A.7.13 Physical
Equipment maintenance
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (9)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- MA-2mostlyaligns with — Both controls require scheduled, authorized maintenance with documented records and post-maintenance verification to keep equipment in a secure, operational state.
- MA-4mostlyaligns with — Both controls mandate authorization, supervision, and confidentiality protections for remote or external maintenance personnel accessing organizational equipment.
- MA-5mostlyaligns with — Both controls restrict maintenance activities to authorized personnel and require oversight when those personnel perform work on-site.
- CM-3partialaligns with — Both controls require documented approval and tracking of changes that result from maintenance activities to preserve configuration integrity.
- MA-6partialaligns with — Both controls emphasize timely maintenance to sustain equipment reliability and security, though the ISO control focuses more on procedural controls than explicit timeliness metrics.
Aligned NIST CSF 2.0 outcomes (9)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PR.PS-03mostlyaligns with — The ISO control's requirement to maintain hardware according to supplier specifications and to inspect equipment after maintenance directly supports the CSF outcome of keeping hardware maintained and replaced commensurate with risk.
- ID.AM-08partialaligns with — Tracking maintenance activities, faults, and post-maintenance inspections throughout the equipment life cycle supports the CSF outcome of managing hardware and systems across their entire life span.
- PR.AA-01partialaligns with — Authorizing only approved personnel, enforcing confidentiality agreements, and controlling remote-maintenance access reinforce the management of identities and credentials for authorized users and services.
- PR.IR-02partialaligns with — Requiring inspection after maintenance and adherence to insurance-driven maintenance obligations help protect technology assets from environmental or operational degradation.
- PR.PS-01partialaligns with — Establishing and monitoring a formal maintenance program with documented faults and corrective actions contributes to the broader configuration-management discipline required by the CSF subcategory.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.