Capacity management is a documented process for monitoring resource use. It ensures system availability by predicting future requirements. You must integrate this into business-as-usual tools. Use SharePoint to store capacity plans. Monitor metrics within your internal technical wikis to maintain service levels. This approach avoids disconnected security silos.
Table of contents
Key Takeaways
- Establish Formal Capacity Management Plans: Create clear operational policies to monitor system resource use and forecast future capacity requirements.
- Monitor System Resource Usage continuously: Track CPU usage, memory allocation, storage limits, and network bandwidth to prevent performance bottlenecks.
- Forecast Future Capacity Requirements: Analyze usage trends and business growth projections to scale infrastructure before capacity limits are reached.
- Set Automated Resource Threshold Alerts: Configure early warning alerts when system resource usage exceeds target thresholds to enable proactive capacity adjustments.
- Maintain Capacity Records in Central Repositories: Document system health metrics and capacity plans in central document stores to maintain service level agreements.
- Perform Regular Infrastructure Scaling Reviews: Review hardware, cloud resources, and software licenses regularly to ensure systems meet operational demand.
- Integrate Capacity Management with Change Control: Align resource planning with system change management workflows to prevent unexpected performance issues during upgrades.
- Conduct Periodic Redundancy and Failover Testing: Test backup capacity and failover systems to confirm operational stability during high demand or system failures.
How to Implement ISO 27001 Annex A 8.6
- Define System Resource Requirements: Identify and document processing power, memory, storage, and network bandwidth needs for all critical business systems.
- Maintain Centralised Asset Limits: Store system capacity thresholds and resource specifications in central document repositories for clear operational tracking.
- Set Clear Resource Usage Thresholds: Establish performance baselines and early warning alert levels for system storage, memory, and network usage.
- Monitor Resource Usage Continuously: Track system performance and utilisation trends regularly using existing internal monitoring and logging processes.
- Review Performance Trends in Management Meetings: Evaluate capacity trends, usage growth, and potential bottlenecks during monthly operational reviews.
- Record Capacity Decisions and Action Minutes: Document all capacity review findings, risk assessments, and growth forecasts in official management logs.
- Manage Capacity Upgrades via Formal Workflows: Assign and track infrastructure expansion tasks, license updates, and hardware upgrades through standard task systems.
- Forecast Future Capacity and Scaling Needs: Predict future system demands based on business growth projections, user onboarding, and data expansion rates.
- Train Teams on Capacity Reporting Steps: Educate technical leads and system administrators on how to report capacity risks and request resource expansion early.
How to Audit ISO 27001 Annex A 8.6
- Inspect Capacity Policies and Baselines: Review documented standards to verify clear baseline requirements exist for processing power, memory, storage space, and network bandwidth.
- Verify Monitoring and Alert Thresholds: Audit central monitoring systems to confirm automated alerts trigger before system resources reach critical limits.
- Check Demand Forecasting and Growth Projections: Review capacity planning reports to ensure system requirements are modeled against future business expansion and seasonal traffic spikes.
- Audit Automated Scaling and Resource Limits: Inspect system settings and account quotas to confirm auto-scaling rules expand resources safely within budget controls.
- Review Data Retention and Archival Rules: Check database and storage cleanup rules to confirm automated archiving prevents unexpected storage depletion.
- Verify Incident Logs and Root Cause Reviews: Sample recent system slowdowns or resource shortages to confirm teams completed post-incident reviews and updated limits.
- Check Third-Party Provider Capacity Limits: Review supplier contracts and service level agreements to ensure bandwidth, API rate limits, and service capacity meet business needs.
- Audit Stress and Performance Test Results: Inspect recent load testing records from major software updates to confirm systems stay stable during peak usage.
- Verify Redundancy and Failover Capacity: Confirm that backup infrastructure and failover systems have sufficient resource capacity to handle full operational loads during outages.
- Check Ongoing Management Review Minutes: Review regular management meeting records to confirm leadership tracks capacity metrics and approves expansion plans promptly.
Audit Evidence Checklist
- Documented Capacity Management Policy: Present an official capacity management policy stored in central document repositories with full version histories and management approvals.
- Management Capacity Review Minutes: Share regular management review records and meeting notes detailing discussions on resource trends, system limits, and growth plans.
- Defined System Resource Baselines: Provide documented performance thresholds and resource limits for processing power, memory, storage space, and network bandwidth.
- Resource Expansion Request Logs: Produce documented ticket histories and sign-off records showing formal approvals for ordering additional hardware, cloud resources, or licenses.
- Historical System Performance Logs: Supply historical utilization logs and performance reports showing ongoing monitoring of critical servers, databases, and network links.
- Resource Threshold Incident Logs: Provide incident response records showing how teams investigated and resolved alerts when system usage exceeded pre-set limits.
- Pre-Deployment Performance Test Evidence: Present load test results and stress test reports proving system capacity was verified before launching major software releases.
What to Teach Employees
- Understand Why Capacity Planning Matters: Teach technical and management staff how proactive resource planning prevents system outages, slow performance, and service delays.
- Spot Early Signs of Resource Stress: Train IT and operations teams to spot early warning signs like slow system response times, reduced memory, and high storage growth.
- Share Business Growth Plans Early: Show product leads how to give early notice to technical teams before product launches or campaigns that increase system traffic.
- Follow Good Data Storage Habits: Teach employees to delete old, unneeded files and follow company storage rules to prevent disk space exhaustion.
- Respond Quickly to Capacity Alerts: Show technical staff how to set up, track, and act on early warning alerts when system resource use grows too high.
- Manage System Scaling Responsibly: Teach administrators how automated system scaling works to balance smooth performance with budget limits and growth goals.
- Test System Performance Before Releases: Train development teams to test software under heavy loads in safe test areas before launching updates to users.
- Review Capacity Incidents to Improve: Show team leads how to review resource shortages after they happen so future planning models stay accurate.
- Locate Master Capacity Guidelines: Show employees where to find company capacity plans, resource limit policies, and upgrade request forms in central document stores.
Common Implementation Challenges
- Unpredictable Costs from Automated System Scaling: Relying on automatic system scaling without strict budget limits can cause huge bill spikes during sudden traffic surges.
- Siloed Business and Technical Planning: Marketing or sales teams launching big campaigns without informing IT leads to sudden system overload and service crashes.
- Alert Fatigue from Poor Monitoring Triggers: Setting resource alerts too low causes frequent false alarms, leading teams to miss real capacity warnings.
- Overlooking Storage and Database Growth: Focusing only on processor speed while ignoring log files and database size growth leads to sudden system lockups.
- Inaccurate System Load Testing: Testing software in small test areas that do not match real user volume creates a false sense of performance safety.
- Third-Party Rate Limits and Quotas: Overlooking external vendor service limits can slow down operations even when internal systems scale well.
- Accumulation of Unneeded and Old Files: Delaying automated file cleanup leads to rising storage costs and slow database response times over time.
- Complex Forecasting for Distributed Systems: Managing resource needs across interconnected service components can hide single points of failure that slow down whole systems.
- Lack of Routine Capacity Reviews: Failing to hold regular management reviews leads to reactive hardware purchases rather than planned resource upgrades.
How to Measure Effectiveness (KPIs)
- Capacity-Related Service Disruptions: Tracks the number and total duration of system outages or slow performance caused directly by resource exhaustion.
- Resource Threshold Breach Frequency: Measures how often system memory, processing power, or storage space exceeds pre-set alert levels.
- Capacity Forecast Accuracy Rate: Tracks the percentage difference between predicted resource growth and actual system usage over monthly or quarterly periods.
- Data Retention Policy Compliance Rate: Measures the percentage of databases and log files following automated cleanup and archiving rules to stop storage bloat.
- Automated Scaling Buffer Margin: Tracks the safety margin remaining between peak system traffic spikes and maximum system scaling limits.
- Pre-Release Load Testing Pass Rate: Measures the percentage of major software updates that pass peak load performance tests before going live.
- Third-Party Service Quota Compliance: Tracks how often system usage stays safely within external supplier bandwidth and service limits.
- On-Time Capacity Review Rate: Measures the percentage of scheduled management reviews completed to check resource trends and approve upgrade plans.
Related ISO 27001 Controls
ISO 27001 Annex A 8.6 relates to several core requirements:
- ISO 27001 Clause 8.1: Operational planning and control.
- ISO 27001 Annex A 5.9: Inventory of information and other assets.
- ISO 27001 Annex A 8.1: User endpoint device security.


