A.8.6 Technological
Capacity management
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (10)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CP-2mostlyaligns with — Both controls require identifying resource needs and planning actions to ensure systems can meet operational demands under varying conditions.
- CM-6partialaligns with — Both emphasize ongoing monitoring and tuning of system resources to maintain performance and availability.
- PL-2partialaligns with — Both require documenting capacity-related planning decisions for critical systems to support consistent resource management.
- SC-6partialaligns with — Both address ensuring adequate resources are available to prevent degradation of security functions due to resource exhaustion.
- SI-4partialaligns with — Both require monitoring of system resources to detect capacity issues before they impact operations or security.
Aligned NIST CSF 2.0 outcomes (10)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- ID.AM-08mostlyaligns with — Capacity planning that accounts for business criticality, future requirements, and life-cycle considerations aligns with managing systems, hardware, software, services, and data throughout their life cycles.
- PR.IR-04mostlyaligns with — The ISO control's focus on monitoring utilization, stress-testing, and ensuring sufficient capacity to meet peak demands directly supports maintaining adequate resource capacity for availability.
- ID.IM-03partialaligns with — Using capacity monitoring data and stress-test results to identify and avoid resource constraints reflects identifying improvements from execution of operational processes and activities.
- ID.RA-04partialaligns with — Projecting future capacity needs and identifying resource limitations or single points of failure contributes to understanding potential impacts and likelihoods of threats exploiting vulnerabilities.
- PR.PS-01partialaligns with — Establishing a documented capacity management plan and applying tuning, monitoring, and optimization practices supports configuration management practices.
Related OWASP ASVS 5.0 requirements (10)
Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- V13.1.2partialaligns with — Defining and monitoring maximum concurrent connections and resource limits for services is a concrete implementation of the ISO control's call to identify capacity requirements and apply monitoring to maintain availability.
- V13.1.3partialaligns with — The ISO control's emphasis on documented projections of future capacity needs and resource-management strategies for external services aligns with the ASVS requirement to define resource-management strategies for every external system the application uses.
- V15.2.2partialaligns with — The ISO control's requirement to monitor utilization and perform stress-testing to ensure capacity meets peak demand directly supports the ASVS requirement to implement defenses against loss of availability caused by resource-intensive functionality.
Related weaknesses / CWE (30)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-400mostlyprevents — By continuously monitoring utilization, stress-testing peak loads, and maintaining documented plans to scale or throttle resources, the control directly limits an attacker’s ability to drive a system into uncontrolled resource exhaustion.
- CWE-410mostlyprevents — Capacity management directly addresses sizing resource pools to handle peak demand and prevent exhaustion.
- CWE-770mostlyprevents — Capacity projections and elasticity measures ensure that allocation requests are bounded and can be throttled, reducing the window in which an attacker can force unbounded resource reservations.
- CWE-1049partialfinds — Capacity management identifies and mitigates resource exhaustion from inefficient large-table queries.
- CWE-1050partialmitigates — Capacity management directly limits resource exhaustion caused by unbounded loops.
- CWE-1072partialmitigates — Capacity management can indirectly reduce resource exhaustion from unpooled connections but does not mandate pooling.
- CWE-1176partialfinds — Capacity management can drive optimization of CPU-intensive algorithms to prevent resource exhaustion.
- CWE-1325partialmitigates — Capacity management directly limits total memory consumption across objects, mitigating unbounded sequential allocations.
- CWE-401partialfinds — Capacity management may detect memory exhaustion symptoms but does not prevent the coding flaw.
- CWE-407partialmitigates — Capacity management can detect and mitigate performance degradation caused by algorithmic complexity attacks.
- CWE-408partialmitigates — Capacity management may mitigate impact of amplification but does not prevent the weakness itself.
- CWE-409partialmitigates — Capacity management can detect and prevent resource exhaustion from decompression bombs.
- CWE-674partialfinds — Capacity management includes monitoring and limits that mitigate resource exhaustion from runaway recursion.
- CWE-774partialprevents — Capacity management directly limits resource allocation including file descriptors.
- CWE-405nonemitigates — Stress-testing and demand-reduction tactics (e.g., bandwidth throttling) blunt amplification vectors that would otherwise let an attacker multiply resource consumption through a single request.
- CWE-406nonemitigates — Capacity management directly limits excessive outbound traffic that an actor could otherwise trigger.
- CWE-789nonenone — Capacity management monitors overall resource use but does not prevent individual allocation bugs.
- CWE-799nonenone — Capacity management directly limits request rates and resource exhaustion that CWE-799 describes.
- CWE-920nonemitigates — Capacity management directly limits resource consumption, including power, thereby mitigating the weakness.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.