A.7.13 Physical
Equipment maintenance
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (13)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- MA-2mostlyaligns with — Both controls require scheduled, authorized maintenance with documented records and post-maintenance verification to keep equipment in a secure, operational state.
- MA-2mostlycovers — A.7.13's maintenance objective and preventive intent fully account for the scheduling, documentation, review, approval, and monitoring requirements in MA-2, but a real residual remains around MA-2's explicit emphasis on manufacturer/vendor specifications, on-site vs. remote distinctions, and removal of components that A.7.13 does not detail.
- MA-4mostlyaligns with — Both controls mandate authorization, supervision, and confidentiality protections for remote or external maintenance personnel accessing organizational equipment.
- MA-5mostlyaligns with — Both controls restrict maintenance activities to authorized personnel and require oversight when those personnel perform work on-site.
- CM-3partialaligns with — Both controls require documented approval and tracking of changes that result from maintenance activities to preserve configuration integrity.
- MA-6partialaligns with — Both controls emphasize timely maintenance to sustain equipment reliability and security, though the ISO control focuses more on procedural controls than explicit timeliness metrics.
- MA-6partialcovers — A.7.13's broad requirement to maintain equipment to avoid operational interruption and asset compromise is only partially accounted for by MA-6's narrower focus on obtaining timely support/spare parts after failure; the ISO control also encompasses preventive/scheduled maintenance, procedures, and records not required by MA-6.
Aligned NIST CSF 2.0 outcomes (16)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PR.PS-03mostlyaligns with — The ISO control's requirement to maintain hardware according to supplier specifications and to inspect equipment after maintenance directly supports the CSF outcome of keeping hardware maintained and replaced commensurate with risk.
- ID.AM-08partialaligns with — Tracking maintenance activities, faults, and post-maintenance inspections throughout the equipment life cycle supports the CSF outcome of managing hardware and systems across their entire life span.
- PR.AA-01partialaligns with — Authorizing only approved personnel, enforcing confidentiality agreements, and controlling remote-maintenance access reinforce the management of identities and credentials for authorized users and services.
- PR.IR-02partialaligns with — Requiring inspection after maintenance and adherence to insurance-driven maintenance obligations help protect technology assets from environmental or operational degradation.
- PR.PS-01partialaligns with — Establishing and monitoring a formal maintenance program with documented faults and corrective actions contributes to the broader configuration-management discipline required by the CSF subcategory.
- ID.AM-08implements — A.7.13 operationalizes the hardware/equipment portion of the asset life-cycle management outcome named in ID.AM-08 (maintenance prevents loss/damage/interruption across the life cycle); the link is within the shared domain but ID.AM-08 does not name maintenance explicitly.
- PR.AA-01implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.IR-02implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.PS-01implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.PS-03implements — A.7.13 directly operationalizes the hardware maintenance outcome named in PR.PS-03
Mitigated MITRE ATT&CK techniques (114)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- T1199prevents — A.7.13 requires authorizing/controlling remote maintenance access, supervising on-site maintenance personnel, using confidentiality agreements, and implementing controls (including before/after inspection) when external parties perform maintenance; this directly constrains the supply-chain trusted-relationship vector described in T1199, but leaves the bulk of the technique (pre-existing compromised third-party accounts, delegated admin offers, non-maintenance contractors) untouched.
- T1485recovers — A.7.13 clause k explicitly requires applying secure disposal/re-use measures (cross-referenced to 7.14) if equipment is to be disposed of after maintenance, which recovers availability for any data/assets on that equipment; this directly counters the post-destruction state for the subset of T1485 that targets equipment taken off-premises or handled during maintenance, but leaves the bulk of in-place network-wide or cloud deletion untouched.
- T1486recovers — A.7.13 is exclusively about preventive maintenance, authorized servicing, logging faults, and secure handling of equipment taken off-site or disposed; it contains no provision for restoring encrypted data or system state after a ransomware impact.
- T1490recovers — A.7.13 requires backup of equipment containing information when taken off-premises for maintenance, secure disposal/re-use after maintenance, and inspection to ensure proper function post-maintenance, directly enabling recovery of assets and operations disrupted by the T1490 technique on affected systems.
- T1561recovers — A.7.13 explicitly requires backup/recovery preparation via secure off-premises handling, post-maintenance inspection to ensure integrity, and secure disposal/re-use controls that enable restoration of wiped or corrupted assets, aligning with the recovery verb for availability interruption from disk wipe (per event-lane anchors like A.8.13 vs T1486).
- T1561.001recovers — A.7.13 clause j (inspect/verify post-maintenance) and k (secure disposal/re-use per 7.14) plus the purpose of preventing operational interruption from lack of maintenance provide a recovery path after a wipe has rendered storage unusable, but only for hardware faults or maintenance-induced loss, not for an active adversarial wipe performed via direct disk access or third-party drivers.
- T1561.002recovers — A.7.13 requires backup of equipment containing information (via 7.9 and 7.14 cross-references) plus post-maintenance inspection and secure re-use, enabling restoration of wiped boot structures from clean images or backups after the destructive event.
- T1578.003recovers — A.7.13 requires backup/recovery-capable maintenance processes (records, inspection before return-to-service, secure off-site handling, and secure disposal/re-use per 7.14) that can restore a deleted cloud instance from snapshots or backups, but this is limited to on-premises-style equipment maintenance and does not address ephemeral cloud IaaS deletion or automated instance termination.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.