ISO 27001A.7 — Equipment maintenance
A.7.13
Equipment maintenance
ISO 27001 · ISO/IEC 27001:2022 · Last verified August 2026
Objective
Maintain equipment correctly to ensure availability and integrity of information processing.
Points of focus
- Authorized maintainers only
- Record maintenance activities
- Protect data during maintenance
- Cover remote hands / CSP processes
Implementation notes
Escort third-party maintainers. Log firmware and hardware changes. Prefer cloud provider maintenance over owning servers. Wipe disks before RMA. Assign a named owner in the SoA, tie operating evidence to maintenance procedure, and sample the control during internal audit before Stage 2 fieldwork.
Audit tip: Sample firewall firmware updates and vendor visit logs; show wipe evidence for any RMA.
Evidence auditors typically request:
- Maintenance procedure
- Vendor NDAs for maintainers
- Maintenance tickets/logs
- CSP maintenance inheritance note
Common gaps
- Unescorted vendor in IDF
- No logs of firmware updates on firewalls
- Drives removed without wipe
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| ISO 27001 | A.7.13 | This control |
| SOC 2 | CC7.1 | Related SOC 2 themes (CC7.1) — map in your crosswalk; not identical requirements. |
Primary sources
- ISO/IEC 27001:2022 Annex A: ISO/IEC 27001:2022 Annex A (A.7.13)
Frequently Asked Questions
Yes as inherited control — document shared responsibility.
No — that is supplier security (A.5.19–A.5.21); A.7.13 is physical/equipment maintenance.
Use approved vendors, remove disks or wipe before shipping.
Even without owned data centers, equipment maintenance still applies to how you operate endpoints, IdP, cloud consoles, and vendor services in scope. Exclude controls in the SoA only with a documented, risk-based rationale.
Start with maintenance procedure, assign a named control owner, and retain dated samples from your ticketing or GRC system — not one-off screenshots assembled before audit fieldwork.