SOC2-A1.1 A1.1 Managing processing capacity
SOC2-A1.1 in SOC 2 (the AICPA 2017 Trust Services Criteria with the revised points of focus). All SOC 2 controls held. Open SOC 2 on the standards site.
The control as we hold it
A1.1 Managing processing capacity. Current processing capacity and the use of infrastructure, data and software are maintained, monitored and evaluated so capacity demand can be managed and extra capacity added in time to meet objectives. Points of focus: usage is measured to set a capacity baseline and judge the risk of impaired availability; average and peak demand are forecast against capacity and tolerances, including capacity lost when components fail; and change management is triggered when forecasts exceed tolerances.
Reviewed and closest counterparts in the other frameworks
Reviewed rows come from a released pair; a closest match is the nearest held text and is not a reviewed row.
NIST SP 800-53 Rev 5
- NIST800-AU-4 AU-4 Audit Log Storage Capacity (closest match)
- NIST800-CA-7 CA-7 Continuous Monitoring (closest match)
- NIST800-CP-2 CP-2 Contingency Plan (closest match)
- NIST800-CP-9 CP-9 System Backup (closest match)
- NIST800-SC-6 SC-6 Resource Availability (closest match)
- NIST800-SI-13 SI-13 Predictable Failure Prevention (closest match)
What an auditor commonly asks for
General guidance for this control area (domain: A - Availability), in our words, not a statement of the standard and not binding on an assessor.
- the capacity-monitoring record
- the backup and restore test record
- the recovery-plan test record
- the environmental-protection records