ISO/IEC 27001:2022 Annex A · Control 8.6
Capacity Management: A Practical Implementation Guide
Monitor and plan resources so systems remain secure and available under expected and exceptional demand.
This control concerns monitoring resource use and adjusting capacity to current and expected needs.
What should the control achieve?
- Critical capacity resources are identified.
- Thresholds and forecasts support timely action.
- Security services retain adequate capacity.
- Scaling and exhaustion scenarios are tested.
Step-by-step implementation
Identify resources
Include compute, memory, storage, network, licenses, queues, connections and people.
Set thresholds
Define normal, warning, critical and hard limits with owners.
Monitor trends
Use telemetry, business forecasts, projects and supplier quotas.
Plan headroom
Account for peaks, failover, attacks, maintenance and growth.
Automate safely
Use controlled scaling, rate limits and cost safeguards.
Test exhaustion
Exercise volume, failover and denial-of-service scenarios.
What this could look like in practice
A SaaS platform monitors storage, database connections and queue depth. Forecasting includes customer growth and failover capacity. Log storage alerts well before retention is threatened.
| Activity | Practical implementation | Evidence |
|---|---|---|
| Monitoring | Dashboards track resource and security-service health. | Capacity dashboard |
| Forecast | Business growth translates into resource plan. | Forecast |
| Threshold | Warning creates owned scaling ticket. | Alert and ticket |
| Stress test | Load test verifies scaling and rate limits. | Test report |
Implementation evidence
- Capacity policy
- Resource inventory
- Thresholds
- Dashboards
- Forecasts
- Scaling plans
- Load tests
- Capacity incidents
Useful metrics
- Threshold breaches
- Forecast accuracy
- Capacity actions overdue
- Security data lost through exhaustion
Common mistakes
- Monitoring averages instead of peaks.
- Ignoring logging and backup capacity.
- Assuming cloud capacity is unlimited.
- Failing to include supplier quotas.
- Scaling without cost and abuse limits.
Questions an auditor may ask
- Which resources can constrain critical services?
- How much headroom is required?
- Show a forecast and action.
- How is exhaustion tested?
Continue through Annex A
Explore the growing library of practical guides for all 93 Annex A controls.
Open the ISO 27001 Annex A Control LibraryThis independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.