A.7.11 Physical
Supporting utilities
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (13)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PE-11mostlyaligns with — Both controls address the need for reliable emergency power to sustain critical operations during utility failures.
- PE-12mostlyaligns with — Both controls require emergency lighting to ensure safe operations and personnel movement when primary utilities are disrupted.
- PE-14mostlyaligns with — Both controls require ongoing monitoring, testing, and maintenance of environmental and utility systems that support information processing facilities.
- PE-9mostlyaligns with — Both controls require the organization to protect and maintain the power and utility infrastructure that supports information systems.
- CP-8partialaligns with — Both controls require redundant or alternate utility feeds to maintain telecommunications and other essential services during outages.
- PE-15partialaligns with — Both controls address protection against utility-related hazards such as water damage by requiring safeguards and emergency shut-off mechanisms.
Aligned NIST CSF 2.0 outcomes (10)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PR.IR-02mostlyaligns with — The ISO control's focus on maintaining and testing utility equipment directly supports protecting technology assets from environmental threats such as power or HVAC failures.
- PR.IR-03mostlyaligns with — Requiring redundant utility feeds, alarms, and emergency cut-offs implements mechanisms that sustain operations during adverse environmental or infrastructure conditions.
- DE.CM-02partialaligns with — Installing alarms and performing regular inspections of utility equipment contributes to monitoring the physical environment for conditions that could lead to adverse events.
- ID.AM-08partialaligns with — Managing utility-supporting equipment throughout its lifecycle through configuration, inspection, and testing aligns with the CSF outcome for lifecycle asset management.
- PR.IR-04partialaligns with — Regular capacity appraisals and multiple utility feeds help maintain adequate resource capacity to ensure availability of information processing facilities.
Related weaknesses / CWE (5)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-1384mostlyprevents — Ensures supporting utilities (power, HVAC) are protected, mitigating environmental-condition failures.
- CWE-400nonemitigates — Regular capacity appraisal and redundant utility feeds reduce the likelihood that resource exhaustion or service interruption will occur due to single points of failure or uncontrolled growth.
- CWE-693nonenone — Placing utility equipment on a separate network and restricting internet connectivity only when necessary and securely configured reduces the exposure of protection mechanisms to bypass or failure.
- CWE-770nonenone — Periodic inspection, testing, and capacity planning limit the chance that supporting utilities will be allocated without throttling or limits, thereby preventing uncontrolled resource consumption.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.