Skip to main content
Category: Technical Security Controls

Utilities Protection

Also known as: Underground Utility Damage Prevention, Call Before You Dig, 811
Simply put

Utilities Protection refers to practices and programs designed to prevent damage to underground utility lines during excavation and digging work. In many U.S. jurisdictions, this involves contacting an 811 service before digging so that the locations of buried utilities can be marked, helping protect essential services and public safety. On-site programs may also send inspectors to job sites to verify that excavators follow safe digging practices.

Formal definition

Utilities Protection encompasses the coordinated processes, notification systems, and on-site controls used to prevent damage to underground infrastructure during excavation. Typically it centers on one-call notification services (commonly reached by dialing 811 in the United States), which coordinate the marking of buried utility lines prior to digging, as reflected in state and regional programs such as Georgia 811 and Ohio 811. On-site utility protection programs may extend this by dispatching knowledgeable inspectors to job sites to ensure excavators comply with safe digging laws and best practices. The specific requirements, program structures, and enforcement mechanisms vary by jurisdiction and provider, and this domain concerns physical infrastructure damage prevention rather than information security controls under frameworks such as SOC 2 or ISO/IEC 27001.

Why it matters

Utilities Protection addresses a distinct category of physical risk: damage to buried infrastructure such as gas, electric, water, and telecommunications lines during excavation. Striking an underground utility line can interrupt essential services, create safety hazards for workers and the public, and disrupt operations for a wide area beyond the immediate dig site. Because these lines are not visible from the surface, the location of buried utilities must be established before digging begins, which is the core purpose of one-call notification services reached by dialing 811 in many U.S. jurisdictions.

For organizations and homeowners, engaging with utilities protection practices is often the primary way to verify that it is safe to dig in a given location. Programs such as Georgia 811 operate as nonprofit corporations dedicated to preventing damage to underground utilities and promoting public safety, and state utility commissions describe calling 811 before digging as the only reliable way to confirm safe excavation. Preventing damage protects a home's or facility's essential utilities and helps avoid the dangers associated with striking active underground lines.

It is worth noting that this domain concerns physical infrastructure damage prevention and is separate from information security compliance frameworks such as SOC 2 or ISO/IEC 27001. The practices, requirements, and enforcement mechanisms vary by jurisdiction and provider, so specific obligations depend on local law and the applicable one-call program.

Who it's relevant to

Excavation contractors and construction crews
Contractors performing digging work rely on one-call services to establish the location of buried utilities before breaking ground. Following safe digging practices and honoring utility markings helps protect crews and prevents service disruptions. On-site inspectors may verify compliance with safe digging laws depending on the program.
Homeowners planning digging projects
Homeowners undertaking landscaping, fencing, or other projects that involve digging can use 811 services to learn where it is safe to dig. Knowing the location of buried lines protects a home's essential utilities and helps prevent the dangers of damaging active underground infrastructure.
Utility owners and operators
Owners of underground gas, electric, water, and telecommunications infrastructure participate in one-call systems and marking processes to reduce the risk of damage to their assets and to help maintain continuity of essential services.
State regulators and one-call program operators
State utility commissions and nonprofit one-call corporations such as Georgia 811 and Ohio 811 administer notification services, promote public safety, and, in some cases, coordinate enforcement or on-site inspection programs. Their specific roles and requirements vary by jurisdiction.

Inside Utilities Protection

Supporting Utilities Coverage
Utilities Protection addresses the supporting utilities, such as electricity, telecommunications, water supply, gas, heating/ventilation, and air conditioning, that underpin the operation of information processing facilities. In ISO/IEC 27001 this maps to an Annex A reference control; in the 2022 revision the Annex A controls are organized into four themes (physical being one of them), and the applicability of this control is determined through the Statement of Applicability informed by risk assessment rather than being automatically mandatory.
Adequacy and Capacity Considerations
The control typically concerns ensuring supporting utilities are adequate for the systems they support and capable of meeting anticipated demand. What constitutes 'adequate' depends on the organization's scope, risk assessment, and the criticality of the facilities involved, so specific capacity requirements vary by engagement.
Redundancy and Resilience Measures
In most implementations, utilities protection may involve redundancy arrangements such as backup power sources, uninterruptible power supplies, or alternative supply routes. The extent of redundancy is a scoping and risk-driven decision rather than a fixed requirement, and it should be evaluated against the availability needs of the covered systems.
Monitoring and Maintenance
Utilities protection typically includes inspection, testing, and maintenance of supporting utilities and any protective equipment. Where relevant to a SOC 2 examination, evidence of such activities may support controls under the Availability category of the Trust Services Criteria, though Availability is optional and only in scope when the organization selects it.
Relationship to Trust Services Criteria (SOC 2)
In a SOC 2 context, utility-related controls generally relate to the Common Criteria (Security, the only required category) and, depending on scope, the Availability category. It is important not to conflate the Trust Services Criteria with ISO 27001 Annex A controls; they are distinct control sets from distinct frameworks that can be partially mapped but are not equivalent.

Common questions

Answers to the questions practitioners most commonly ask about Utilities Protection.

Is utilities protection an ISO 27001 requirement that I must certify against?
Utilities protection appears as a reference control in ISO/IEC 27001 Annex A, not as a certifiable clause requirement. The certifiable requirements sit in clauses 4 through 10 (the ISMS requirements). Annex A controls, including those addressing supporting utilities, are selected through your risk assessment and documented in the Statement of Applicability. This means an organization may justifiably exclude a given utilities control if its risk assessment supports doing so, rather than treating it as universally mandatory. The specific control identifier and grouping depend on which edition of the standard applies, since Annex A was restructured in the 2022 revision.
Does a SOC 2 report cover utilities protection the same way ISO 27001 Annex A does?
Not in the same structured way. SOC 2 is an attestation examination performed by a licensed CPA firm under the AICPA SSAE 18 standard and is evaluated against the Trust Services Criteria, not against ISO 27001 Annex A controls. Utilities-related considerations may surface within the Common Criteria or, depending on scope, the Availability category, but SOC 2 does not maintain a discrete Annex A-style control catalog. Mapping between the two frameworks is possible but partial, so a control satisfying utilities protection under ISO 27001 does not automatically satisfy any specific Trust Services Criterion, and vice versa.
How should utilities protection be handled when our infrastructure runs in a cloud provider's data center?
In most engagements where infrastructure is hosted by a cloud or colocation provider, the physical utilities controls typically fall to that provider, and the customer's responsibility shifts toward vendor management, obtaining and reviewing the provider's own attestation or certification, and confirming the shared-responsibility boundary. Auditors and certification bodies generally expect the boundary to be documented and evidenced through the provider's reports rather than through controls you operate directly. The exact expectations depend on the scope of your ISMS or SOC 2 examination.
What kinds of evidence typically demonstrate utilities protection during an assessment?
Evidence commonly includes documented procedures, maintenance and inspection records for supporting utilities, and results of any testing performed on protective measures, depending on scope. For a SOC 2 Type II examination, which assesses operating effectiveness over a defined review period, expect the auditor to look for evidence spanning that period rather than a single point in time; a Type I engagement assesses suitability of design at a point in time and typically relies more on design documentation. The precise evidence set is determined by the auditor or certification body and the scope of the engagement.
How do I decide whether to include utilities protection in my Statement of Applicability?
The inclusion or exclusion of any Annex A control, including utilities protection, is typically driven by your risk assessment. Where your risk assessment identifies exposure related to supporting utilities relevant to your defined ISMS scope, the control would generally be marked as applicable with a justification. Where the risk is addressed by a third party or falls outside your ISMS scope, you can document that rationale instead. The Statement of Applicability should record the decision and its basis for each control so the certification body can review it.
Does having utilities protection controls guarantee my systems will stay available?
No. Neither a SOC 2 report nor an ISO 27001 certificate guarantees freedom from outages or breaches. A SOC 2 report attests only to the controls and period covered, and an ISO 27001 certificate covers only the defined scope of the ISMS. Utilities protection controls are intended to reduce, not eliminate, risks associated with supporting utilities, and their effectiveness depends on how they are designed, operated, and maintained within your specific environment and scope.

Common misconceptions

Implementing utilities protection controls means a facility is guaranteed against outages or breaches.
No control provides an absolute guarantee. A SOC 2 report attests only to the controls and period covered and does not guarantee freedom from disruptions or breaches, and an ISO 27001 certificate covers only the defined scope of the ISMS. Utilities protection reduces risk but does not eliminate it.
The utilities protection control is mandatory for every ISO 27001 certification.
Annex A controls are reference controls selected via the Statement of Applicability and informed by the risk assessment. Whether this control is included and how it is implemented depends on scope and risk, so it should not be treated as universally mandatory. The certifiable ISMS requirements themselves reside in clauses 4 through 10.
Meeting utilities protection expectations under SOC 2 automatically satisfies the equivalent ISO 27001 control.
Mapping between SOC 2 and ISO 27001 is possible but partial. Satisfying utility-related controls in one framework does not automatically satisfy the other, because the frameworks, their criteria, and their assessment approaches differ. SOC 2 is a CPA-performed attestation examination; ISO 27001 is a certification issued by an accredited certification body.

Best practices

Base the selection and design of utilities protection controls on a documented risk assessment, and record the decision in the Statement of Applicability when working within an ISO 27001 ISMS.
Match redundancy and capacity measures to the criticality and availability needs of the systems supported, recognizing that appropriate levels vary by scope rather than following a fixed standard.
Establish and retain evidence of regular inspection, testing, and maintenance of supporting utilities and protective equipment, since such evidence may support both ISO 27001 and, where in scope, SOC 2 Availability controls.
When pursuing SOC 2, confirm whether the optional Availability category is within the agreed scope before relying on utility controls to demonstrate that criterion, and keep the Trust Services Criteria distinct from ISO 27001 Annex A controls.
Specify the ISO 27001 version when referencing Annex A control structure, as the 2022 revision reorganized controls into four themes and changed the total count relative to the 2013 edition.
Clearly define and communicate the boundaries of what utilities protection covers, noting that neither a SOC 2 report nor an ISO 27001 certificate guarantees uninterrupted service outside the assessed controls and defined scope.