ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. 4. ISO 27001 Annex A Cont...
  5. ISO 27001 Annex A 7.11 Supporting utilities

ISO 27001 Annex A 7.11 Supporting utilities

What is ISO 27001 Annex A 7.11 – Supporting Utilities?

ISO 27001 Annex A 7.11 – Supporting Utilities requires organizations to protect information-processing facilities from failures or disruptions of supporting utilities.

Supporting utilities are the services that allow information-processing equipment and facilities to operate safely and continuously.

Examples include:

  • Electricity
  • Power supply
  • UPS systems
  • Backup generators
  • Internet connectivity
  • Telecommunications
  • Heating, ventilation and air conditioning (HVAC)
  • Cooling systems
  • Water supply, where relevant
  • Fire suppression systems
  • Building management systems
  • Other utilities required for critical operations

Simple explanation: Your servers, network devices, security systems and other technology are only as reliable as the utilities that keep them running.

A power failure, overheating, network outage, or failure of another critical utility can cause:

  • Service interruption
  • Data loss
  • Equipment damage
  • Security incidents
  • Loss of availability
  • Business disruption

Why is Annex A 7.11 Important?

Information security is not only about protecting systems from hackers.

A system can become unavailable because:

  • Power goes out.
  • A UPS fails.
  • A server room overheats.
  • Internet connectivity is lost.
  • Cooling equipment stops working.
  • A building utility fails.
  • A backup generator does not start.
  • A critical facility becomes inaccessible.

For organizations that depend heavily on technology, these failures can directly affect:

  • Availability
  • Business operations
  • Customer services
  • Security monitoring
  • Data processing
  • Communications
  • Incident response
  • Business continuity

Example

Imagine a SaaS company whose network equipment is located in a small office server room.

The building loses power.

Without adequate protection:

Power failure → network equipment shuts down → internet unavailable → employees cannot access systems → customer support is disrupted

With appropriate controls:

Power failure → UPS activates → critical equipment remains operational → outage detected → controlled shutdown/backup power → business continuity process activated

Simple principle: Protect the utilities that keep critical information systems available.


What Does ISO 27001 Annex A 7.11 Require?

The organization should identify utilities that are important to its information-processing facilities and protect them against:

  • Failure
  • Interruption
  • Damage
  • Environmental conditions
  • Unauthorized interference
  • Capacity limitations
  • Single points of failure
  • Other foreseeable disruptions

The level of protection should be proportionate to business and information-security risk.

ISO 27001 does not mean every organization must install:

  • A diesel generator
  • Dual power feeds
  • Redundant internet providers
  • Industrial cooling systems
  • Large UPS systems

A small startup operating primarily through cloud services may have very different requirements from a bank operating its own data center.


What Are Supporting Utilities?

Supporting utilities are the underlying services needed to operate information-processing facilities.

Common Supporting Utilities

UtilityPurposePotential Security Impact
ElectricityPowers systemsSystem shutdown
UPSTemporary backup powerPrevents sudden shutdown
GeneratorExtended backup powerSupports operations during outages
InternetConnectivityService disruption
TelecomVoice/data communicationCommunication failure
HVACTemperature controlEquipment overheating
CoolingProtects critical equipmentHardware failure
Fire suppressionProtects facilitiesEquipment/fire damage
WaterFacility operations/coolingPotential physical disruption
Building systemsFacility supportLoss of physical availability

Not every utility applies to every organization.

The organization should identify what is actually required.


Supporting Utilities and the CIA Triad

Annex A 7.11 primarily supports availability, but utility failures can affect all three information-security principles.

Confidentiality

A utility failure may force emergency access or uncontrolled movement of equipment.

Integrity

Sudden power loss may cause data corruption or incomplete transactions.

Availability

Power, cooling or connectivity failures can make systems unavailable.

Most utility-related incidents appear to be availability problems, but their consequences can extend to confidentiality and integrity as well.


Activities Required to Implement Annex A 7.11

1. Identify Critical Information-Processing Facilities

Start by identifying where information processing occurs.

Examples:

  • Office network rooms
  • Server rooms
  • Data centers
  • Security operations centers
  • Backup facilities
  • Communication rooms
  • Cloud infrastructure dependencies
  • Critical work areas

For a cloud-first startup, this may be much simpler.

For example:

AWS production environment + SaaS applications + office network + employee endpoints


2. Identify Supporting Utilities

For each critical facility, identify the utilities it depends upon.

Example:

FacilityUtilityDependency
Network RoomElectricityCritical
Network RoomUPSHigh
Network RoomCoolingHigh
OfficeInternetHigh
Security SystemElectricityCritical
Server RoomHVACCritical

3. Assess Utility Risks

Determine what could happen if a utility fails.

Consider:

  • How likely is the failure?
  • How long could it last?
  • Which systems would be affected?
  • Which customers would be affected?
  • Could information be lost?
  • Could equipment be damaged?
  • Is there an alternative?
  • Is there a single point of failure?

4. Protect Against Power Failure

Depending on risk, controls may include:

  • UPS
  • Surge protection
  • Backup generator
  • Dual power supplies
  • Redundant power circuits
  • Automatic shutdown
  • Power monitoring
  • Emergency procedures

Startup example

A small startup may only need:

UPS → critical network equipment → graceful shutdown

It may not need a generator.

The control should match the actual risk.


5. Protect Critical Equipment From Overheating

Information-processing equipment generates heat.

Critical equipment may therefore require:

  • HVAC
  • Dedicated cooling
  • Temperature monitoring
  • Ventilation
  • Environmental alerts
  • Equipment placement away from heat sources

For a small network room, an organization may use:

  • Air conditioning
  • Temperature sensor
  • Alert notification
  • Regular inspection

6. Protect Internet and Telecommunications

Modern businesses may depend heavily on internet connectivity.

Consider:

  • Primary internet provider
  • Backup internet connection
  • Mobile hotspot
  • Secondary ISP
  • SD-WAN
  • Failover configuration
  • Telecom redundancy

However, redundancy should be based on business impact.

A company operating a non-critical internal application may not require two ISPs.

A customer-facing 24/7 SaaS platform may have much stronger availability requirements.


7. Consider Single Points of Failure

A single point of failure is a component where one failure can cause a significant disruption.

Examples:

One ISP → Internet outage → Entire office offline

One UPS → UPS failure → Network equipment shuts down

One cooling unit → Cooling failure → Equipment overheating

The organization should identify important single points of failure and determine whether they require mitigation.


8. Monitor Supporting Utilities

Where appropriate, utilities should be monitored.

Examples:

  • Power status
  • UPS battery status
  • Temperature
  • Humidity
  • Internet connectivity
  • Generator status
  • HVAC status
  • Fire detection
  • Environmental alarms

Monitoring can provide early warning before a utility failure becomes a major incident.


9. Maintain Supporting Utilities

Supporting equipment should be maintained according to its importance.

Examples:

  • UPS battery testing
  • Generator maintenance
  • HVAC servicing
  • Electrical inspections
  • Fire system testing
  • Network equipment maintenance
  • Environmental sensor testing

Maintenance records can provide useful audit evidence.


10. Define Response Procedures

The organization should know what to do when a critical utility fails.

For example:

Power outage

Power failure detected

↓

UPS activates

↓

IT team notified

↓

Assess outage duration

↓

Activate backup power / controlled shutdown

↓

Monitor critical systems

↓

Recover services

↓

Document incident

This should connect with:

  • A.5.24 – Information Security Incident Management Planning and Preparation
  • A.5.26 – Response to Information Security Incidents
  • A.5.29 – Information Security During Disruption
  • A.5.30 – ICT Readiness for Business Continuity

Startup Example

Imagine a 35-person SaaS startup.

The organization uses:

  • AWS for production
  • Google Workspace
  • Company laptops
  • Office internet
  • Office Wi-Fi
  • Firewall
  • Network switches
  • Small network room
  • Cloud-based business applications

The company does not operate its own data center.

Supporting utilities

UtilityRequirement
ElectricityCritical for office/network
UPSProtect firewall, switches and network equipment
InternetCritical for employee/customer operations
Backup connectivityMobile hotspot or secondary ISP
CoolingRequired for network room
Temperature monitoringAppropriate for network room
Cloud provider infrastructureCovered through supplier/cloud assurance

Failure scenario

Office power failure

↓

UPS keeps network equipment operational temporarily

↓

IT receives notification

↓

Employees switch to approved remote-working arrangements

↓

Critical cloud services remain available

↓

If outage continues, controlled shutdown occurs

↓

Incident is recorded and reviewed

This may be sufficient for a startup depending on its risk assessment.


Supporting Utilities Register

A simple register can be maintained.

Utility IDUtilityFacilityCriticalityControlOwnerReview
UTIL-001ElectricityNetwork RoomCriticalUPSITQuarterly
UTIL-002InternetOfficeHighPrimary + backupITQuarterly
UTIL-003CoolingNetwork RoomHighHVAC + monitoringFacilitiesMonthly
UTIL-004TemperatureNetwork RoomHighSensor + alertITMonthly
UTIL-005Fire ProtectionOfficeHighBuilding fire systemFacilitiesAs scheduled

Utility Dependency Assessment

Organizations can document how critical systems depend on utilities.

SystemElectricityInternetCoolingBackupBusiness Impact
Production CloudProvider-managedYesProvider-managedProvider-managedHigh
Office NetworkYesYesModerateUPSMedium
FirewallYesYesYesUPSHigh
Employee LaptopsYesYesNoBatteryMedium
CCTVYesSometimesNoUPSMedium
Access ControlYesSometimesNoBackup powerHigh

This helps management focus resources on the utilities that matter most.


Utility Failure Scenarios

A basic scenario assessment can be useful.

ScenarioPotential ImpactPreventive ControlResponse
Power outageNetwork unavailableUPSBackup power / controlled shutdown
Internet outageCloud access unavailableSecondary connectionFailover
Cooling failureEquipment overheatingHVAC monitoringShut down/protect equipment
UPS failureLoss of backup powerMaintenance/testingReplace/repair
Fire system failureIncreased physical riskInspection/testingEscalate immediately
Water leakageEquipment damageEquipment positioningIsolate/protect equipment

Cloud-First Startup Considerations

Many startups assume that because they use AWS, Azure, or another cloud provider, Annex A 7.11 does not apply to them.

That is not necessarily correct.

The startup still has supporting utilities for its own environment.

For example:

  • Office electricity
  • Internet connectivity
  • Wi-Fi
  • Firewall
  • Network switches
  • Access-control systems
  • Security monitoring
  • Employee devices
  • Local backup systems

At the same time, the startup generally does not directly manage the cloud provider’s:

  • Data-center electricity
  • Generators
  • Cooling
  • Physical network infrastructure

Those responsibilities are normally addressed through the organization’s cloud/supplier risk-management approach.

The organization should understand the applicable shared responsibility model and obtain appropriate assurance from the cloud provider.


Audit Evidence for Annex A 7.11

An auditor may review evidence such as:

Policies and procedures

  • Physical Security Policy
  • Supporting Utilities Procedure
  • Business Continuity Policy
  • ICT Continuity Procedure
  • Environmental Protection Procedure
  • Incident Management Procedure

Operational evidence

  • Utility dependency register
  • Utility risk assessment
  • UPS inspection records
  • UPS battery test records
  • Generator maintenance records
  • HVAC maintenance records
  • Temperature monitoring records
  • Internet failover test results
  • Electrical inspection records
  • Fire-system inspection records
  • Utility incident records
  • Business continuity test records

Supplier evidence

Where utilities are provided by third parties:

  • Data center assurance reports
  • Supplier assessments
  • SOC reports
  • ISO 27001 certificates
  • Availability commitments
  • Contractual requirements
  • Business continuity information

Audit Checklist – ISO 27001 Annex A 7.11

QuestionYes/NoEvidence
Have critical information-processing facilities been identified?
Have supporting utilities been identified?
Has the organization assessed utility-related risks?
Are critical power requirements identified?
Is backup power provided where necessary?
Are UPS systems maintained and tested?
Are critical environmental conditions monitored?
Is cooling adequate for critical equipment?
Are telecommunications dependencies identified?
Are critical internet dependencies considered?
Have single points of failure been identified?
Are important utilities monitored?
Are utility systems regularly maintained?
Are utility failure procedures documented?
Are utility incidents recorded and reviewed?
Are third-party utility dependencies assessed?
Are business continuity requirements connected to utility failures?
Are utility controls reviewed periodically?

Common Mistakes

1. Buying a generator without assessing the risk

A generator is not automatically required.

The organization should first determine:

What systems need to remain operational, for how long, and what is the impact of failure?


2. Ignoring internet connectivity

For a cloud-first organization, internet connectivity may be as important as electricity.

If employees cannot reach cloud services, business operations may stop.


3. Ignoring cooling

Organizations sometimes protect equipment from unauthorized access but forget that overheating can cause equipment failure.


4. No UPS maintenance

Having a UPS is not enough.

The organization should know:

  • Is the battery healthy?
  • Has it been tested?
  • Does it support the required load?
  • What happens when power fails?

5. No backup connectivity

A company that depends entirely on one internet connection may have an avoidable single point of failure.


6. No utility failure testing

A documented procedure is useful, but the organization should test important assumptions where appropriate.

For example:

What actually happens when the primary internet connection fails?


7. Assuming cloud providers eliminate all responsibility

Cloud providers manage their own facilities, but the organization remains responsible for understanding its own operational dependencies and supplier responsibilities.


8. Treating maintenance records as optional

Maintenance records can demonstrate that supporting utilities are actually being maintained rather than simply documented in a policy.


Practical Startup Implementation Model

A startup can implement Annex A 7.11 using this model:

1. Identify

Identify critical information-processing facilities.

2. Map

Identify the utilities each facility depends upon.

3. Assess

Assess the impact of utility failure.

4. Protect

Implement proportionate controls.

5. Monitor

Monitor critical utilities where appropriate.

6. Maintain

Perform required inspections and maintenance.

7. Test

Test important backup and failover arrangements.

8. Respond

Define what happens during a utility failure.

9. Recover

Restore normal operations safely.

10. Improve

Review failures, tests and incidents.

Startup formula: Know the dependency → Assess the impact → Protect the critical utility → Test the backup → Learn from failures.


Policy vs. Process vs. Evidence

LayerExample
PolicyPhysical and Environmental Security Policy
ProcessSupporting Utilities Management Procedure
Risk AssessmentUtility Dependency Risk Assessment
Technical ControlUPS, backup internet, temperature monitoring
MaintenanceUPS/HVAC service records
TestingInternet failover test
IncidentPower outage report
ReviewBusiness continuity/utility review

Having a Supporting Utilities Policy alone does not demonstrate effective implementation.

The organization should be able to show that the identified controls are actually operating.


Relationship With Other ISO 27001 Controls

ControlRelationship
A.5.9 Inventory of Information and Other Associated AssetsIdentifies equipment and facilities requiring utilities
A.5.24 Incident Management Planning and PreparationPrepares for utility-related incidents
A.5.26 Response to Information Security IncidentsSupports response to utility failures with security impact
A.5.29 Information Security During DisruptionMaintains security during disruptions
A.5.30 ICT Readiness for Business ContinuityAddresses ICT continuity requirements
A.7.1 Physical Security PerimetersProtects physical boundaries
A.7.3 Securing Offices, Rooms and FacilitiesProtects facilities containing equipment
A.7.4 Physical Security MonitoringHelps detect physical/environmental events
A.7.5 Physical and Environmental ThreatsProtects against physical/environmental threats
A.7.8 Equipment Siting and ProtectionProtects equipment from environmental and physical risks
A.7.10 Storage MediaProtects storage media from physical/environmental risks
A.8.13 Information BackupSupports recovery following utility disruption
A.8.14 Redundancy of Information Processing FacilitiesAddresses redundancy where required
A.8.16 Monitoring ActivitiesCan support monitoring of relevant systems and events

A.7.5 vs A.7.11

These controls are related but different.

ControlMain Focus
A.7.5 Protecting Against Physical and Environmental ThreatsProtection from threats such as fire, flood, temperature, humidity and natural events
A.7.11 Supporting UtilitiesEnsuring utilities required for information processing are protected against failure or disruption

Example

A server room becomes too hot.

  • A.7.5 → recognizes excessive temperature as an environmental threat.
  • A.7.11 → addresses the supporting cooling utility needed to prevent or manage that condition.

A.7.11 vs A.8.14 Redundancy of Information Processing Facilities

These controls also work together.

A.7.11 focuses on supporting utilities.

A.8.14 focuses on redundancy of information-processing facilities.

For example:

Primary power → UPS → backup generator

is primarily a supporting-utility consideration.

Whereas:

Primary production environment → secondary processing facility

is an information-processing redundancy consideration.


Useful Resources

Organizations can create the following supporting documents:

  1. Supporting Utilities Policy
    [Insert Draft Document Link]
  2. Supporting Utilities Procedure
    [Insert Draft Document Link]
  3. Utility Dependency Register
    [Insert Draft Document Link]
  4. Supporting Utilities Risk Assessment
    [Insert Draft Document Link]
  5. UPS Inspection Checklist
    [Insert Draft Document Link]
  6. Backup Power Test Record
    [Insert Draft Document Link]
  7. Internet Failover Test Record
    [Insert Draft Document Link]
  8. Environmental Monitoring Checklist
    [Insert Draft Document Link]
  9. Utility Maintenance Register
    [Insert Draft Document Link]
  10. Utility Failure Incident Report
    [Insert Draft Document Link]
  11. Supporting Utilities Audit Checklist
    [Insert Draft Document Link]

Questions an Auditor May Ask

1. What utilities are critical to your information-processing environment?

Explain the organization’s key dependencies.

2. What happens if the power fails?

Demonstrate the actual response process.

3. Do you have backup power?

If yes, explain its scope and testing.

If no, explain the risk assessment and why alternative controls are appropriate.

4. What happens if your internet connection fails?

Explain redundancy, failover or business continuity arrangements.

5. How do you protect critical equipment from overheating?

Show cooling, environmental monitoring and maintenance arrangements.

6. How do you know your UPS will work?

Show testing and maintenance evidence.

7. Have you identified single points of failure?

Show the relevant risk assessment or dependency analysis.

8. How do you maintain supporting utilities?

Show maintenance schedules and service records.

9. Have you tested your backup arrangements?

Show relevant test results.

10. How do cloud providers fit into your utility dependency model?

Explain the responsibilities managed by the cloud provider and how the organization obtains appropriate assurance.


Startup-Focused Final Takeaway

ISO 27001 Annex A 7.11 is fundamentally about availability and resilience.

Technology cannot operate reliably if the utilities supporting it fail.

A startup does not need to build a data center or purchase expensive infrastructure simply to satisfy ISO 27001.

Instead, it should understand its actual dependencies.

Ask:

  • What systems are critical?
  • What utilities do they depend on?
  • What happens if electricity fails?
  • What happens if internet connectivity fails?
  • What happens if cooling fails?
  • Which utilities have a single point of failure?
  • Which backup arrangements actually exist?
  • Have they been tested?
  • What does our cloud provider manage?
  • What do we manage ourselves?

The simple rule

Do not protect only the technology. Protect the utilities that allow the technology to operate.

For a startup, the practical approach is:

Identify → Assess → Protect → Monitor → Maintain → Test → Respond → Recover → Improve

A good Annex A 7.11 implementation is not the one with the most expensive backup infrastructure.

It is the one where the organization understands its critical utility dependencies and has proportionate, tested measures to keep important information-processing activities available.

How can we help?

Leave a Reply

Your email address will not be published. Required fields are marked *