SekitCrosswalk
ISO/IEC 27001:2022 · derived mapping target

A.8.6Capacity management

Monitor and tune the capacity of your resources, such as storage, compute and bandwidth, to meet current and future needs and avoid availability problems.

Mapped from the Sekit CSF

The Sekit controls that cover this requirement, lens by lens.

NIST CSF 2.0 counterparts

Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.

Evidence that proves this control

What an auditor, or Sekit's evidence engine, asks for.

Availability and capacity management
How the company ensures its critical services are available as expected, plans their capacity, and prevents problems from recurring.
From the Sekit evidence catalog

In practice

Capacity management usually means someone gets an alert when a disk fills up, not a forecast that prevented it. An SME with cloud infrastructure can point to auto-scaling rules for the main application, but the database behind it has no growth plan and gets resized reactively after a slowdown. Uptime monitoring exists and pages the on-call engineer, but nobody reviews utilization trends monthly to see the next constraint coming, so scaling stays an emergency response rather than a plan. Reliability targets sit in a document that nobody has opened since the quarter it was written.

Common gaps

Auto-scaling is configured for the application tier, but the database has no capacity plan and is resized only after performance degrades.
Uptime is monitored and alerts fire on outages, but nobody reviews utilization trends to anticipate the next bottleneck before it causes one.
Reliability targets exist in a document but are not tracked as error budgets that genuinely influence sprint planning decisions.

Questions your auditor will ask

How does the company know a service is running out of capacity before it fails?
Monitoring tracks resource utilization against agreed thresholds and warns the team, or triggers automatic scaling, before the constraint causes an outage.
Is capacity planning reactive or does it account for growth?
The company documents how it plans computing, storage and connectivity capacity for both current operations and expected growth.
What tells the team a critical service has degraded?
Automated uptime monitoring checks every critical service against its target and alerts the responsible person the moment it degrades or fails.

Where regulation demands it

NIS2 Article 21 links resilience obligations to redundancy and backup management (4.2), which capacity planning underpins.
ENS op.pl.4 requires explicit capacity sizing and management, the direct Spanish-framework counterpart to A.8.6.

Related controls

Via the shared Sekit CSF topic, not the framework's own index.

Ask Sekura: “What evidence proves A.8.6?”
Also via MCP, free with account