A.8.6 Capacity management
- Andy Systems
- ISMS Guides
A.8.6 Capacity Management would include:
-
Capacity Planning Documentation: Evidence of capacity planning documentation that outlines the organization's capacity requirements, forecasts future needs, and ensures sufficient resources are available to meet demands.
-
Resource Monitoring Tools: Documentation of tools and systems used to monitor resource utilization, such as CPU, memory, storage, and network bandwidth, to identify trends and potential capacity issues.
-
Incident Reports: Records of any capacity-related incidents, such as performance degradation or service interruptions, along with the actions taken to resolve these incidents.
-
Capacity Thresholds: Documentation of established capacity thresholds and performance targets to proactively manage resource utilization and prevent service degradation.
-
Performance Testing Results: Evidence of performance testing results for critical systems and applications to assess their capacity under different scenarios and identify potential bottlenecks.
-
Scalability Measures: Documentation of scalability measures taken to ensure that systems and infrastructure can easily adapt to increased demands and growth.
-
Capacity Expansion Plans: Evidence of plans and procedures in place for capacity expansion, including hardware upgrades, cloud resources provisioning, and workload balancing.
-
SLA Compliance: Records of service level agreement (SLA) compliance regarding capacity-related metrics and performance targets.
-
Incident Response Procedures: Documentation of incident response procedures specific to capacity-related incidents, outlining escalation paths and resolution strategies.
-
Regular Capacity Reviews: Evidence of regular reviews of capacity requirements and performance metrics to proactively identify potential capacity issues.
-
Business Continuity Planning: Integration of capacity management into the organization's business continuity plans to ensure continued service availability during peak demand or resource shortages.
-
Change Management Processes: Documentation of change management processes that include capacity considerations for any system or infrastructure changes.
As an auditor, I would review these pieces of evidence to assess the organization's capacity management practices, ensuring that they have a well-defined capacity management strategy in place to meet current and future business needs while maintaining optimal performance and avoiding capacity-related incidents.