Skip to content
compliancebase
ISO 27001A.7 — Supporting utilities

A.7.11

Supporting utilities

ISO 27001 · ISO/IEC 27001:2022 · Last verified August 2026

Objective

Protect facilities against failures of supporting utilities that could impact information processing.

Points of focus

  • Identify critical utilities
  • Inherit CSP utility controls
  • Office UPS/surge for critical network gear
  • Maintenance contacts

Implementation notes

For production in major clouds, cite provider SOC/ISO evidence. For offices, keep proportionate UPS on firewalls if they terminate critical VPN. Assign a named owner in the SoA, tie operating evidence to utility dependency note in risk assessment, and sample the control during internal audit before Stage 2 fieldwork.

Audit tip: Present SoA decision and CSP evidence or office UPS records.

Evidence auditors typically request:

  • Utility dependency note in risk assessment
  • CSP report excerpt on power/HVAC
  • Office UPS maintenance log if applicable
  • SoA applicability decision

Common gaps

  • No statement on cloud inheritance
  • Office Wi-Fi router without surge protection for a regulated on-prem appliance

Cross-Framework Mapping

FrameworkRequirementImplementation note
ISO 27001A.7.11This control
SOC 2A1.2Related SOC 2 themes (A1.2) — map in your crosswalk; not identical requirements.

Primary sources

Frequently Asked Questions

Not for cloud production; focus on CSP SLAs and office continuity for people.

A.8.14 is processing redundancy; A.7.11 is utility supply to facilities.

Network service continuity overlaps A.8.21/A.8.14 — document where you put it.

Even without owned data centers, supporting utilities still applies to how you operate endpoints, IdP, cloud consoles, and vendor services in scope. Exclude controls in the SoA only with a documented, risk-based rationale.

Start with utility dependency note in risk assessment, assign a named control owner, and retain dated samples from your ticketing or GRC system — not one-off screenshots assembled before audit fieldwork.

Framework versions referenced in this page:

  • ISO/IEC 27001ISO/IEC 27001:2022

Last verified: August 2026 · Primary sources linked above