A7.13 Equipment maintenance
4 min read
ISO 27001 A7.13 Equipment maintenance emphasizes the need to maintain equipment in accordance with manufacturer specifications and organizational requirements. This includes both hardware (e.g., servers, workstations, network devices) and environmental systems (e.g., UPS, air conditioning units). Effective maintenance also reduces the likelihood of unauthorized access or information leakage due to malfunctioning or improperly handled devices.
Equipment maintenance is crucial for ensuring the availability, reliability, and longevity of IT and operational assets. Poorly maintained equipment can lead to unexpected downtime, data loss, security vulnerabilities, and reduced productivity. Preventive and corrective maintenance practices help safeguard information systems from malfunctions and physical deterioration.
Implementation Guide #
Step 1: Establish Maintenance Policies and Procedures
- Define maintenance schedules for all critical equipment types.
- Differentiate between preventive (routine) and corrective (issue-based) maintenance.
- Ensure maintenance plans align with equipment manufacturer recommendations.
Step 2: Assign Maintenance Responsibilities
- Designate internal personnel or third-party vendors responsible for equipment servicing.
- Maintain contracts and service level agreements (SLAs) with external maintenance providers.
- Ensure all maintenance staff are authorized and trained for their tasks.
Step 3: Maintain Accurate Maintenance Records
- Log all maintenance activities, including the date, type of service, personnel involved, and any detected issues.
- Keep records digitally with regular backups.
- Ensure logs are tamper-proof and auditable.
Step 4: Protect Information During Maintenance
- Back up data before performing maintenance on critical systems.
- Disable access to sensitive data where possible during servicing.
- Supervise third-party personnel and restrict their access to only necessary areas.
Step 5: Conduct Regular Equipment Inspections
- Periodically inspect equipment for wear, overheating, dust accumulation, or unusual noise.
- Check for firmware or software updates as part of routine maintenance.
- Identify signs of tampering or malfunction that may indicate a security threat.
Templates #
- Equipment Maintenance Policy
- Maintenance Log Sheet
- Maintenance Checklist
- Third-Party Maintenance Agreement Template
- Incident Report for Equipment Malfunction
Example #
A company relied on a series of routers and switches in its data center. However, due to a lack of scheduled maintenance, dust accumulation led to overheating and equipment failure, resulting in network downtime. After updating their maintenance policy, the organization implemented quarterly cleanings, firmware updates, and inspections. The result: system uptime improved, and equipment lifespan increased.
Had the organization not acted, critical services could have been interrupted, or sensitive data might have been lost due to system failure.
How to Comply #
To comply with ISO 27001 A.7.13, organizations should:
- Establish and follow equipment maintenance policies.
- Maintain a log of all maintenance activities.
- Protect data and system integrity during servicing.
- Supervise and control third-party access during maintenance.
- Ensure equipment is functioning optimally to avoid security gaps.
How to Pass an Audit #
Key Documents to Prepare:
- Equipment Maintenance Policy
- Maintenance Logs and Checklists
- Maintenance Contracts and SLAs
- Evidence of Staff Authorization
- Incident Reports (if applicable)
What the Auditor Will Check:
- Are maintenance procedures documented and followed?
- Are logs of all maintenance activities available and complete?
- Is equipment regularly inspected and kept in good working condition?
- Are safeguards in place to protect information during maintenance activities?
- Are third-party vendors properly vetted and monitored?
Top 3 Mistakes People Make #
- Failing to maintain logs of routine maintenance activities.
- Allowing third-party vendors unsupervised access to sensitive equipment.
- Not performing regular inspections, leading to preventable equipment failure.
ISO 27001 Equipment Maintenance FAQ #
Q1: Is preventive maintenance required even if the equipment seems to be working fine?
Yes. Preventive maintenance helps identify potential issues before they cause outages or data loss. It’s essential for long-term reliability and compliance.
Q2: What should be done before equipment is serviced by a third party?
Data should be backed up, sensitive systems secured, and the vendor’s access should be restricted and supervised. NDAs and SLAs should be in place.
Q3: Do software or firmware updates count as maintenance?
Yes. Keeping firmware and system software up to date is a vital aspect of equipment maintenance and helps address known vulnerabilities.
ISO 27001 Controls and Attribute Values #
| Control | Attribute Value |
| A.7.13 Equipment Maintenance | Preventive, Risk-Based, Operational |
| Purpose | Ensure IT and infrastructure equipment is maintained to reduce downtime and prevent security risks. |
| Applicability | All departments using IT or environmental equipment |
| ISO 27001 Domains | Asset Management, Physical and Environmental Security, Operations Security |
By implementing a proactive equipment maintenance program, organizations minimize disruptions, extend hardware life, and reduce the risk of vulnerabilities caused by neglected systems. Regular maintenance is not just good practice—it’s a vital component of any robust information security strategy.