Skip to content
compliancebase
ISO 27001A.8 — Capacity management

A.8.6

Capacity management

ISO 27001 · ISO/IEC 27001:2022 · Last verified August 2026

Objective

Monitor and adjust resource use to meet current and future capacity requirements.

Points of focus

  • Define capacity metrics
  • Alert on thresholds
  • Plan for growth and launches
  • Test scaling regularly

Implementation notes

Instrument CPU, memory, storage, queue depth, and error budgets. Autoscale stateless tiers. Run load tests before major launches. Document scale limits of managed services you depend on. Assign a named owner in the SoA, tie operating evidence to capacity/monitoring dashboards, and sample the control during internal audit before Stage 2 fieldwork.

Audit tip: Show alerts and one capacity-related change or postmortem. Demonstrate autoscaling configuration.

Evidence auditors typically request:

  • Capacity/monitoring dashboards
  • Autoscaling policies
  • Load test reports
  • Incident tickets from capacity events

Common gaps

  • No DB connection limits
  • Silent disk full on logging volume
  • Marketing launch without load test

Cross-Framework Mapping

FrameworkRequirementImplementation note
ISO 27001A.8.6This control
SOC 2A1.1, A1.2Related SOC 2 themes (A1.1, A1.2) — map in your crosswalk; not identical requirements.

Primary sources

Frequently Asked Questions

Include SaaS dependencies — email sending limits, API rate limits, warehouse slots.

Before major releases and periodically for critical paths.

A.8.14 is redundancy architecture; A.8.6 is ongoing capacity monitoring and planning.

Even without owned data centers, capacity management still applies to how you operate endpoints, IdP, cloud consoles, and vendor services in scope. Exclude controls in the SoA only with a documented, risk-based rationale.

Start with capacity/monitoring dashboards, assign a named control owner, and retain dated samples from your ticketing or GRC system — not one-off screenshots assembled before audit fieldwork.

Framework versions referenced in this page:

  • ISO/IEC 27001ISO/IEC 27001:2022

Last verified: August 2026 · Primary sources linked above