Capacity Management - ISO 27001 Annex A Control

ISO 27001 Annex A 8.6

Capacity exhaustion takes systems down as effectively as a deliberate attack.

ISO 27001 Annex A 8.6 - Capacity Management

Capacity sits in the availability column of the security triad. When systems run out of storage, memory, processing capacity or network bandwidth, they slow down or stop. The control asks for capacity to be tracked actively rather than discovered when something fails. Cloud platforms make scaling easier but do not remove the need to monitor and forecast.

Practical capacity management combines monitoring (current usage of key resources), forecasting (projected demand), and provisioning (action taken before limits are reached). Each element matters: monitoring without forecasting only catches problems late; forecasting without provisioning is information without action.

The control links to business continuity. Capacity failures count as availability incidents and need the same incident response process as security events. They also feed into capacity-related risk in the risk register and into the requirements for redundancy under A.8.14.

Capacity issues tend to compound. A storage volume nearing capacity slows down, which slows the application, which extends user sessions, which generates more log data, which fills the storage faster. Catching the early signs through monitoring stops the cycle before it becomes user-visible.

Practical Compliance Guidance

Capacity management is described in the IMS1 Manual in Section 8.2 on IT equipment alongside the wider operational arrangements. Monitoring tools and provisioning procedures provide the operational record.

alphaZ document How to use it
ISO 27001 Toolkit The full alphaZ ISO 27001 toolkit including the IMS1 Manual, policies, procedures, registers and audit checklists.
PP-8-100 Information Security Policy Procedure Contains the operational arrangements relevant to capacity management. Use as the source for capacity governance and the link to wider availability controls.

Note - all the above files can be downloaded with an alphaZ subscription.

Frequently Asked Questions

The resources that constrain availability - storage, memory, processing, network bandwidth, database connections, license counts. Each system has its own capacity profile and the monitoring should reflect what actually limits that system.
Cloud platforms can scale automatically for many resources, but the organisation still needs to monitor cost (auto-scaling has a budget impact) and to confirm that scaling actually happens as expected. Cloud capacity management tends to focus on cost ceilings rather than physical limits.
Through the incident management process. The same recording, response and learning steps apply whether the incident was a security breach, a hardware failure or a capacity exhaustion. The risk register should reflect any patterns that emerge.

Further Resources

payment logos