ISO 27001 Annex A 7.13 Equipment Maintenance requires regular hardware maintenance to keep equipment safe and working well. Organisations follow clear service plans to protect data and prevent system downtime.
Table of contents
Key Takeaways
- Follow service schedules: Perform routine hardware maintenance according to vendor guides and internal service timelines.
- Document maintenance logs: Record all repairs, inspections, and servicing details in a central asset tracking system.
- Use authorized repairers: Ensure only qualified technical staff or approved vendor contractors carry out equipment repairs.
- Clear data before off-site repairs: Remove or encrypt sensitive files before sending hardware off-site for external servicing.
- Verify gear after repairs: Check hardware integrity and run security tests before returning repaired equipment to active use.
- Control physical access: Escort external service engineers while they work on sensitive equipment inside company premises.
- Monitor environmental controls: Inspect support hardware like power units and cooling systems to prevent unexpected outages.
- Track asset warranties: Maintain active support contracts and warranty records to ensure rapid hardware fixes when faults occur.
How to Implement ISO 27001 Annex A 7.13
- List all hardware assets: Record every physical equipment asset in a central inventory register.
- Link vendor service guides: Attach official maintenance guides directly to each asset record for easy access.
- Set recurring service tasks: Build automated schedule alerts to remind teams when hardware checks are due.
- Assign clear ownership: Name specific staff members to manage internal checks and oversee vendor service engineers.
- Log every repair action: Keep full records of all inspections, repairs, and service work in a central knowledge base.
- Review maintenance performance: Check service completion rates during quarterly management review meetings.
- Wipe data before repairs: Remove or lock sensitive files before sending hardware off site for servicing.
- Verify gear after service: Test equipment safety and functionality before returning repaired units to live use.
- Supervise external engineers: Escort vendor contractors while they perform on site hardware repairs.
How to Audit ISO 27001 Annex A 7.13
- Inspect central asset logs: Check equipment registers to confirm all hardware assets link to clear service plans.
- Verify maintenance records: Sample completed service logs to prove routine maintenance matches vendor schedules.
- Review repair sign-offs: Check repair tickets to verify that qualified staff or approved vendors approved all work.
- Check off-site repair logs: Verify that sensitive data was wiped or encrypted before sending hardware off site.
- Inspect physical equipment: Conduct site walks to check that hardware is clean, working well, and physically secure.
- Verify post-repair tests: Check records showing safety and function tests were run before returning gear to live use.
- Audit vendor service checks: Review contracts and safety credentials for external repair partners to ensure secure handling.
- Check visitor escort logs: Verify that external service engineers were escorted while working in sensitive company areas.
- Review power and cooling checks: Inspect maintenance logs for support hardware like backup power units and cooling tools.
- Check warranty status logs: Confirm that active support agreements are kept up to date to ensure rapid equipment repairs.
- Verify alert tracking systems: Test automated schedule alerts to ensure upcoming maintenance tasks trigger on time.
- Review management reports: Inspect quarterly review notes to prove leaders monitor maintenance pass rates regularly.
- Audit spare parts inventories: Check stock records for critical backup parts to ensure fast hardware recovery during failures.
- Verify emergency shutdown plans: Review safety plans to ensure staff can shut down failing equipment safely without losing data.
Audit Evidence Checklist
- Maintenance policy document history: Keep clear document change logs showing historical versions of your hardware service policy.
- Completed service logs: Supply detailed service sheets showing maintenance dates, completed work steps, and engineer names.
- Fault resolution tickets: Provide tracking tickets that show full resolution steps for all reported hardware faults.
- Signed contractor reports: Store signed work reports from approved external service engineers in your central repository.
- Management review minutes: Keep meeting notes that record executive decisions on hardware lifecycles and repair budgets.
- Data sanitisation logs: Provide proof of data erasure or encryption before hardware was sent off site for external servicing.
- Visitor access logs: Supply signed visitor records showing external service engineers were escorted inside secure areas.
- Post-repair test certificates: Show safety and function check receipts completed before returning repaired gear to live use.
What to Teach Employees
- Report hardware faults fast: Teach staff to log unusual sounds, overheating, or system errors right away so technical teams can fix issues early.
- Follow manufacturer rules: Instruct employees to use and care for hardware according to official vendor guidelines to stop accidental damage.
- Keep work areas clean: Remind staff to keep food, drinks, dust, and liquids away from laptops, servers, and power gear.
- Allow scheduled service checks: Train users to hand over devices promptly when routine maintenance or hardware checks are due.
- Never do DIY repairs: Instruct workers never to open, fix, or modify company hardware themselves instead of using approved technicians.
- Protect data before off-site repairs: Remind staff to back up and encrypt sensitive files before handing devices over for off-site servicing.
- Escort third-party engineers: Teach office workers to check vendor IDs and escort external service technicians while they work on site.
- Protect power and cables: Remind employees to avoid overloading power sockets and keep cables tidy to prevent power trips or fires.
- Protect portable gear in transit: Train staff to use padded bags and safe carrying habits when moving hardware between sites.
- Verify gear after repairs: Teach users to check that repaired devices work correctly and securely before resuming normal daily tasks.
- Report environmental alerts: Instruct workers to report cooling failures or water leaks near hardware rooms immediately.
- Know emergency shutdown steps: Train key staff on safe emergency shutdown steps to protect hardware during power or facility failures.
- Report missing maintenance tags: Teach staff to check that physical service tags on hardware are up to date and report expired checks.
- Understand maintenance risks: Train employees on how unserviced hardware leads to data loss, unexpected downtime, and security breaches.
Common Implementation Challenges
- Missing maintenance logs: Teams fix hardware faults but forget to record the work done. Keep a central register that logs every service and repair action.
- Skipping vendor service schedules: Staff ignore routine maintenance tasks due to heavy daily workloads. Build automated schedule alerts to enforce regular equipment checks.
- Unprotected data on off-site repairs: Hardware is sent to third-party repair shops with sensitive files left intact. Require staff to wipe or encrypt all drives before off-site shipping.
- Unsupervised vendor contractors: External technicians carry out site repairs without staff oversight. Escort all external service engineers while they work on company premises.
- Unperformed post-repair tests: Repaired devices return straight to live use without security or safety testing. Require formal test checks before re-issuing serviced hardware.
- Neglecting support hardware: Teams service primary servers but ignore backup power units and cooling tools. Include all supporting facility hardware in your maintenance plan.
- Remote staff delaying routine checks: Remote workers skip hardware checks because shipping gear takes time. Send loaner units or use local certified engineers for remote servicing.
- Lapsed warranties and support contracts: Support agreements expire unnoticed, causing long delays when hardware breaks. Track warranty renewal dates inside your main asset register.
- Uncontrolled DIY hardware fixes: Well-meaning staff try to fix broken gear themselves and void support rules. Train staff to report all hardware faults directly to approved teams.
- Lack of critical spare parts: Faulty hardware sits idle for days while waiting for replacement components. Keep a stock of key spare parts to speed up emergency repairs.
- Vague maintenance guidelines: Employees misuse equipment because care rules are too complex or unclear. Write short maintenance steps so all workers understand their duties.
- Unmonitored environmental controls: Server rooms overheat or suffer power trips due to poor room checks. Set up environmental alerts to warn teams of temperature or power shifts.
How to Measure Effectiveness (KPIs)
- Scheduled maintenance completion rate: Measure the percentage of planned service checks completed on time across all hardware.
- Unplanned hardware downtime: Track total operational hours lost due to unexpected equipment failures or hardware faults.
- Average repair response time: Measure the average time taken from reporting a hardware fault to starting active repair work.
- Maintenance log accuracy rate: Track the proportion of serviced assets that have full, up-to-date repair records in your central register.
- Off-site data sanitisation pass rate: Measure the percentage of devices successfully wiped or encrypted before leaving site for repairs.
- Post-repair testing success rate: Track the percentage of repaired devices that pass formal security and function checks before returning to live use.
- Vendor service compliance score: Measure the pass rate during regular checks of external repair partners and support contractors.
- Support contract coverage rate: Track the percentage of critical hardware assets covered by active support agreements and warranties.
- Repeat fault rate: Monitor the proportion of hardware units that suffer the same technical fault within thirty days of repair.
- Escorted contractor compliance rate: Track the percentage of external service engineer visits that have signed visitor escort logs.
- Support hardware check rate: Measure completion rates for routine maintenance on backup power units and cooling systems.
- Maintenance audit finding count: Monitor the number of compliance issues flagged during internal reviews of hardware service logs.
Relational Mapping
ISO 27001 Annex A 7.13 connects to several core ISO 27001 requirements:
- ISO 27001 Clause 8.1 (Operational Planning): Directs the scheduling of maintenance.
- ISO 27001 Annex A 5.9 (Inventory of Assets): Provides the list of equipment to maintain.
- ISO 27001 Annex A 7.11 (Supporting Utilities): Covers the maintenance of power and cooling.


