A.8.6 Capacity management
Monitor and tune resource use against current and expected capacity needs.
12
artefacts
6
held by a system
1
at each review
easy
to go live
SIEM / log platform
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Cpu memory usage dashboard · Cloud console / configuration management
- Network bandwidth utilization log · SIEM / log platform
- Scenario simulation results · Document repository
- Performance tuning log · SIEM / log platform
- Resource scaling change log · SIEM / log platform
- Optimization task ticket 4567 · SIEM / log platform
periodic reviewEvidence produced at each review
- Quarterly capacity review.pptx · Cloud console / configuration management
governing documentDocuments that govern the control
- Annual capacity plan · Policy repository / GRC workspace
- Capacity gap analysis · Policy repository / GRC workspace
- Storage consumption report · Policy repository / GRC workspace
- Projected load model v2.1 · Document repository
- Capacity forecast assumptions doc · Policy repository / GRC workspace
First move
Automate the pull from your SIEM / log platform. Retention and alert rules exported from the SIEM; review evidence is the closed-alert record with reviewer and time.
Common gaps auditors find
- relying on manual spreadsheets only
- no regular review schedule
- failure to link forecasts with business growth plans
- ignoring seasonal usage patterns
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetA.8.5 Secure authentication · A.8.7 Protection against malware