Skip to main content
Category: Technical Security Controls

Capacity Management

Also known as: Capacity Planning
Simply put

Capacity management is the practice of making sure an organization has enough of the right resources, such as IT infrastructure, systems, people, time, and budget, to meet both current and future demands. Its aim is to keep resources adequate and cost-effective, avoiding both shortages that disrupt service and waste from over-provisioning.

Formal definition

Capacity management refers to the tools, processes, strategies, and responsibilities used to ensure that IT and organizational resources are sufficient to satisfy current and anticipated business and data demands cost-effectively. In practice it encompasses forecasting future requirements, monitoring resource utilization across infrastructure, systems, personnel, and budget, and aligning available capacity with business needs. In a security compliance context, capacity management activities typically support control objectives related to availability, though the specific controls and evidence expected depend on the framework, scope, and applicable criteria of a given engagement.

Why it matters

Capacity management directly supports the availability of systems and services, which is a central concern in security compliance engagements. When resources such as IT infrastructure, systems, personnel, time, or budget fall short of demand, services can degrade or fail, disrupting the delivery of commitments an organization has made to its customers. Conversely, over-provisioning wastes resources and drives up costs, so effective capacity management seeks a balance between adequacy and cost-effectiveness.

Who it's relevant to

Compliance and GRC Managers
Those responsible for scoping engagements need to understand where capacity management fits. In SOC 2, it is relevant primarily when the optional Availability category is selected; in ISO 27001, it may be addressed through Annex A reference controls chosen via the Statement of Applicability. Understanding these boundaries helps ensure capacity-related controls are captured only where the applicable criteria and scope call for them.
IT Operations and Infrastructure Teams
These teams own the day-to-day work of forecasting demand, monitoring utilization across infrastructure, systems, personnel, and budget, and aligning resources to business needs. They are typically the source of the operational evidence that supports availability-related control objectives when those controls are in scope.
Auditors and Certification Bodies
CPA firms performing a SOC 2 examination assess capacity-related controls where Availability is within the scope of the report, evaluating design for a Type I and both design and operating effectiveness over the review period for a Type II. Accredited certification bodies assessing an ISO 27001 ISMS consider capacity-related reference controls where the Statement of Applicability includes them. In both cases, the evidence expected depends on scope and applicable criteria.
Security Engineers and Service Owners
Individuals accountable for service reliability rely on capacity management to help meet availability commitments and to avoid both service-disrupting shortages and costly over-provisioning. Their monitoring and planning practices often generate the artifacts examined when availability controls are in scope.

Inside Capacity Management

Capacity Planning
The forward-looking process of forecasting future resource demands (compute, storage, network, personnel) and provisioning to meet them, so that service performance and availability commitments can be sustained as usage grows.
Resource Monitoring
Ongoing observation of utilization metrics such as CPU, memory, storage consumption, and network throughput against defined thresholds to detect approaching limits before they affect service delivery.
Threshold and Alerting Configuration
Defined utilization levels that, when crossed, trigger notifications or automated responses, enabling teams to act before capacity is exhausted.
Demand Management
Techniques for understanding and, where possible, shaping resource demand, including scaling policies and workload prioritization, so that supply and demand remain aligned.
Relationship to Availability Criteria
In a SOC 2 examination, capacity management is most relevant where the Availability category is included in scope, as it supports the entity's ability to meet availability commitments; it is not a required focus where only the Security Common Criteria applies. Its treatment depends on the scope selected for the engagement.
Relationship to ISO 27001
Under ISO/IEC 27001, capacity considerations are typically addressed through Annex A reference controls selected via the Statement of Applicability and informed by risk assessment. The specific control designations and counts depend on the edition of the standard (for example, the 2013 version versus the restructured 2022 version), so the applicable reference should be identified by version.

Common questions

Answers to the questions practitioners most commonly ask about Capacity Management.

Is capacity management a mandatory control that every SOC 2 and ISO 27001 organization must implement?
Not universally. In SOC 2, capacity-related controls typically become relevant when the Availability category is included in scope, which is optional and selected based on scoping decisions; the Security (Common Criteria) category is the only required one. In ISO 27001, capacity management appears among the Annex A reference controls, which are selected via the Statement of Applicability and informed by the risk assessment rather than imposed as blanket mandates. Whether and how you address capacity depends on scope, applicable criteria, and your risk assessment.
Does having capacity management controls in place guarantee the system will never experience an outage or capacity failure?
No. A SOC 2 report attests only to the controls and the period covered and does not guarantee freedom from incidents, including capacity-related outages. Similarly, an ISO 27001 certificate confirms that a management system meeting the standard's requirements exists within the defined scope, not that failures cannot occur. Capacity management is intended to reduce the likelihood and impact of such events within the boundaries assessed, not to provide an absolute assurance.
How is capacity management typically evidenced in a SOC 2 Type II examination?
In most engagements where Availability is in scope, an auditor examines evidence that capacity-related controls were both suitably designed and operating effectively over the defined review period. This can include monitoring records, resource-utilization reports, forecasting or planning documentation, and evidence of action taken when thresholds were reached. The exact evidence and period length vary depending on scope and the auditor's approach, since a Type II assesses operating effectiveness over time rather than at a single point.
Where does capacity management fit within an ISO 27001 ISMS?
The certifiable ISMS requirements sit in clauses 4 through 10, and capacity management would typically be operationalized through those requirements, such as planning, operational control, and monitoring, while the specific capacity control is drawn from Annex A reference controls. Its inclusion is documented in the Statement of Applicability and justified by the risk assessment. Depending on the version of the standard referenced, the placement and grouping of the Annex A control differs, so specify the edition when citing structure.
How can an organization align its capacity management practices across both SOC 2 and ISO 27001?
Mapping between the frameworks is possible but only partial, so a shared set of monitoring, forecasting, and remediation practices can often provide evidence relevant to both. However, satisfying one framework does not automatically satisfy the other: SOC 2 evaluates capacity against the Availability Trust Services Criteria when in scope, while ISO 27001 evaluates it through ISMS requirements and selected Annex A controls. Organizations typically maintain a common process while addressing the distinct evidentiary and scoping expectations of each.
What should be considered out of scope when documenting capacity management?
The boundaries depend on what was defined in the engagement or ISMS scope. A SOC 2 report addresses only the systems, controls, and period covered, so capacity practices for systems outside that scope are not represented. An ISO 27001 certificate similarly covers only the defined ISMS scope. It is also worth distinguishing capacity management from related but separate concerns and standards, such as SOC 1's focus on financial reporting controls, so stakeholders do not assume broader coverage than the defined scope provides.

Common misconceptions

Capacity management is a mandatory control that every SOC 2 report must address.
Capacity management is most directly relevant when the optional Availability category is included in scope. Security (the Common Criteria) is the only required Trust Services Criteria category, so whether capacity management is examined depends on the scope selected for the engagement rather than being universally required.
Demonstrating capacity management in one framework automatically satisfies the other.
Mapping between SOC 2 and ISO 27001 is possible but only partial. Satisfying capacity-related expectations under the Trust Services Criteria does not automatically satisfy the ISO 27001 ISMS requirements or its selected Annex A reference controls, and vice versa; each is assessed on its own terms.
A clean SOC 2 report covering capacity management guarantees the service will never experience an outage or resource exhaustion.
A SOC 2 report attests only to the controls and the period covered by the examination and does not guarantee freedom from future incidents. It provides assurance about the suitability of design (Type I) or design and operating effectiveness over the review period (Type II), not an absolute promise of continuous availability.

Best practices

Confirm whether capacity management falls within your engagement scope, typically it is most relevant when the Availability category is selected for a SOC 2 examination, and document that scoping decision.
Establish and monitor utilization thresholds for key resources so that approaching limits are detected and addressed before they affect service commitments.
Retain evidence of capacity monitoring, forecasting, and remediation actions over the review period, since a SOC 2 Type II examination assesses operating effectiveness across the defined period rather than at a single point in time.
Where ISO 27001 applies, select and justify any capacity-related Annex A reference controls through the Statement of Applicability and risk assessment, citing the specific edition of the standard being used.
Avoid assuming that capacity evidence prepared for one framework fully satisfies the other; map controls deliberately and treat any overlap as partial.
Clearly document the boundaries of what capacity management covers, recognizing that a report or certificate attests only to the controls, scope, and period defined and does not guarantee against future resource exhaustion or outages.