair?
  • Show technician authorization and custody.
  • What checks occur before return to service?
Implementation test: Select a recent repair and trace approval, technician access, data protection, parts, configuration and validation.

Continue through Annex A

Explore the growing library of practical guides for all 93 Annex A controls.

Open the ISO 27001 Annex A Control Library

This independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.