EvidenceSheet

8.6 Capacity management

Requires resource consumption to be monitored, and capacity to be adjusted so it matches both current demand and what is expected.

5
artefacts
2
held by a system
2
at each review
moderate
to go live
SIEM / log platform
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

  • Monitoring evidence for resource consumption across compute, storage, network, licence and, where relevant, personnel capacity · SIEM / log platform
  • Evidence capacity is considered for security functions too, such as log storage and detection processing · SIEM / log platform

periodic reviewEvidence produced at each review

  • Capacity forecasts based on trend and on planned business change, with the review cycle · Cloud console / configuration management
  • Records of capacity being adjusted as a result, showing the control produces action · Cloud console / configuration management

governing documentDocuments that govern the control

  • Defined thresholds and alerting on approaching capacity limits · Policy repository / GRC workspace

First move

Start with the 2 of 5 artefacts that already live in a system (SIEM / log platform); keep the periodic reviews but log each one as a dated record with a named reviewer.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

8.5 Secure authentication · 8.7 Protection against malware