Answers to the questions practitioners most commonly ask about Capacity Management.
Is capacity management a mandatory control that every SOC 2 and ISO 27001 organization must implement?
Not universally. In SOC 2, capacity-related controls typically become relevant when the Availability category is included in scope, which is optional and selected based on scoping decisions; the Security (Common Criteria) category is the only required one. In ISO 27001, capacity management appears among the Annex A reference controls, which are selected via the Statement of Applicability and informed by the risk assessment rather than imposed as blanket mandates. Whether and how you address capacity depends on scope, applicable criteria, and your risk assessment.
Does having capacity management controls in place guarantee the system will never experience an outage or capacity failure?
No. A SOC 2 report attests only to the controls and the period covered and does not guarantee freedom from incidents, including capacity-related outages. Similarly, an ISO 27001 certificate confirms that a management system meeting the standard's requirements exists within the defined scope, not that failures cannot occur. Capacity management is intended to reduce the likelihood and impact of such events within the boundaries assessed, not to provide an absolute assurance.
How is capacity management typically evidenced in a SOC 2 Type II examination?
In most engagements where Availability is in scope, an auditor examines evidence that capacity-related controls were both suitably designed and operating effectively over the defined review period. This can include monitoring records, resource-utilization reports, forecasting or planning documentation, and evidence of action taken when thresholds were reached. The exact evidence and period length vary depending on scope and the auditor's approach, since a Type II assesses operating effectiveness over time rather than at a single point.
Where does capacity management fit within an ISO 27001 ISMS?
The certifiable ISMS requirements sit in clauses 4 through 10, and capacity management would typically be operationalized through those requirements, such as planning, operational control, and monitoring, while the specific capacity control is drawn from Annex A reference controls. Its inclusion is documented in the Statement of Applicability and justified by the risk assessment. Depending on the version of the standard referenced, the placement and grouping of the Annex A control differs, so specify the edition when citing structure.
How can an organization align its capacity management practices across both SOC 2 and ISO 27001?
Mapping between the frameworks is possible but only partial, so a shared set of monitoring, forecasting, and remediation practices can often provide evidence relevant to both. However, satisfying one framework does not automatically satisfy the other: SOC 2 evaluates capacity against the Availability Trust Services Criteria when in scope, while ISO 27001 evaluates it through ISMS requirements and selected Annex A controls. Organizations typically maintain a common process while addressing the distinct evidentiary and scoping expectations of each.
What should be considered out of scope when documenting capacity management?
The boundaries depend on what was defined in the engagement or ISMS scope. A SOC 2 report addresses only the systems, controls, and period covered, so capacity practices for systems outside that scope are not represented. An ISO 27001 certificate similarly covers only the defined ISMS scope. It is also worth distinguishing capacity management from related but separate concerns and standards, such as SOC 1's focus on financial reporting controls, so stakeholders do not assume broader coverage than the defined scope provides.