A.7.11 Physical
Supporting utilities
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (20)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PE-11mostlyaligns with — Both controls address the need for reliable emergency power to sustain critical operations during utility failures.
- PE-11mostlycovers — A.7.11's requirement to protect against utility failures (explicitly including power) accounts for the bulk of PE-11's uninterruptible power supply mandate, but leaves a residual of specifics (e.g., exact ODP parameters for duration, testing, or alternate provisions) uncovered.
- PE-12mostlyaligns with — Both controls require emergency lighting to ensure safe operations and personnel movement when primary utilities are disrupted.
- PE-14mostlyaligns with — Both controls require ongoing monitoring, testing, and maintenance of environmental and utility systems that support information processing facilities.
- PE-9mostlyaligns with — Both controls require the organization to protect and maintain the power and utility infrastructure that supports information systems.
- PE-9mostlycovers — A.7.11's broad requirement to protect against utility failures (explicitly including power) accounts for the bulk of PE-9's narrower focus on safeguarding power equipment/cabling; a residual of PE-9's detailed implementation expectations for cabling routing and physical protections sits outside the high-level ISO statement.
- CP-8partialaligns with — Both controls require redundant or alternate utility feeds to maintain telecommunications and other essential services during outages.
- PE-15partialaligns with — Both controls address protection against utility-related hazards such as water damage by requiring safeguards and emergency shut-off mechanisms.
- CP-8covers — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PE-12covers — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PE-14covers — Assessed as NOT holding by the authoring instrument at v1.19-2026-08-23. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PE-15covers — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
Aligned NIST CSF 2.0 outcomes (20)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PR.IR-02mostlyaligns with — The ISO control's focus on maintaining and testing utility equipment directly supports protecting technology assets from environmental threats such as power or HVAC failures.
- PR.IR-03mostlyaligns with — Requiring redundant utility feeds, alarms, and emergency cut-offs implements mechanisms that sustain operations during adverse environmental or infrastructure conditions.
- DE.CM-02partialaligns with — Installing alarms and performing regular inspections of utility equipment contributes to monitoring the physical environment for conditions that could lead to adverse events.
- ID.AM-08partialaligns with — Managing utility-supporting equipment throughout its lifecycle through configuration, inspection, and testing aligns with the CSF outcome for lifecycle asset management.
- PR.IR-04partialaligns with — Regular capacity appraisals and multiple utility feeds help maintain adequate resource capacity to ensure availability of information processing facilities.
- DE.CM-02implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- ID.AM-08implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.IR-02implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.IR-03implements — A.7.11 operationalizes resilience by protecting against utility failures that would otherwise violate PR.IR-03 requirements in adverse situations; the link is within the resilience domain but the CSF outcome does not name utilities specifically.
- PR.IR-04implements — A.7.11's technical measures for utility continuity (power, cooling, comms, etc.) directly operationalize the resource-capacity outcome named in PR.IR-04
Related weaknesses / CWE (3)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-400nonemitigates — Regular capacity appraisal and redundant utility feeds reduce the likelihood that resource exhaustion or service interruption will occur due to single points of failure or uncontrolled growth.
- CWE-1384prevents — Ensures supporting utilities (power, HVAC) are protected, mitigating environmental-condition failures.
Mitigated MITRE ATT&CK techniques (63)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- T1485recovers — A.7.11 explicitly requires emergency lighting, communications, contact details, cut-off switches/valves near exits, and (via purpose) continuity against utility-driven operational interruption; this restores availability after a realized destruction event but only for the utility-failure slice of T1485, not the dominant malware-driven file overwrite or cloud object deletion vectors.
- T1490recovers — A.7.11 requires backup-capable utilities (power, comms, emergency lighting, cut-off switches) plus regular testing/alarms to keep recovery mechanisms available; this directly restores operational state after T1490 has disabled built-in recovery features, matching the cp-9 vs T1486 anchor, with the named remainder being cloud/IaaS snapshots and non-utility backups outside physical-facility scope.
- T1496.001detects — A.7.11 explicitly requires raising alarms to detect utility malfunctions (e.g. power/ventilation anomalies that would accompany sustained high compute load from hijacking), providing detection of the impact described in T1496.001; this is only a slice of the technique because the control is scoped to supporting utilities rather than general resource-consumption or process anomalies.
- T1496.002detects — A.7.11 requires raising alarms to detect utility malfunctions (e.g. network bandwidth exhaustion from hijacking) and regular inspection/testing of supporting equipment, which surfaces the availability impact but only for the named utility slice rather than the full technique (botnets, proxyjacking, scanning).
- T1498detects — A.7.11 explicitly requires raising alarms to detect utility malfunctions (e.g. power, ventilation, network-link outages), which surfaces some availability-impacting events that can realize or accompany a Network DoS, but the control is scoped to physical/supporting utilities and does not address detection of malicious traffic, bandwidth exhaustion, spoofing or botnet-driven DoS itself.
- T1498recovers — A.7.11 explicitly requires emergency lighting/communications, cut-off switches/valves near exits, recorded emergency contacts, and (via multiple feeds, alarms, and capacity appraisal) provisions that enable restoration of utility-dependent operations after a disruption such as network-bandwidth exhaustion from a Network DoS.
- T1498.001detects — A.7.11 explicitly requires raising alarms to detect utility malfunctions (e.g. network/telecom disruptions), which surfaces the availability impact of a direct network flood once it saturates supporting utilities, but this is only a narrow slice of the technique's full scope (botnet-driven packet floods, non-utility impacts, and pre-impact detection).
- T1499detects — A.7.11 explicitly requires raising alarms to detect utility malfunctions that can cause service interruption, which surfaces some endpoint DoS realized via resource exhaustion from supporting utilities (e.g. power, HVAC), but is silent on all other layers, techniques, and non-utility resource exhaustion described in T1499.
- T1499recovers — A.7.11 explicitly requires emergency lighting/communications, cut-off switches/valves near exits, recorded emergency contacts, and (via maintenance/alarms/multiple feeds) rapid restoration of supporting utilities whose failure would interrupt operations, which recovers availability after an endpoint DoS that exhausts or crashes resources via utility disruption; partial because most Endpoint DoS vectors (application-layer exhaustion, botnets, resource crashes) are unrelated to utilities.
- T1499.004detects — A.7.11 explicitly requires raising alarms to detect utility malfunctions that can cause operational interruption or DoS-like effects, which surfaces some exploitation-induced crashes (especially those affecting supporting utilities like power or HVAC), but does not address software vulnerability exploitation in applications or systems themselves.
- T1529recovers — A.7.11 explicitly requires emergency lighting/communications, cut-off switches/valves near exits, recorded emergency contacts, and (via utility redundancy, alarms, and maintenance) enables restoration of operations after a shutdown/reboot event that disrupts availability.
- T1561.001recovers — A.7.11 requires backup/recovery-capable supporting utilities (power, HVAC, comms) plus emergency lighting, cutoffs, and contacts to restore operations after utility-driven outages; while this can recover availability after a disk-wipe event that has already occurred, it does not address the wiped data itself and only partially overlaps the technique's availability impact.
- T1561.002recovers — A.7.11 explicitly requires backup/recovery-oriented measures (multiple diverse feeds, emergency lighting/comms, cut-off switches near exits, recorded emergency contacts) that enable restoration of operations after a supporting-utility outage caused by disk-structure wipe; the named remainder is that it does not itself restore wiped structures or data.
- T1578.003detects — A.7.11 explicitly requires raising alarms to detect utility malfunctions (and regular inspection/testing of supporting equipment), which surfaces anomalous deletion events that disrupt availability of cloud instances as a supporting utility in IaaS environments.
- T1578.003recovers — A.7.11 requires backup/recovery-capable utilities (power, comms, emergency lighting) and cut-off mechanisms that enable restoration of operations after a supporting-utility outage; the same outage-tolerant posture can restore a deleted cloud instance from snapshots or backups when the deletion is treated as a utility-like disruption, but the clause never addresses cloud-instance recoverability or forensic artifacts and the bulk of the technique’s impact lies outside utility support.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.