What is ISO 27001 Annex A 7.13 – Equipment Maintenance?
ISO 27001 Annex A 7.13 – Equipment Maintenance requires organizations to maintain equipment appropriately to ensure the continued availability, integrity, and security of information-processing equipment.
Equipment maintenance means ensuring that equipment is:
- Maintained according to its requirements
- Repaired when necessary
- Protected during maintenance
- Serviced by authorized personnel
- Returned to service securely
- Properly documented where appropriate
Equipment can include:
- Servers
- Network switches
- Routers
- Firewalls
- Laptops
- Desktops
- Mobile devices
- Printers
- Backup devices
- UPS systems
- Security appliances
- Storage devices
- CCTV systems
- Access-control equipment
- Environmental monitoring equipment
- Other information-processing equipment
Simple explanation: Equipment that supports information processing should be maintained so that it remains secure, reliable, and fit for purpose.
Why is Annex A 7.13 Important?
Equipment can become a security or availability risk when it is:
- Not maintained
- Outdated
- Damaged
- Misconfigured
- Overheating
- Running with failing components
- Repaired by unauthorized personnel
- Returned from maintenance without security checks
For example:
Server overheating → unexpected shutdown → service unavailable
Or:
Network equipment fails → connectivity lost → employees cannot access business systems
Or:
Laptop sent to an external repair provider → sensitive information exposed
Equipment maintenance therefore has both operational and information-security implications.
What Does ISO 27001 Annex A 7.13 Require?
The organization should establish appropriate arrangements to maintain information-processing equipment.
The maintenance approach should consider:
- Equipment criticality
- Security sensitivity
- Manufacturer requirements
- Business impact
- Environmental conditions
- Maintenance frequency
- Authorized personnel
- Third-party maintenance providers
- Remote maintenance
- Data stored on equipment
- Replacement parts
- Configuration changes
- Maintenance records
- Secure return to service
The level of maintenance should be proportionate to risk.
A small startup with laptops and cloud services will have very different maintenance requirements from an organization operating its own data center.
What is Equipment Maintenance?
Equipment maintenance includes activities performed to keep equipment working securely and reliably.
Preventive maintenance
Performed before a failure occurs.
Examples:
- UPS battery testing
- HVAC maintenance
- Firmware updates
- Hardware inspections
- Disk-health checks
- Cleaning
- Preventive replacement
Corrective maintenance
Performed after a problem occurs.
Examples:
- Replacing a failed hard drive
- Repairing a network switch
- Replacing a damaged laptop
- Fixing a failed power supply
Security maintenance
Focused specifically on maintaining security.
Examples:
- Firmware updates
- Security patches
- Configuration reviews
- Endpoint security updates
- Certificate updates
- Secure configuration validation
Equipment Maintenance and the CIA Triad
Equipment maintenance supports all three information-security objectives.
| Security Objective | Maintenance Example |
|---|---|
| Confidentiality | Prevent unauthorized access during repair |
| Integrity | Ensure equipment/configuration is not improperly modified |
| Availability | Prevent equipment failure and service interruption |
For example, replacing a failed storage device may restore availability.
But if the failed drive contains sensitive information, the organization must also consider secure handling and disposal.
Activities Required to Implement Annex A 7.13
1. Identify Equipment Requiring Maintenance
Start with the organization’s asset inventory.
Identify equipment that is important to information processing.
Examples:
- Servers
- Firewalls
- Switches
- Routers
- Laptops
- Backup equipment
- UPS
- CCTV
- Access-control systems
- Network appliances
This should connect with A.5.9 – Inventory of Information and Other Associated Assets.
2. Determine Equipment Criticality
Not every device requires the same maintenance approach.
For example:
| Equipment | Criticality | Maintenance Approach |
|---|---|---|
| Production firewall | Critical | Scheduled maintenance |
| Core switch | High | Preventive + corrective |
| Employee laptop | Medium | Standard IT maintenance |
| Spare monitor | Low | As required |
| UPS | High | Periodic testing |
| CCTV recorder | High | Periodic inspection |
This helps avoid spending excessive resources on low-risk equipment.
3. Define Maintenance Requirements
Maintenance requirements may come from:
- Manufacturer instructions
- Supplier recommendations
- Internal risk assessment
- Business continuity requirements
- Security requirements
- Warranty conditions
- Regulatory requirements
- Contractual commitments
For example:
UPS → battery testing
Network equipment → firmware/security maintenance
Laptop → operating system/security updates
HVAC → scheduled servicing
4. Create a Maintenance Schedule
Critical equipment should have appropriate maintenance schedules.
Example:
| Equipment | Maintenance | Frequency | Responsible |
|---|---|---|---|
| UPS | Battery/functional test | Quarterly | IT |
| Firewall | Firmware/security review | As required | IT |
| Network switch | Health/configuration review | Quarterly | IT |
| Laptop | Security updates | Monthly/automatic | IT |
| CCTV | Functional check | Monthly | Facilities |
| Temperature sensor | Functional check | Quarterly | IT |
The frequency should be determined based on:
- Risk
- Manufacturer requirements
- Usage
- Criticality
- Failure history
5. Authorize Maintenance Personnel
Maintenance should be performed by:
- Authorized employees
- Approved contractors
- Authorized vendors
- Qualified service providers
The organization should know:
Who is allowed to access the equipment?
What are they authorized to do?
What information could they potentially access?
6. Control Third-Party Maintenance
Many organizations use external providers for equipment maintenance.
Examples:
- Laptop repair vendors
- Network engineers
- Data-center technicians
- Printer service providers
- CCTV vendors
- HVAC providers
- UPS maintenance companies
Third-party access should be appropriately controlled.
Consider:
- Supplier authorization
- NDA/confidentiality
- Visitor controls
- Supervision
- Access restrictions
- Maintenance records
- Data protection
- Secure handling of equipment
- Return procedures
This connects with:
A.5.19 – Information Security in Supplier Relationships
and
A.5.20 – Addressing Information Security Within Supplier Agreements.
7. Protect Information During Maintenance
Maintenance can expose sensitive information.
For example:
An employee laptop is sent to a repair center.
The device may contain:
- Emails
- Customer information
- Source code
- Documents
- Credentials
- Browser sessions
- Security information
Before external maintenance, determine whether:
- Data can be removed
- The device can be encrypted
- The technician can work without accessing data
- Access should be supervised
- The device should be wiped
- A replacement device should be provided
The appropriate approach depends on the risk.
8. Control Remote Maintenance
Modern equipment may support remote maintenance.
Examples:
- Remote administration
- Vendor support portals
- Remote diagnostics
- Cloud management consoles
- Remote firmware updates
Remote maintenance should be appropriately controlled.
Controls may include:
- Strong authentication
- MFA
- Authorized accounts
- Time-limited access
- Logging
- Approval
- Session monitoring
- Secure communication
Remote maintenance should not create an uncontrolled administrative access path.
9. Protect Equipment During Maintenance
Physical protection should continue while equipment is being serviced.
For example:
- Prevent unauthorized access
- Protect equipment from damage
- Use appropriate tools
- Protect components from electrostatic discharge where relevant
- Maintain secure work areas
- Prevent information exposure
- Secure removed components
10. Control Maintenance Activities
For important equipment, maintenance may be managed through a ticket or change record.
Example:
Maintenance request
↓
Risk/impact assessment
↓
Approval
↓
Maintenance
↓
Testing
↓
Security verification
↓
Return to service
↓
Record completion
This is especially important for critical infrastructure.
11. Verify Equipment After Maintenance
After maintenance, verify that:
- Equipment operates correctly
- Security configuration remains appropriate
- Required software/firmware is installed
- Access controls remain active
- Logging is functioning
- Network connectivity works
- Security tools are operational
- Configuration has not been unnecessarily changed
For example:
Firewall maintenance completed → configuration verified → connectivity tested → logging confirmed → service restored.
12. Securely Handle Removed Components
Maintenance may involve removing:
- Hard drives
- SSDs
- Memory
- Backup media
- Network components
- Storage devices
If removed components contain information, they must be handled appropriately.
This connects with:
- A.7.10 – Storage Media
- A.8.10 – Information Deletion
For example:
Failed SSD → identify data sensitivity → secure handling → sanitization/destruction → disposal record
Startup Example
Imagine a 50-person SaaS startup.
The company uses:
- Cloud production infrastructure
- Company laptops
- Firewall
- Network switches
- Wi-Fi access points
- UPS
- CCTV
- Access-control system
The startup does not have its own data center.
Practical maintenance approach
Laptops
- Automatic security updates
- Endpoint protection
- Periodic health checks
- Repair through approved providers
Firewall
- Firmware/security updates
- Configuration backup
- Authorized administrator access
- Maintenance/change records
Network switches
- Periodic health checks
- Firmware updates where appropriate
- Configuration backup
UPS
- Battery testing
- Maintenance records
- Replacement based on condition
CCTV/access control
- Periodic functional checks
- Vendor maintenance where required
The startup does not need an enormous equipment-maintenance program.
It needs a documented and risk-based approach to maintaining important equipment.
Equipment Maintenance Register
A simple register can provide useful evidence.
| Asset ID | Equipment | Criticality | Maintenance | Frequency | Owner | Last Done | Next Due |
|---|---|---|---|---|---|---|---|
| AST-001 | Firewall | Critical | Firmware/configuration review | Quarterly/as required | IT | ||
| AST-002 | Core Switch | High | Health check | Quarterly | IT | ||
| AST-003 | UPS | High | Battery test | Quarterly | IT | ||
| AST-004 | Laptop | Medium | Security/health check | Monthly | IT | ||
| AST-005 | CCTV | High | Functional test | Monthly | Facilities |
Maintenance Request Example
For critical equipment:
| Field | Example |
|---|---|
| Asset | Firewall |
| Maintenance Type | Firmware update |
| Reason | Security update |
| Requested By | IT |
| Risk | Temporary network interruption |
| Approval | IT Manager |
| Maintenance Window | Approved period |
| Backup | Configuration backup completed |
| Testing | Connectivity and security validation |
| Result | Successful |
| Record | Maintenance ticket |
Maintenance Risk Assessment
| Risk | Impact | Control |
|---|---|---|
| Unauthorized technician access | High | Authorized vendor + supervision |
| Data exposure during repair | High | Encryption / data removal / controlled repair |
| Incorrect configuration | High | Backup + change control |
| Service interruption | High | Maintenance window + rollback plan |
| Failed update | High | Tested update + recovery plan |
| Lost equipment | High | Asset tracking |
| Insecure remote maintenance | High | MFA + controlled access + logging |
| Improper disposal of parts | High | Secure media disposal |
Equipment Maintenance and Change Management
Equipment maintenance and change management are closely connected.
Not every maintenance activity is necessarily a major change.
However, maintenance that can affect:
- Security configuration
- Network architecture
- System availability
- Software/firmware
- Access rights
- Critical services
should be appropriately controlled.
Example
Routine cleaning of a laptop
May simply be recorded as maintenance.
Firewall firmware upgrade
May require:
- Change request
- Approval
- Backup
- Maintenance window
- Testing
- Rollback plan
- Completion record
This connects with A.8.32 – Change Management.
Cloud-First Startup Considerations
A cloud-first organization may have fewer physical IT assets, but equipment maintenance still applies.
The startup may maintain:
- Laptops
- Network equipment
- Firewalls
- Wi-Fi equipment
- UPS systems
- Mobile devices
- Security equipment
For cloud infrastructure, physical equipment maintenance is generally performed by the cloud provider.
The organization should therefore understand:
- What equipment it owns
- What equipment suppliers maintain
- What contractual responsibilities exist
- What service assurances are available
- How cloud provider maintenance could affect availability
Relevant supplier assurance may include:
- SOC reports
- ISO certifications
- Availability commitments
- Maintenance procedures
- Business continuity information
The organization should not claim that it physically maintains cloud provider servers if it does not.
Audit Evidence for Annex A 7.13
An auditor may request:
Policies and procedures
- Equipment Maintenance Policy
- Equipment Maintenance Procedure
- Asset Management Policy
- IT Operations Procedure
- Change Management Procedure
- Supplier Management Procedure
Operational evidence
- Equipment inventory
- Maintenance schedule
- Maintenance register
- Maintenance tickets
- Service reports
- Vendor maintenance reports
- Warranty records
- Inspection records
- Repair records
- Firmware update records
- UPS maintenance records
- CCTV maintenance records
Security evidence
- Authorized maintenance personnel list
- Vendor authorization
- Maintenance access logs
- Remote maintenance logs
- Change approvals
- Configuration backups
- Post-maintenance testing records
- Secure disposal records
Audit Checklist – ISO 27001 Annex A 7.13
| Question | Yes/No | Evidence |
|---|---|---|
| Has equipment requiring maintenance been identified? | ||
| Has equipment criticality been determined? | ||
| Are maintenance requirements defined? | ||
| Is preventive maintenance performed where appropriate? | ||
| Are maintenance activities scheduled? | ||
| Are maintenance personnel authorized? | ||
| Are third-party maintenance providers controlled? | ||
| Is information protected during equipment maintenance? | ||
| Is remote maintenance appropriately controlled? | ||
| Are maintenance activities recorded? | ||
| Are important maintenance activities authorized? | ||
| Are critical equipment configurations backed up before maintenance where appropriate? | ||
| Is equipment tested after maintenance? | ||
| Are removed storage components securely handled? | ||
| Are maintenance failures or incidents recorded? | ||
| Are maintenance schedules periodically reviewed? |
Common Mistakes
1. Treating maintenance as purely an IT issue
Maintenance can create information-security risks.
A technician repairing a laptop may have access to sensitive company information.
2. No maintenance records
Organizations sometimes perform maintenance but retain no evidence.
An auditor may ask:
“How do you know this equipment is actually maintained?”
Records provide evidence.
3. Allowing unauthorized vendors
An external technician should not automatically receive unrestricted access to company equipment.
4. Ignoring remote maintenance
Remote vendor access can create a powerful administrative access path.
It should be controlled and monitored appropriately.
5. Sending laptops for repair without considering data
A laptop may contain:
- Customer information
- Source code
- Documents
- Credentials
- Personal information
The organization should assess the risk before sending it to an external repair provider.
6. No post-maintenance verification
Maintenance is not finished simply because the technician says the repair is complete.
The organization should verify:
- Functionality
- Security configuration
- Access controls
- Logging
- Connectivity
7. No maintenance for UPS systems
A UPS that has never been tested may provide little practical protection during a power failure.
8. Excessive maintenance bureaucracy
Not every laptop requires a complex maintenance ticket every week.
The maintenance approach should be risk-based and proportionate.
Practical Startup Implementation Model
A startup can implement Annex A 7.13 using this model:
1. Identify
Identify equipment that requires maintenance.
2. Classify
Determine equipment criticality and sensitivity.
3. Define
Establish maintenance requirements.
4. Schedule
Create appropriate maintenance schedules.
5. Authorize
Ensure maintenance is performed by authorized personnel.
6. Protect
Protect information and equipment during maintenance.
7. Execute
Perform the maintenance.
8. Verify
Test equipment and security controls after maintenance.
9. Record
Maintain appropriate maintenance evidence.
10. Review
Review maintenance failures, recurring problems and effectiveness.
Startup formula: Identify → Classify → Schedule → Authorize → Maintain → Verify → Record → Improve
Policy vs. Process vs. Evidence
| Layer | Example |
|---|---|
| Policy | Equipment Maintenance Policy |
| Process | Equipment Maintenance Procedure |
| Schedule | Preventive Maintenance Schedule |
| Technical Control | Patch/firmware management |
| Record | Maintenance Register |
| Evidence | Service report |
| Change Control | Approved maintenance/change ticket |
| Verification | Post-maintenance test |
| Review | Maintenance effectiveness review |
The objective is not to create paperwork for every technical activity.
The objective is to demonstrate that important equipment is maintained, protected during maintenance, and returned to service securely.
Relationship With Other ISO 27001 Controls
| Control | Relationship |
|---|---|
| A.5.9 Inventory of Information and Other Associated Assets | Provides the asset inventory used to identify equipment |
| A.5.11 Return of Assets | Relevant when equipment is returned after use or employment termination |
| A.5.15 Access Control | Controls access to equipment and maintenance environments |
| A.5.18 Access Rights | Supports authorization of maintenance personnel |
| A.5.19 Supplier Relationships | Relevant to external maintenance providers |
| A.5.20 Supplier Agreements | Defines security requirements for maintenance suppliers |
| A.5.22 Monitoring, Review and Change Management of Supplier Services | Relevant to supplier-provided maintenance |
| A.5.29 Information Security During Disruption | Maintenance can cause temporary disruption |
| A.5.30 ICT Readiness for Business Continuity | Critical equipment needs maintenance to support continuity |
| A.7.5 Physical and Environmental Threats | Equipment must be protected from environmental threats |
| A.7.8 Equipment Siting and Protection | Addresses physical protection and placement |
| A.7.10 Storage Media | Relevant when equipment contains removable/storage media |
| A.7.11 Supporting Utilities | Utilities supporting equipment may also require maintenance |
| A.7.12 Cabling Security | Cabling supporting equipment may require maintenance |
| A.8.1 User Endpoint Devices | Relevant to laptops and other endpoint equipment |
| A.8.8 Management of Technical Vulnerabilities | Security updates and vulnerability remediation |
| A.8.9 Configuration Management | Maintains secure equipment configurations |
| A.8.14 Redundancy of Information Processing Facilities | Redundant equipment may reduce maintenance-related availability risk |
| A.8.32 Change Management | Controls maintenance activities that introduce changes |
A.7.13 vs A.8.8 Management of Technical Vulnerabilities
These controls are related but different.
| Control | Main Focus |
|---|---|
| A.7.13 Equipment Maintenance | Keeping equipment physically and technically operational and securely maintained |
| A.8.8 Management of Technical Vulnerabilities | Identifying and addressing technical vulnerabilities |
Example
A firewall receives a firmware update.
A.7.13 → maintenance of the equipment.
A.8.8 → addressing security vulnerabilities contained in the firmware.
A.8.32 → controlling the change if the update affects the environment.
The same activity can therefore support multiple controls.
A.7.13 vs A.7.11
| Control | Main Focus |
|---|---|
| A.7.11 Supporting Utilities | Protecting utilities needed to operate information-processing facilities |
| A.7.13 Equipment Maintenance | Maintaining the equipment itself |
Example
For a network room:
A.7.11: Maintain UPS and cooling.
A.7.13: Maintain firewall, switches and other equipment.
Both controls work together to maintain availability.
Useful Resources
Organizations can create the following supporting documents:
- Equipment Maintenance Policy
[Insert Draft Document Link] - Equipment Maintenance Procedure
[Insert Draft Document Link] - Equipment Maintenance Schedule
[Insert Draft Document Link] - Equipment Maintenance Register
[Insert Draft Document Link] - Maintenance Request Form
[Insert Draft Document Link] - Third-Party Equipment Maintenance Procedure
[Insert Draft Document Link] - Remote Maintenance Procedure
[Insert Draft Document Link] - Post-Maintenance Verification Checklist
[Insert Draft Document Link] - Equipment Repair Record
[Insert Draft Document Link] - Equipment Maintenance Audit Checklist
[Insert Draft Document Link]
Questions an Auditor May Ask
1. Which equipment requires maintenance?
Show your asset inventory and maintenance requirements.
2. How do you determine maintenance frequency?
Explain risk, criticality, manufacturer requirements and business needs.
3. Who is authorized to perform maintenance?
Show authorized personnel or approved vendors.
4. How do you protect information during equipment repair?
Explain encryption, data removal, controlled access or other relevant measures.
5. How do you control third-party maintenance?
Show supplier agreements, authorization and maintenance records.
6. How do you control remote maintenance?
Explain MFA, authorization, logging and time-limited access where applicable.
7. What happens after equipment is repaired?
Show post-maintenance testing and security verification.
8. What happens to failed storage devices?
Explain secure handling, sanitization and disposal.
9. How do you maintain UPS and other supporting equipment?
Show maintenance and testing records.
10. How do you prevent maintenance from causing an outage?
Explain maintenance windows, backups, approvals, testing and rollback arrangements.
Startup-Focused Final Takeaway
ISO 27001 Annex A 7.13 is about more than “servicing IT equipment.”
It is about ensuring that equipment supporting information processing remains:
- Reliable
- Secure
- Available
- Properly maintained
- Protected during repair
- Returned to service safely
A practical startup approach is:
Identify equipment → Assess criticality → Define maintenance → Authorize personnel → Protect information → Perform maintenance → Verify → Record → Review
The simple rule
Equipment that supports important information should not be left to fail before the organization thinks about how to maintain it.
For startups, this does not mean creating a complicated maintenance program.
A practical approach may be as simple as:
Asset inventory + maintenance schedule + authorized technicians + secure repair process + maintenance records + post-maintenance verification.
The objective is to make sure that a maintenance activity does not accidentally become a security incident, data exposure, or business outage.
