8.6 Capacity management
Requires resource consumption to be monitored, and capacity to be adjusted so it matches both current demand and what is expected.
5
artefacts
2
held by a system
2
at each review
moderate
to go live
SIEM / log platform
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Monitoring evidence for resource consumption across compute, storage, network, licence and, where relevant, personnel capacity · SIEM / log platform
- Evidence capacity is considered for security functions too, such as log storage and detection processing · SIEM / log platform
periodic reviewEvidence produced at each review
- Capacity forecasts based on trend and on planned business change, with the review cycle · Cloud console / configuration management
- Records of capacity being adjusted as a result, showing the control produces action · Cloud console / configuration management
governing documentDocuments that govern the control
- Defined thresholds and alerting on approaching capacity limits · Policy repository / GRC workspace
First move
Start with the 2 of 5 artefacts that already live in a system (SIEM / log platform); keep the periodic reviews but log each one as a dated record with a named reviewer.
Common gaps auditors find
- Monitoring in place with no thresholds, so consumption is visible only after the outage
- Forecasting based on historical trend alone, ignoring known business change such as a product launch or acquisition
- Log and monitoring storage overflowing, silently dropping the security evidence the organisation depends on
- Cloud capacity assumed elastic, ignoring quota limits and cost controls that behave exactly like capacity limits
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheet