On this page
- Quick Reference (60 Seconds)
- What the Standard Actually Requires
- Why Equipment Maintenance Matters
- Scope and Applicability
- Key Definitions and Terminology
- Relationship to Other Controls
- Implementation Roadmap (Week-by-Week)
- Detailed Implementation Guidance
- Tools, Technologies, and Solutions
- Policy and Procedure Templates
- Risk Assessment and Treatment
- Audit and Compliance Checklist
- Metrics and KPIs
- Common Pitfalls and How to Avoid Them
- Illustrative Scenarios
- Multi-Framework Mapping
- Regulatory and Industry Context
- Roles and Responsibilities (RACI)
- Documentation and Evidence Requirements
- Continuous Improvement
- FAQ
- Industry-Specific Maintenance Requirements
- Maturity Model for A.7.13
- Additional FAQ
- Illustrative Scenario: Bangalore IT Company, Maintenance Failure to Security Incident
- Maintenance Security Metrics and KPIs
- References and Further Reading
Quick Reference (60 Seconds)
Figure · At a glance
A.7.13 at a glance
- Control ID
- A.7.13
- Control Name
- Equipment Maintenance
- ISO 27002:2022 Section
- 7.13
- Primary Purpose
- Ensure equipment is maintained to preserve
- Key Activities
- Schedule maintenance
- Typical Owners
- IT Operations, Facility Management
| Aspect | Summary |
|---|---|
| Control ID | A.7.13 |
| Control Name | Equipment Maintenance |
| ISO 27002:2022 Section | 7.13 |
| Primary Purpose | Ensure equipment is maintained to preserve information integrity, availability, and security |
| Key Activities | Schedule maintenance, perform authorized maintenance only, protect data during maintenance, verify integrity after maintenance |
| Typical Owners | IT Operations, Facility Management, Asset Management |
| Implementation Effort | Medium (4–8 weeks) |
| Annual overhead Range | – for growing companies |
Bottom Line: Equipment maintenance is not just about keeping things running, it is about ensuring that maintenance activities do not introduce security vulnerabilities, data loss, or unauthorized access. Proper maintenance preserves both availability and security.
What the Standard Actually Requires
Figure · Process
What A.7.13 asks you to do

ISO 27001:2022 Annex A.7.13 states:
ISO 27001:2022 Annex A 7.13 asks organizations to maintain equipment properly to keep information available and intact.
ISO 27002:2022 expands this into practical guidance covering:
- Maintenance scheduling, Equipment must be maintained at appropriate intervals based on manufacturer recommendations and operational requirements
- Authorized maintenance only, Maintenance must be performed by authorized personnel, whether internal staff or external vendors
- Data protection during maintenance, Information must be protected from unauthorized access, disclosure, or modification during maintenance activities
- Log and record maintenance, All maintenance activities must be logged and documented
- Verification after maintenance, Equipment must be verified for proper operation and security after maintenance
- Sanitization before disposal, Equipment must be properly sanitized before being disposed of or repurposed
- Maintenance in secure areas, Maintenance in secure areas requires additional access controls and supervision
Why Equipment Maintenance Matters
The Maintenance-Security Connection
Maintenance is often viewed as an operational activity separate from security. In reality, maintenance activities create significant security exposure: maintenance personnel have physical access to equipment, may bypass security controls, and may inadvertently or intentionally compromise data.
Key Statistics
- 30% of data breaches involve third-party vendors or contractors, including maintenance personnel
- Equipment failures are a leading cause of unplanned downtime, with 45% of failures attributed to inadequate maintenance
- Unauthorized maintenance, performed by untrained or unapproved personnel, is a common cause of security incidents
- Improper maintenance procedures can corrupt data, disable security features, or leave equipment in a vulnerable state
Real-World Consequences
- An unauthorized technician "fixed" a server by resetting the BIOS, which disabled TPM and BitLocker, leaving the disk unencrypted; the server was later stolen, and all data was exposed
- A maintenance vendor replacing a hard drive kept the failed drive (which contained recoverable data) instead of returning it for secure disposal; the data was later found on the secondary market
- A routine firmware update applied incorrectly bricked 12 network switches, causing a 6-hour network outage affecting 2,000 employees
- A cleaning crew servicing HVAC in a server room accidentally unplugged a UPS, causing an immediate shutdown of all critical systems
- A maintenance log was not maintained, making it impossible to determine which vendor had access to a compromised system during a breach investigation
Regulatory and Business Drivers
- DPDP Act 2023 requires organizations to ensure data protection during all processing activities, including maintenance
- RBI Cyber Security Framework mandates maintenance records for critical banking infrastructure; unauthorized maintenance is a compliance violation
- PCI DSS v4.0 Requirement 9.5 requires physical security of hardware during maintenance and repairs
- SOC 2 CC6.7 requires physical security of systems and equipment, including during maintenance
- ISO 55000 (Asset Management) provides a framework for systematic equipment maintenance
Scope and Applicability
What Is Covered
- All information processing equipment (servers, workstations, storage, network devices)
- All peripheral equipment (printers, scanners, kiosks, ATMs)
- All security equipment (firewalls, IDS/IPS, CCTV, access control systems)
- All utility equipment (UPS, generators, HVAC, fire suppression)
- All cabling infrastructure (patch panels, switches, routers)
- All mobile and endpoint devices (laptops, tablets, smartphones)
- All maintenance activities, whether performed by internal staff or external vendors
What Is Not Covered
- Non-IT equipment not associated with information processing (e.g., general office furniture, kitchen appliances)
- Personal devices not used for work (though BYOD policies may extend coverage)
Applicability by Organization Type
| Organization Type | Applicability | Key Maintenance Concerns |
|---|---|---|
| IT/Software Services | High | Server farms, dev environments, network infrastructure, cloud hardware |
| BFSI | Critical | ATMs, core banking servers, trading infrastructure, security systems |
| Healthcare | Critical | Medical devices, patient record systems, imaging equipment, life support IT |
| Manufacturing | High | SCADA/ICS systems, production control servers, IoT devices |
| Government/Defense | Critical | Classified systems, citizen data servers, secure communications |
| Education | Medium | Campus networks, lab equipment, student systems, research compute |
| SaaS/Cloud | Critical | Data center infrastructure, customer-facing servers, network equipment |
| Retail/E-commerce | High | POS systems, inventory servers, payment terminals, warehouse automation |
Key Definitions and Terminology
| Term | Definition |
|---|---|
| Preventive Maintenance | Scheduled maintenance activities designed to prevent equipment failures before they occur |
| Corrective Maintenance | Maintenance performed in response to an equipment failure or malfunction |
| Predictive Maintenance | Maintenance based on condition monitoring and data analysis to predict when maintenance is needed |
| Authorized Maintenance | Maintenance performed by personnel who have been approved and authorized by the organization |
| Maintenance Window | A scheduled period of time during which maintenance activities are performed, typically with reduced service impact |
| Change Management | A formal process for managing changes to IT systems, including maintenance-related changes |
| Service Level Agreement (SLA) | A contract between the organization and a maintenance vendor defining response times, service levels, and responsibilities |
| Mean Time Between Failures (MTBF) | The average time between equipment failures, used to schedule preventive maintenance |
| Mean Time to Repair (MTTR) | The average time required to repair equipment after a failure |
| Firmware | Software embedded in hardware devices that controls their operation |
| BIOS/UEFI | The firmware interface between a computer's hardware and its operating system |
| Sanitization | The process of removing data from equipment before disposal or repurposing |
| Spare Parts Inventory | A stock of critical components kept on-site to minimize repair time |
| Maintenance Log | A record of all maintenance activities performed on a piece of equipment |
Relationship to Other Controls
| Control | Relationship |
|---|---|
| A.5.9 Inventory of information and other assets | Maintenance must be tracked against the asset inventory |
| A.5.33 Protection of records | Maintenance records must be protected |
| A.7.2 Physical entry controls | Maintenance personnel require controlled access to equipment areas |
| A.7.6 Working in secure areas | Maintenance in secure areas requires additional controls |
| A.7.8 Equipment siting and protection | Equipment siting affects maintenance accessibility and safety |
| A.7.11 Supporting utilities | Utility maintenance is essential for equipment operation |
| A.7.13 Secure disposal of equipment | Maintenance may result in equipment replacement requiring disposal |
| A.8.1 User endpoint devices | Endpoint devices require maintenance and patch management |
| A.8.9 Configuration management | Maintenance may change configurations; must be managed |
| A.8.13 Information backup | Backups before maintenance protect against data loss |
| A.8.15 Information transfer | Maintenance may involve data transfer for remote support |
| A.8.24 Use of cryptography | Maintenance must not disable or compromise encryption |
| A.8.29 Secure development | Maintenance may involve software updates and patches |
| A.8.34 Protection of information systems during disruption | Maintenance windows are planned disruptions that must be managed |
Implementation Roadmap (Week-by-Week)
Week 1: Equipment Inventory and Maintenance Assessment
- Inventory all equipment requiring maintenance
- Identify manufacturer maintenance recommendations for each asset
- Review current maintenance practices and identify gaps
- Identify all maintenance vendors and contracts
- Assess maintenance personnel authorization and training
- Review maintenance records and documentation quality
- Identify critical equipment with no maintenance plan
Week 2: Policy and Procedure Development
- Draft equipment maintenance policy
- Define maintenance scheduling standards (preventive, predictive, corrective)
- Define authorization requirements for internal and external maintenance personnel
- Create maintenance procedures for different equipment types
- Define data protection requirements during maintenance
- Create maintenance logging and documentation standards
- Define post-maintenance verification requirements
- Create maintenance window and change management procedures
Week 3: Maintenance Scheduling System Implementation
- Implement maintenance scheduling system (CMMS, ITSM, or calendar-based)
- Create maintenance schedules for all equipment based on manufacturer recommendations and criticality
- Define maintenance windows (low-impact times for different systems)
- Set up automated reminders and escalations for overdue maintenance
- Create maintenance calendar and communicate to stakeholders
- Integrate maintenance scheduling with change management
Week 4: Vendor Management and Authorization
- Vet all maintenance vendors (security background, insurance, certifications)
- Establish SLAs with all maintenance vendors
- Create vendor access procedures (escort, badging, access limitations)
- Require NDAs and security agreements for all external maintenance vendors
- Create vendor performance monitoring process
- Define vendor authorization and de-authorization procedures
Week 5: Data Protection During Maintenance
- Create pre-maintenance checklist (backup verification, data protection measures)
- Define data handling requirements for maintenance personnel (no data removal, no photography, etc.)
- Create post-maintenance verification checklist (functionality, security settings, data integrity)
- Define requirements for maintenance of encrypted devices (key management, decryption procedures)
- Create procedures for maintenance involving component replacement (hard drives, memory, etc.)
- Define secure disposal requirements for components replaced during maintenance
Week 6: Maintenance Execution and Logging
- Perform first scheduled maintenance using new procedures
- Log all maintenance activities in the maintenance system
- Document any issues, deviations, or lessons learned
- Verify post-maintenance functionality and security
- Collect feedback from maintenance personnel and equipment owners
- Refine procedures based on practical experience
Week 7: Training and Communication
- Train all IT staff on maintenance procedures and documentation
- Train all maintenance vendors on organizational requirements
- Create quick reference guides for common maintenance tasks
- Communicate maintenance windows and schedules to all stakeholders
- Train security staff on maintenance monitoring and incident response
- Create maintenance awareness materials for general staff
Week 8: Audit and Validation
- Conduct internal audit of maintenance controls
- Verify all equipment has maintenance schedules
- Verify all maintenance is being logged and documented
- Verify post-maintenance verification is occurring
- Verify vendor authorization and access controls
- Prepare documentation for external audit
- Plan for continuous improvement
Detailed Implementation Guidance
Maintenance Types and Scheduling
Preventive Maintenance (PM):
| Equipment Type | PM Frequency | Typical Activities |
|---|---|---|
| Servers | Monthly | Dust cleaning, fan inspection, temperature check, log review, firmware check |
| Storage arrays | Monthly | Health check, SMART review, cache battery check, firmware update |
| Network switches | Quarterly | Port inspection, firmware update, configuration backup, log review |
| Firewalls | Quarterly | Rule review, firmware update, log review, performance check |
| UPS | Monthly | Battery test, voltage check, fan inspection, alarm test |
| Generator | Monthly | Start test, fuel check, coolant check, battery check |
| HVAC | Quarterly | Filter replacement, coil cleaning, refrigerant check, airflow check |
| Printers | Monthly | Cleaning, consumable check, firmware update, security setting review |
| Laptops/Workstations | Quarterly | Disk cleanup, malware scan, patch check, physical inspection |
| CCTV | Quarterly | Camera cleaning, lens check, recording review, storage check |
| Access control | Quarterly | Reader test, card check, log review, backup test |
| Fire suppression | Annually | Detector test, suppression test, pressure check, inspection certificate |
Predictive Maintenance (PdM):
- Use sensor data and analytics to predict failures before they occur
- Monitor: temperature trends, vibration, power consumption, error rates, performance degradation
- Use tools: IPMI, SNMP monitoring, SMART data, BMS/DCIM analytics, AI-powered prediction
- Schedule maintenance based on predicted failure probability, not fixed intervals
Corrective Maintenance (CM):
- Respond to failures, alarms, or detected issues
- Document root cause for all corrective maintenance
- Analyze trends to identify systemic issues
- Update preventive maintenance schedules based on corrective findings
Maintenance Personnel Authorization
Internal Maintenance Staff:
- Must be employees with appropriate technical skills and certifications
- Must have background verification completed
- Must sign confidentiality and security agreements
- Must be trained on organizational security policies and maintenance procedures
- Must have access rights limited to the equipment they maintain
- Must be supervised when working in secure areas
External Maintenance Vendors:
- Must be security-vetted before engagement (background checks, financial checks, reference checks)
- Must sign NDAs and security agreements
- Must provide proof of insurance and certifications
- Must be escorted when working in secure areas (unless pre-approved and security-cleared)
- Must have access limited to the specific equipment being maintained
- Must not be left unattended with equipment containing sensitive data
- Must return all replaced components to the organization (for secure disposal)
- Must not photograph, record, or remove data from equipment
Authorization Process:
- Vendor/staff submits application with credentials, certifications, and references
- Security team conducts background verification
- Legal/Procurement reviews and signs NDA/security agreement
- IT Operations reviews technical qualifications
- CISO or designated authority approves authorization
- Authorization is time-limited (typically 1 year, renewable)
- Authorization is revoked immediately upon contract termination or security incident
- Authorized list is reviewed quarterly
Data Protection During Maintenance
Pre-Maintenance Checklist:
| Step | Action | Responsibility |
|---|---|---|
| 1 | Verify recent backup of all data on the equipment | IT Operations |
| 2 | Verify backup integrity (restore test if possible) | IT Operations |
| 3 | Document current security settings (encryption, authentication, access controls) | IT Security |
| 4 | Remove or secure sensitive data if maintenance does not require access to it | Data Owner |
| 5 | Disable remote access and network connectivity if not required for maintenance | IT Security |
| 6 | Assign maintenance escort for secure areas | Security |
| 7 | Verify maintenance personnel authorization | Security |
| 8 | Brief maintenance personnel on data protection requirements | IT Operations |
| 9 | Record maintenance start time and personnel in maintenance log | IT Operations |
During Maintenance:
| Requirement | Description |
|---|---|
| No data removal | Maintenance personnel must not remove data, media, or components containing data without authorization |
| No photography/recording | Photography, video recording, or audio recording of equipment, screens, or documents is prohibited without authorization |
| Supervision | Maintenance in secure areas must be supervised by an authorized employee |
| Access limitation | Maintenance personnel must only access the specific equipment being maintained |
| Tool control | Personal tools may be subject to inspection; organization may provide approved tools |
| Network isolation | Equipment under maintenance should be isolated from production networks if possible |
| Encryption preservation | Maintenance must not disable, bypass, or compromise encryption without authorization and documentation |
Post-Maintenance Checklist:
| Step | Action | Responsibility |
|---|---|---|
| 1 | Verify equipment powers on and functions correctly | IT Operations |
| 2 | Verify all security settings are restored (encryption, authentication, access controls) | IT Security |
| 3 | Verify network connectivity and security configurations | IT Security |
| 4 | Verify data integrity (checksums, database consistency, file integrity) | IT Operations |
| 5 | Verify no unauthorized software or configurations were installed | IT Security |
| 6 | Collect all replaced components for secure disposal or inventory | IT Operations |
| 7 | Verify maintenance area is cleared and secure | Security |
| 8 | Record maintenance completion, activities performed, and verification results | IT Operations |
| 9 | Close change request and maintenance ticket | IT Operations |
Component Replacement and Sanitization
Hard Drive Replacement:
- Failed hard drives must be returned to the organization, not retained by the vendor
- Failed hard drives must be sanitized (degaussed or physically destroyed) before disposal
- New hard drives must be encrypted before data is written (if encryption is required)
- RAID rebuild must be monitored and verified after replacement
- Data must be restored from backup if the failed drive was not in a redundant array
Memory Replacement:
- Memory modules may retain data for a short period after power loss
- For sensitive environments, memory must be cleared before removal (power off, wait, discharge)
- Replaced memory modules should be inventoried and securely disposed of if faulty
Motherboard/BIOS Replacement:
- BIOS settings must be documented before replacement
- TPM/encryption keys must be backed up or recovered if the motherboard contains the TPM
- Secure boot settings must be reconfigured after replacement
- BitLocker recovery keys must be available if the motherboard is replaced
Network Component Replacement:
- Configuration must be backed up before replacement
- New component must be configured with the same security settings as the old one
- Firmware must be updated to the latest secure version
- Default passwords must be changed immediately
- Component must be tested for proper security operation before being placed into production
Maintenance in Secure Areas
Additional Requirements for Secure Areas:
- Maintenance personnel must be escorted at all times
- Maintenance personnel must surrender personal devices (phones, cameras) before entering
- Maintenance must be scheduled during supervised hours
- Security personnel must be present during maintenance of security-critical equipment (firewalls, access control, CCTV)
- All tools and equipment brought into secure areas must be inspected and logged
- All replaced components must be inspected and logged before leaving the secure area
- Maintenance activities must be recorded in the secure area access log
Tools, Technologies, and Solutions
Computerized Maintenance Management Systems (CMMS)
| Vendor | Product | Key Features | licensing Range (INR) |
|---|---|---|---|
| Fiix | CMMS | Cloud-based, preventive maintenance, reporting | |
| UpKeep | CMMS | Mobile-first, work orders, asset management | |
| Hippo CMMS | CMMS | Easy to use, preventive maintenance, vendor management | |
| eMaint | CMMS | Enterprise, complete, integration | |
| Limble CMMS | CMMS | Growing companies, intuitive, mobile |
IT Service Management (ITSM) Tools with Maintenance
| Vendor | Product | Key Features | licensing Range (INR) |
|---|---|---|---|
| ServiceNow | ITSM | Enterprise, complete, CMDB, change management | |
| Freshservice | ITSM | Growing companies, asset management, CMDB, change management | |
| ManageEngine | ServiceDesk Plus | Indian market, efficient, ITSM, asset management | |
| Jira Service Management | ITSM | Development-focused, agile, integration |
Remote Maintenance and Monitoring Tools
| Vendor | Product | Key Features | licensing Range (INR) |
|---|---|---|---|
| SolarWinds | NPM/SAM | Network and server monitoring, remote diagnostics | |
| Nagios | Nagios XI | Open-source monitoring, alerting, remote checks | |
| PRTG | PRTG Network Monitor | Complete monitoring, remote probes | |
| Datadog | Infrastructure Monitoring | Cloud-native, AI-powered, predictive analytics | |
| Zabbix | Zabbix | Open-source, scalable, remote monitoring |
Asset Management and Inventory Tools
| Vendor | Product | Key Features | licensing Range (INR) |
|---|---|---|---|
| Snipe-IT | Open Source Asset Management | Free, web-based, maintenance tracking | Free (self-hosted) |
| Wasp Barcode | AssetCloud | Barcode/RFID, maintenance tracking, reporting | |
| ServiceNow | IT Asset Management | Enterprise, CMDB, lifecycle management | |
| ManageEngine | AssetExplorer | Growing companies, feature-rich, maintenance history | |
| Freshservice | Asset Management | Cloud-based, integrated with ITSM |
Policy and Procedure Templates
Equipment Maintenance Policy Template
Template
Equipment Maintenance Policy
1. Purpose
This policy establishes requirements for the maintenance of information processing equipment to ensure continued availability, reliability, and security.
2. Scope
This policy applies to all information processing equipment, security equipment, utility equipment, and peripheral devices owned or operated by the organization.
3. Maintenance Types
3.1 Preventive Maintenance
- Scheduled maintenance performed at manufacturer-recommended intervals
- Includes: cleaning, inspection, testing, firmware updates, component replacement
- Frequency determined by equipment type, criticality, and manufacturer guidance
3.2 Predictive Maintenance
- Maintenance triggered by condition monitoring and predictive analytics
- Uses sensor data, performance metrics, and trend analysis
- Reduces unnecessary maintenance while preventing failures
3.3 Corrective Maintenance
- Maintenance performed in response to failures or detected issues
- Must include root cause analysis
- Must update preventive maintenance schedules based on findings
4. Maintenance Authorization
4.1 Internal Staff
- Must be qualified and certified for the equipment they maintain
- Must have completed background verification
- Must have signed security and confidentiality agreements
- Must have access limited to authorized equipment and areas
4.2 External Vendors
- Must be security-vetted before engagement
- Must sign NDAs and security agreements
- Must provide proof of insurance and certifications
- Must be escorted in secure areas unless individually cleared
- Must return all replaced components to the organization
- Authorization is time-limited and reviewed annually
5. Data Protection During Maintenance
5.1 Pre-Maintenance
- Verify recent backup of all equipment data
- Document current security settings
- Assign escort for secure areas
- Verify maintenance personnel authorization
5.2 During Maintenance
- Maintenance personnel must not remove data or media without authorization
- Photography and recording are prohibited without authorization
- Supervision is required in secure areas
- Network isolation is recommended for production equipment
- Encryption must not be disabled without authorization
5.3 Post-Maintenance
- Verify equipment functionality and security settings
- Verify data integrity
- Verify no unauthorized software or configurations
- Collect replaced components for secure disposal
- Document all activities in maintenance log
6. Maintenance Logging
- All maintenance activities must be logged with: date, time, equipment ID, personnel, activities performed, components replaced, verification results
- Maintenance logs must be retained for the life of the equipment plus 3 years
- Maintenance logs must be protected from unauthorized modification
7. Change Management
- Maintenance that changes equipment configuration, firmware, or software must follow change management procedures
- Maintenance windows must be scheduled to minimize business impact
- Rollback procedures must be documented for all maintenance changes
8. Roles and Responsibilities
- IT Operations: Schedule maintenance, perform authorized maintenance, document activities
- IT Security: Verify security settings before and after maintenance, monitor for unauthorized changes
- Facility Management: Maintain utility equipment, coordinate physical access
- Security: Escort maintenance personnel, verify authorization, monitor secure areas
- CISO: Approve policy, authorize vendors, audit compliance
9. Enforcement
- Unauthorized maintenance is prohibited and subject to disciplinary action
- Maintenance that compromises security must be investigated and remediated
- Failure to document maintenance activities will result in corrective action
10. Review
This policy is reviewed annually or after any maintenance-related security incident.
Maintenance Log Template
Template
Equipment Maintenance Log
Equipment Details
- Equipment ID: _______________
- Equipment Type: _______________
- Manufacturer/Model: _______________
- Serial Number: _______________
- Location: _______________
- Asset Owner: _______________
Maintenance Record
| Date | Time | Type (PM/PdM/CM) | Personnel | Activities Performed | Components Replaced | Security Verification | Notes |
|---|---|---|---|---|---|---|---|
Maintenance Schedule
| Maintenance Type | Frequency | Next Due Date | Last Completed | Status |
|---|---|---|---|---|
| Preventive | ||||
| Predictive | ||||
| Firmware Update | ||||
| Battery Replacement |
Vendor Authorization
| Vendor Name | Authorization Date | Expiry Date | Scope | Status |
|---|---|---|---|---|
Signatures
- Log Maintained By: _______________ Date: _______________
- Reviewed By: _______________ Date: _______________
Risk Assessment and Treatment
Risk Assessment Matrix for Equipment Maintenance
| Risk ID | Threat | Vulnerability | Likelihood | Impact | Risk Level | Treatment |
|---|---|---|---|---|---|---|
| R1 | Unauthorized vendor accesses sensitive data | No vendor vetting; no supervision | Medium | High | High | Vendor vetting; NDAs; escort; access limitation |
| R2 | Maintenance disables encryption | Untrained personnel; poor procedures | Low | High | High | Pre/post verification; training; encryption monitoring |
| R3 | Data lost during maintenance | No backup; no verification | Medium | High | High | Pre-maintenance backup; post-maintenance integrity check |
| R4 | Replaced components contain recoverable data | Components not returned; not sanitized | Medium | High | High | Component return; secure disposal; inventory |
| R5 | Maintenance introduces malware | Untrusted tools; unauthorized software | Low | High | Medium | Tool control; software whitelist; post-scan verification |
| R6 | Equipment failure due to missed maintenance | No maintenance schedule; no tracking | High | High | Critical | CMMS/ITSM; automated scheduling; reminders; escalation |
| R7 | Maintenance window causes business disruption | Unscheduled maintenance; no rollback | Medium | Medium | Medium | Change management; maintenance windows; rollback procedures |
| R8 | Secure area breached during maintenance | No escort; no access control | Medium | High | High | Escort requirement; access logs; CCTV; device surrender |
| R9 | Configuration drift after maintenance | No configuration backup; no verification | Medium | Medium | Medium | Configuration backup; baseline comparison; automated verification |
| R10 | Maintenance vendor contract terminated but access not revoked | Poor access management | Low | High | Medium | Quarterly access review; immediate revocation on termination |
Audit and Compliance Checklist
Internal Audit Checklist (30 Questions)
Policy and Documentation (5 Questions)
- Is an equipment maintenance policy documented and approved?
- Are maintenance schedules defined for all critical equipment?
- Are maintenance authorization procedures documented?
- Are data protection procedures during maintenance documented?
- Is the policy reviewed annually?
Maintenance Scheduling (5 Questions)
- Is all equipment in a maintenance scheduling system?
- Are preventive maintenance schedules aligned with manufacturer recommendations?
- Are maintenance windows defined and communicated?
- Are overdue maintenance items tracked and escalated?
- Is maintenance integrated with change management?
Authorization and Vendors (5 Questions)
- Are all maintenance vendors security-vetted?
- Do all vendors have signed NDAs and security agreements?
- Are vendor authorizations time-limited and reviewed annually?
- Is vendor access controlled and logged?
- Are vendors escorted in secure areas?
Data Protection (5 Questions)
- Is backup verified before maintenance of critical equipment?
- Are security settings documented before maintenance?
- Is post-maintenance verification performed and documented?
- Are replaced components collected and securely disposed of?
- Is encryption preserved during maintenance?
Logging and Records (5 Questions)
- Are all maintenance activities logged?
- Do maintenance logs include personnel, activities, and verification?
- Are maintenance logs protected from tampering?
- Are maintenance logs retained for the required period?
- Are maintenance logs reviewed periodically?
Secure Area Maintenance (5 Questions)
- Is maintenance in secure areas supervised?
- Do maintenance personnel surrender devices in secure areas?
- Are tools and components logged in and out of secure areas?
- Is maintenance in secure areas recorded in the access log?
- Are security personnel present during maintenance of security equipment?
Audit Scoring
- 30–27: Excellent (Green), Full compliance
- 26–22: Good (Yellow), Minor gaps, address within 30 days
- 21–15: Needs Improvement (Orange), Significant gaps, address within 60 days
- 14–0: Critical (Red), Major non-compliance, immediate action required
Metrics and KPIs
Figure · Measures
The measures that show A.7.13 is working
- Maintenance Schedule Compliance>= 95%Monthly
- Overdue Maintenance Rate<= 5%Monthly
- Vendor Authorization Currency100%Quarterly
- Pre-Maintenance Backup Compliance100%Monthly
- Post-Maintenance Verification Rate100%Monthly
Key Performance Indicators
| KPI | Formula | Target | Measurement Frequency |
|---|---|---|---|
| Maintenance Schedule Compliance | (On-time maintenance / Total scheduled maintenance) x 100 | >= 95% | Monthly |
| Overdue Maintenance Rate | (Overdue items / Total scheduled items) x 100 | <= 5% | Monthly |
| Vendor Authorization Currency | (Current authorizations / Total active vendors) x 100 | 100% | Quarterly |
| Pre-Maintenance Backup Compliance | (Backups verified before maintenance / Total maintenance events) x 100 | 100% | Monthly |
| Post-Maintenance Verification Rate | (Verification completed / Total maintenance events) x 100 | 100% | Monthly |
| Component Secure Disposal Rate | (Securely disposed components / Total replaced components) x 100 | 100% | Monthly |
| Encryption Preservation Rate | (Encryption maintained / Total maintenance events on encrypted devices) x 100 | 100% | Monthly |
| Equipment Uptime | (Available hours / Total hours) x 100 | >= 99.5% | Monthly |
| Mean Time Between Failures (MTBF) | Average time between equipment failures | Trending upward | Quarterly |
| Mean Time to Repair (MTTR) | Average time to repair after failure | Trending downward | Quarterly |
| Maintenance-Related Security Incidents | Count of security incidents caused by maintenance | 0 | Monthly |
| Corrective Maintenance Ratio | (Corrective maintenance / Total maintenance) x 100 | <= 30% | Quarterly |
| Vendor Escort Compliance | (Escorted vendors in secure areas / Total vendors in secure areas) x 100 | 100% | Monthly |
| Policy Review Cycle Adherence | (Reviews on time / Required reviews) x 100 | 100% | Annually |
| Audit Finding Closure Rate | (Closed findings / Total findings) x 100 | 100% within 60 days | Per audit |
Common Pitfalls and How to Avoid Them
Pitfall 1: Maintenance as an Afterthought
Problem: Maintenance is reactive, not proactive. Equipment fails, then maintenance is called. There is no schedule, no tracking, and no accountability. Solution: Implement a CMMS or ITSM system with automated scheduling. Start with critical equipment and expand. Set maintenance calendars. Assign ownership. Escalate overdue items. Make maintenance a KPI, not an afterthought.
Pitfall 2: "Trusted Vendor" Syndrome
Problem: Vendors who have worked with the organization for years are given unrestricted access without ongoing verification, background checks, or access reviews. Solution: Vet all vendors, regardless of tenure. Require annual re-authorization. Review access rights quarterly. Do not allow vendors to work unsupervised in secure areas. Trust but verify, continuously.
Pitfall 3: No Backup Before Maintenance
Problem: Maintenance is performed without verifying backups, assuming "nothing will go wrong." When something does go wrong, data is lost. Solution: Make pre-maintenance backup verification a mandatory step. Automate backup verification where possible. Include it in the maintenance checklist. Do not allow maintenance to proceed without verified backup. This is non-negotiable.
Pitfall 4: Post-Maintenance Verification Skipped
Problem: After maintenance, equipment is assumed to be "fine" because it powers on. Security settings, data integrity, and configurations are not verified. Solution: Create a post-maintenance verification checklist. Verify functionality, security settings, data integrity, and configurations. Compare against pre-maintenance baselines. Automate verification where possible (e.g., configuration compliance tools). Document verification results.
Pitfall 5: Replaced Components Not Secured
Problem: Failed hard drives, memory, or other components are given to the vendor for disposal or "recycling" without verification of secure destruction. Solution: All replaced components must be returned to the organization. Inventory them. Sanitize or destroy them securely. Obtain certificates of destruction. Do not trust vendors to dispose of components containing your data. This is a direct data protection issue.
Pitfall 6: Maintenance Windows Not Scheduled
Problem: Maintenance is performed during business hours without planning, causing unexpected disruptions, service outages, and user complaints. Solution: Define maintenance windows for different systems. Schedule maintenance during low-impact times. Communicate maintenance windows to stakeholders. Use change management to coordinate. Have rollback procedures. Plan for worst-case scenarios.
Pitfall 7: Insecure Remote Maintenance
Problem: Vendors access equipment remotely for maintenance without proper controls, logging, or supervision. Remote access credentials are shared or not revoked. Solution: Use secure remote access tools (VPN, jump servers, session recording). Limit remote access to specific equipment and time windows. Monitor and record all remote sessions. Require multi-factor authentication. Revoke remote access immediately after maintenance. Do not share credentials.
Pitfall 8: Maintenance Logs Not Maintained
Problem: No records are kept of who performed maintenance, what was done, or what components were replaced. When an incident occurs, there is no audit trail. Solution: Maintain detailed maintenance logs for all equipment. Log who, what, when, where, and why. Use electronic systems to prevent tampering. Retain logs for the required period. Review logs periodically for anomalies. Logs are not just compliance documents, they are security evidence.
Illustrative Scenarios
Illustrative scenario, a composite example for guidance, not a specific Singahi engagement or a verified outcome.
Illustrative Scenario 1: Indian SaaS Company, Maintenance Transformation (Growing company)
Organization: A 350-employee SaaS company in Hyderabad with 200+ servers, 500+ endpoints, and a small data center Challenge: The company had grown rapidly from 50 to 350 employees in 2 years. The IT team was focused on scaling and feature delivery, with maintenance treated as a low priority. Servers were never proactively maintained. A vendor replacing a failed hard drive in a database server was not supervised, did not verify backups, and did not return the failed drive. The failed drive was later found for sale online with recoverable customer data. The company faced a DPDP Act investigation and potential fine. Before State:
- No maintenance policy or schedule
- No vendor vetting process; vendors were hired based on licensing alone
- No maintenance logs; no one could say when a server was last serviced
- No pre-maintenance backup verification
- No post-maintenance verification
- Replaced components were given to vendors for "disposal"
- No CMMS or ITSM system
- Secure area maintenance was unsupervised
Implementation: Month 1: Emergency response to the data breach. Engaged forensic investigators. Notified affected customers. Began remediation. Month 2: Developed and approved equipment maintenance policy. Defined all procedures. Month 3: Implemented Freshservice ITSM for maintenance scheduling, logging, and vendor management. Month 4: Vetted all existing vendors. Terminated 3 vendors who could not meet security requirements. Signed NDAs with all remaining vendors. Month 5: Implemented pre-maintenance and post-maintenance checklists. Enforced backup verification. Month 6: Deployed configuration management tools (Ansible) for automated post-maintenance verification. Month 7: Implemented secure component disposal process with certificates. Month 8: Trained all IT staff and vendors on new procedures. Month 9: Conducted internal audit. Addressed findings.
Results (After 12 Months):
- 100% maintenance schedule compliance for critical equipment
- 100% vendor vetting and authorization coverage
- 100% pre-maintenance backup verification
- 100% post-maintenance verification
- 100% secure component disposal with certificates
- Zero maintenance-related security incidents
- DPDP Act investigation resolved with no fine (demonstrated corrective action)
- Customer trust recovered; only 2% customer churn (vs. projected 15%)
Investment: (ITSM, CMMS, vendor vetting, training, disposal process, forensic investigation) ROI: Avoided DPDP Act fine. The data breach would have overhead an estimated in total (fines, customer compensation, legal, reputation). The maintenance transformation overhead a fraction of that and created a sustainable security practice.
Key Lesson: Maintenance is a security control, not just an operational task. The "failed hard drive" incident was entirely preventable with basic maintenance security procedures. The impact of prevention is always lower than the impact of a breach.
Illustrative Scenario 2: Large Indian Manufacturing Conglomerate, Industrial Equipment Maintenance Standardization
Organization: A manufacturing conglomerate with 12 plants across India, 20,000+ employees, 5,000+ industrial devices including SCADA, PLCs, IoT sensors, and traditional IT Challenge: The conglomerate had grown through decades of organic growth and acquisition. Each plant managed its own maintenance independently. Some plants had excellent preventive maintenance programs; others operated on "fix it when it breaks." An unplanned shutdown at the largest plant (due to a failed PLC that had not been maintained in 3 years) overhead in lost production. A maintenance vendor at another plant replaced a network switch and left the default password active, which was later exploited by an attacker who gained access to the SCADA network. The board mandated standardization of maintenance across all plants within 18 months. Before State:
- 12 plants with completely different maintenance maturity
- No corporate maintenance policy or standards
- 3 plants with no maintenance logs
- Vendor management: ad-hoc, no vetting, no NDAs at 4 plants
- No pre/post maintenance verification at 6 plants
- SCADA and IT maintenance were managed by different teams with no coordination
- No centralized visibility into maintenance status
Implementation: Phase 1 (Months 1–2): Developed corporate maintenance policy and standards for all equipment types (IT, SCADA, industrial, security). Phase 2 (Months 3–4): Assessed all 12 plants. Created maturity scorecards. Prioritized by risk. Phase 3 (Months 5–10): Deployed standardized CMMS (eMaint) across all plants. Implemented maintenance schedules for all 5,000+ devices. Trained plant staff. Phase 4 (Months 11–13): Standardized vendor management. Vetted all vendors. Implemented NDAs and access controls. Implemented escort procedures for secure areas. Phase 5 (Months 14–16): Implemented pre/post maintenance verification. Deployed configuration management for IT and SCADA devices. Implemented secure component disposal. Phase 6 (Months 17–18): Conducted corporate internal audit. All plants passed. Board review.
Results (After 18 Months):
- 100% of plants compliant with corporate maintenance standards
- 5,000+ devices in maintenance scheduling system
- Maintenance schedule compliance: 94% (up from 45%)
- Unplanned downtime due to equipment failure: reduced by 70%
- Vendor authorization: 100% coverage
- Maintenance-related security incidents: zero (down from 2/year)
- PLC and SCADA maintenance: standardized and coordinated with IT
- Estimated savings: /year in avoided downtime and improved efficiency
Investment: (CMMS, vendor vetting, training, configuration management, audit) ROI: The production loss from the PLC failure was prevented from recurring. Standardized maintenance across 12 plants improved operational efficiency and security. The network switch incident would have been prevented by the new verification procedures.
Key Lesson: Industrial and OT (Operational Technology) maintenance is often separated from IT maintenance, creating security gaps. Standardization across a distributed manufacturing enterprise requires strong corporate policy, centralized tools, and local accountability. Maintenance is not just about uptime, it is about security.
Multi-Framework Mapping
ISO 27001:2022 A.7.13 to Other Frameworks
| ISO 27001:2022 A.7.13 | NIST 800-53 Rev 5 | PCI DSS v4.0 | SOC 2 CC6.1 | CIS Controls v8 | COBIT 2019 |
|---|---|---|---|---|---|
| Equipment maintenance | MA-1 (System Maintenance Policy and Procedures) | Req 9.5 (Physical Security of Hardware) | CC6.7 (Physical Security of Systems) | CIS 4.1 (Establish and Maintain a Secure Configuration Process) | DSS05.04 (Manage Physical Security) |
| Vendor management | MA-4 (Nonlocal Maintenance) | Req 9.5 | CC6.7 | CIS 4.6 (Securely Dispose of Assets) | DSS05.04 |
| Data protection during maintenance | MA-2 (Controlled Maintenance) | Req 9.5 | CC6.7 | CIS 4.1 | DSS05.04 |
| Component disposal | MA-2, MA-6 (Timely Maintenance) | Req 9.5 | CC6.7 | CIS 4.6 | DSS05.04 |
NIST 800-53 Rev 5:
- MA-1: System Maintenance Policy and Procedures, Maps to maintenance policy and scheduling
- MA-2: Controlled Maintenance, Maps to authorization, supervision, and data protection during maintenance
- MA-4: Nonlocal Maintenance, Maps to remote maintenance procedures and controls
- MA-6: Timely Maintenance, Maps to maintenance scheduling and compliance
PCI DSS v4.0:
- Requirement 9.5: Physical security of hardware during maintenance, repairs, and disposal
- Requirement 9.6: Physical security of paper media
SOC 2 CC6.7:
- Physical security of systems and facilities, including during maintenance activities
CIS Controls v8:
- CIS Control 4: Secure Configuration of Enterprise Assets, Maintenance preserves secure configurations
- CIS Control 6: Access Control Management, Maintenance personnel access control
- CIS Control 4.6: Securely Dispose of Assets, Component disposal during maintenance
ISO 55000 (Asset Management):
- Provides a complete framework for systematic asset management, including maintenance
- Aligns with ISO 27001 for organizations seeking integrated management systems
Regulatory and Industry Context
India-Specific Regulatory Requirements
Digital Personal Data Protection (DPDP) Act 2023:
- Section 8(5): Data fiduciaries must implement reasonable security safeguards, including during maintenance
- Maintenance activities that expose personal data must be controlled and documented
- Breach notification required within 72 hours if maintenance-related data exposure occurs
Information Technology Act 2000 (as amended):
- Section 43A: Compensation for failure to protect sensitive personal data during maintenance
- Section 72: Breach of confidentiality by maintenance personnel
RBI Cyber Security Framework:
- Maintenance records required for all critical banking infrastructure
- Vendor maintenance of banking systems must be supervised and logged
- Annual cyber audit must include maintenance review
- Maintenance must not compromise security controls or encryption
SEBI Cybersecurity Circular:
- Trading infrastructure maintenance must be documented and supervised
- Maintenance must not introduce vulnerabilities or disable security controls
- Maintenance windows must be planned and communicated
Factories Act, 1948:
- Industrial equipment maintenance must comply with safety and operational standards
- Maintenance records must be maintained for specified equipment
Industry-Specific Context
BFSI:
- RBI mandates maintenance records for ATMs, core banking servers, and security systems
- Vendor maintenance of ATM networks must be supervised and logged
- Maintenance must not compromise ATM encryption or PIN security
- Annual maintenance audit is part of cyber audit
Healthcare:
- Medical device maintenance must comply with Drug Controller and NABH requirements
- Maintenance must not compromise patient data or medical device safety
- Maintenance records are required for accreditation and regulatory compliance
- Life-critical equipment maintenance requires higher standards and documentation
Manufacturing:
- SCADA/ICS maintenance must be coordinated with IT security
- Industrial equipment maintenance must comply with safety standards
- Maintenance must not introduce cybersecurity risks to OT networks
- Predictive maintenance using IoT sensors is increasingly common
Government:
- Classified system maintenance requires security-cleared personnel
- Maintenance of citizen data systems must be documented and supervised
- Maintenance must comply with Ministry of Home Affairs security guidelines
Roles and Responsibilities (RACI)
| Activity | CISO | IT Operations | Facility Mgmt | Security | Asset Owner | Maintenance Vendor |
|---|---|---|---|---|---|---|
| Policy Development | A | R | C | C | C | I |
| Maintenance Scheduling | C | A | C | I | C | I |
| Preventive Maintenance | I | R | R | I | C | R |
| Corrective Maintenance | I | R | R | I | C | R |
| Vendor Vetting | A | C | C | R | I | C |
| Vendor Authorization | A | C | C | R | I | C |
| Maintenance Execution | I | R | R | I | C | R |
| Data Protection (Pre) | C | R | I | C | R | I |
| Data Protection (Post) | C | R | I | C | R | I |
| Secure Disposal | A | R | I | C | I | C |
| Logging and Documentation | C | R | I | I | C | C |
| Change Management | C | A | C | I | C | I |
| Audit and Compliance | A | C | C | R | I | I |
| Continuous Improvement | A | R | C | C | C | I |
Documentation and Evidence Requirements
| Document | Purpose | Retention Period | Owner |
|---|---|---|---|
| Equipment Maintenance Policy | Defines requirements | Duration + 3 years | CISO |
| Maintenance Schedules | Preventive maintenance calendar | Duration + 3 years | IT Operations |
| Maintenance Logs | Activity records | Life of equipment + 3 years | IT Operations |
| Vendor Authorization Records | Vendor approval documentation | Duration + 3 years | Security |
| Vendor NDAs and Agreements | Contractual security requirements | Duration + 3 years | Legal |
| Pre-Maintenance Checklists | Backup and security verification | 1 year | IT Operations |
| Post-Maintenance Checklists | Verification records | 1 year | IT Operations |
| Component Disposal Records | Secure disposal evidence | Duration + 3 years | IT Security |
| Configuration Backups | Pre-maintenance configuration | Duration + 3 years | IT Operations |
| Change Records | Maintenance change documentation | Duration + 3 years | IT Operations |
| Test Results | Maintenance verification | Duration + 3 years | IT Operations |
| Incident Reports | Maintenance-related incidents | Duration + 3 years | Security |
| Audit Checklist and Results | Audit evidence | Duration + 3 years | Internal Audit |
| Risk Assessment | Risk treatment | Duration + 3 years | CISO |
Continuous Improvement
Figure · Tiers
Maturity levels for equipment maintenance
- OptimizedFully automated
- ManagedMetrics-driven; predictive maintenance
- DefinedFull schedules; complete documentation
- DevelopingBasic schedules; some documentation
- InitialReactive maintenance; no schedule
Maturity Model for A.7.13
| Level | Name | Characteristics | Evidence |
|---|---|---|---|
| 1 | Initial | Reactive maintenance; no schedule; no documentation; vendors unvetted | No policy; no logs; no CMMS; ad-hoc fixes |
| 2 | Developing | Basic schedules; some documentation; informal vendor management | Calendar-based scheduling; paper logs; basic vendor contracts |
| 3 | Defined | Full schedules; complete documentation; vetted vendors; verified procedures | CMMS/ITSM; preventive maintenance; vendor NDAs; pre/post verification |
| 4 | Managed | Metrics-driven; predictive maintenance; automated scheduling; vendor performance monitoring | Automated CMMS; predictive analytics; SLA monitoring; trend analysis |
| 5 | Optimized | Fully automated; AI-powered predictive maintenance; self-healing systems; integrated with enterprise systems | IoT-based condition monitoring; AI failure prediction; automated vendor dispatch; zero incidents |
Continuous Improvement Activities
Monthly:
- Maintenance schedule compliance review
- Overdue maintenance escalation and resolution
- Vendor performance review
- Maintenance log review for anomalies
Quarterly:
- Preventive maintenance effectiveness analysis
- Corrective maintenance trend analysis
- Vendor re-authorization and access review
- Internal audit of maintenance controls
- Configuration drift detection
Annually:
- Full policy review
- Complete maintenance program review
- Technology and tool evaluation
- Benchmark against industry standards
- External audit preparation
- Maturity assessment against target level
Trigger-Based:
- After any maintenance-related security incident
- Upon equipment failure that maintenance should have prevented
- Upon vendor contract change or termination
- After significant audit findings
- Upon new equipment technology adoption
FAQ
Q1: What types of equipment need maintenance under A.7.13? A: All information processing equipment: servers, workstations, storage, network devices, security devices, printers, peripherals, and utility equipment (UPS, generators, HVAC). If it processes, stores, or transmits information, it needs maintenance.
Q2: How often should we maintain servers? A: At minimum, monthly preventive maintenance (dust cleaning, log review, temperature check, fan inspection). Quarterly for firmware updates and deep inspection. Annually for complete hardware assessment. Follow manufacturer recommendations (e.g., Dell, HP, Cisco provide specific maintenance schedules). Adjust based on criticality and environment (dusty environments need more frequent cleaning).
Q3: Do we need to supervise all vendor maintenance? A: Supervision is required for all maintenance in secure areas and for all maintenance of sensitive or critical equipment. For routine maintenance of non-critical equipment in general areas, supervision may be reduced to periodic checks rather than continuous escort. However, the vendor must still be authorized, vetted, and their activities logged. Use risk-based judgment: the more sensitive the equipment or data, the more supervision required.
Q4: What if a vendor insists on keeping a failed component for warranty or analysis? A: The vendor can analyze the component on-site or in your presence. If the component must leave the site, the data must be sanitized first (degaussed, wiped, or physically destroyed). If the component cannot be sanitized (e.g., a failed SSD that cannot be erased), document the risk acceptance, require the vendor to sign a data protection agreement, and verify their disposal process. Better yet, choose vendors who do not require component retention.
Q5: How do we maintain equipment in a remote office with no IT staff? A: Use remote monitoring and management (RMM) tools for remote diagnostics and software maintenance. Schedule on-site vendor visits for hardware maintenance. Use cloud-managed devices that can be remotely maintained. Train a local employee (even non-IT) to perform basic tasks (checking lights, rebooting, checking cables). Have a "remote hands" vendor for physical intervention. Ship replacement equipment with pre-configuration for swap-out maintenance.
Q6: What is predictive maintenance and how do we implement it? A: Predictive maintenance uses data (sensor readings, performance metrics, error logs) to predict when equipment will fail, allowing maintenance just before failure. Implementation: (1) Deploy monitoring tools (IPMI, SNMP, SMART, BMS), (2) Collect and analyze data for trends, (3) Set thresholds for intervention, (4) Use AI/ML tools for advanced prediction, (5) Schedule maintenance based on predictions rather than fixed intervals. Predictive maintenance reduces overhead and downtime compared to traditional preventive maintenance.
Q7: How do we handle emergency maintenance when there is no time for backup? A: Emergency maintenance is a risk. If the equipment is failing and immediate action is needed: (1) Assess if the data is already backed up (most organizations have automated backups), (2) If no recent backup, take a quick backup if possible, (3) Document the emergency and why normal procedures could not be followed, (4) After emergency maintenance, perform full verification, (5) Update procedures to prevent similar emergencies. Do not let "emergency" become an excuse for skipping security.
Q8: What about firmware updates? Are they maintenance? A: Yes, firmware updates are maintenance. They are critical for security (firmware often contains security patches). Treat firmware updates as high-priority maintenance: (1) Verify the update is from the manufacturer (checksum verification), (2) Test in a non-production environment first, (3) Have a rollback plan, (4) Schedule during a maintenance window, (5) Verify functionality and security after update, (6) Document the update in the maintenance log. Never apply firmware updates without planning and verification.
Q9: How do we maintain legacy equipment that the manufacturer no longer supports? A: Legacy unsupported equipment is a security risk. Options: (1) Replace with modern equipment, (2) If replacement is not possible, implement compensating controls (air-gap, additional monitoring, restricted access), (3) Maintain the equipment yourself using available documentation and spare parts, (4) Consider third-party maintenance vendors who specialize in legacy equipment, (5) Document the risk and accept it with management approval. Legacy equipment should be on a retirement plan, do not let it become permanent.
Q10: What is the most common audit finding for A.7.13? A: Incomplete maintenance records and lack of vendor management. Auditors will check: Are maintenance schedules documented? Are they being followed? Are maintenance logs complete? Are vendors vetted? Are components securely disposed of? The most common failure is having no evidence of maintenance, no logs, no schedules, no vendor records.
Q11: Do we need to maintain employee personal devices (BYOD)? A: BYOD devices used for work should be included in maintenance policy, but the organization typically cannot perform physical maintenance on personal devices. Instead: (1) Require employees to keep devices updated and patched, (2) Use MDM to enforce security updates, (3) Include device maintenance requirements in BYOD policy, (4) Prohibit use of unsupported or unmaintained devices for work. The organization maintains control over what devices can access corporate data, even if it does not maintain the devices themselves.
Q12: How do we track maintenance for equipment in the cloud? A: Cloud infrastructure (IaaS, PaaS) maintenance is typically the provider's responsibility for the underlying hardware. However, the organization is responsible for: (1) VM and application maintenance, (2) Configuration management, (3) Security patching, (4) Monitoring and alerting. Use cloud-native tools (AWS Systems Manager, Azure Update Manager, Google Cloud OS Patch Management) to schedule and track maintenance. Include cloud maintenance in your CMDB/ITSM. Verify cloud provider maintenance windows and security practices via SOC 2 reports and audit rights.
Q13: How much does implementing A.7.13 overhead for a growing company? A: For a 200-person company with 300+ devices: CMMS/ITSM (–/year), vendor vetting (–), training (–), configuration management tools (–), secure disposal process (–). Total: –/year. The primary overhead is the CMMS/ITSM system and the time to implement disciplined processes.
Q14: Can we use the same maintenance vendor for all equipment? A: Using a single vendor is simpler but creates risk: vendor lock-in, single point of failure, and potential compromise if the vendor is breached. Best practice: use multiple vendors for different equipment types (one for servers, one for network, one for facilities). Ensure all vendors meet your security standards. Diversify to reduce risk while maintaining efficiency.
Q15: What is the difference between maintenance and repair? A: Maintenance is proactive (preventive, predictive) or scheduled (corrective). Repair is reactive, fixing something that has already broken. ISO 27001 A.7.13 covers both. The goal is to move from reactive repair to proactive maintenance. Proactive maintenance reduces failures, improves security, and provides better audit evidence.
Industry-Specific Maintenance Requirements
Banking and Financial Services (BFSI)
RBI Cyber Security Framework Requirements:
- Critical Systems: Core banking, RTGS, NEFT, UPI infrastructure, maintenance windows must be pre-approved by RBI with minimum 72-hour notice
- ATM Maintenance: Monthly physical inspection, quarterly security audit, annual penetration testing. ATM service personnel must be background-verified.
- Patch Management: Critical security patches applied within 48 hours of release. Non-critical patches within 2 weeks. RBI may conduct spot checks.
- Maintenance Windows: Scheduled during non-business hours (post 8 PM IST, pre 8 AM IST). Emergency maintenance requires RBI notification within 2 hours.
- Vendor Access: Maintenance vendors must sign NDAs, undergo background checks, and be escorted during facility visits. All vendor activity logged.
BFSI Maintenance Schedule:
| System | Preventive Maintenance | Vendor Security Review | Patch Cycle | Documentation |
|---|---|---|---|---|
| Core Banking | Weekly health checks | Quarterly | 48 hours (critical) | Full audit trail |
| ATM Network | Monthly physical | Quarterly | 72 hours | Vendor logs + CCTV |
| Trading Platform | Daily checks | Quarterly | 24 hours | Change records |
| UPI Infrastructure | 24/7 monitoring | Monthly | 24 hours | NPCI compliance |
| Data Center | Daily rounds | Quarterly | 48 hours | DCIM records |
Healthcare
NABH and Medical Device Requirements:
- Medical Equipment: Calibration and maintenance per manufacturer specifications. FDA/CDSCO requirements for imported devices.
- Patient Monitoring Systems: ICU monitors, ventilators, and life-support equipment require daily functional checks and annual preventive maintenance by certified technicians.
- PACS and Imaging: MRI, CT, and X-ray equipment require specialized maintenance (often by OEM only). Downtime must be minimized through scheduled maintenance.
- IoT Medical Devices: Smart beds, infusion pumps, and wearable monitors require firmware updates and security patches. Many devices cannot be patched easily, plan for compensating controls.
- Vendor Qualification: Medical device maintenance vendors must be authorized by the manufacturer. Unauthorized maintenance voids warranty and may violate regulations.
Healthcare Maintenance Risks:
- WannaCry 2017: NHS UK was hit by WannaCry ransomware, affecting 80,000 computers and 19,000 appointments. Many systems were unpatched Windows XP. The lesson: legacy medical systems must be maintained or isolated.
- MRI Quench Incidents: Improper maintenance of MRI cooling systems can lead to helium quench, causing equipment damage and patient safety risks. Only certified technicians should maintain MRI equipment.
Government and Critical Infrastructure
NCIIPC and MeitY Requirements:
- Critical Infrastructure: Power, telecom, transport, and banking infrastructure must have maintenance contracts with SLAs for response time and resolution time.
- Air-Gapped Systems: Maintenance of air-gapped systems requires special procedures: sanitized media, escorted personnel, and no external devices. Maintenance must be documented in a physical logbook.
- Defense Equipment: Maintenance of defense IT systems follows strict protocols (armed forces technical manuals). Civilians require security clearance.
- Election Equipment: EVMs and VVPATs require pre-election and post-election maintenance. Maintenance personnel must be election commission officials or authorized vendors.
- SCADA/ICS: Industrial control systems require specialized maintenance. IT patches cannot be applied to OT systems without testing. Use dedicated OT maintenance teams.
IT/ITeS and SaaS
Cloud Infrastructure Maintenance:
- Shared Responsibility: Cloud provider maintains physical infrastructure (AWS, Azure, GCP). Customer maintains VMs, applications, and configurations.
- Maintenance Notifications: Cloud providers announce maintenance windows 7-30 days in advance. Plan for instance migrations and zone failovers.
- Auto-Patching: Use managed services (AWS RDS, Azure SQL, Google Cloud SQL) to offload patch management to the provider.
- Container Maintenance: Docker images, Kubernetes clusters, and serverless functions require regular updates. Use CI/CD pipelines to automate container rebuilds with latest patches.
- Dev/Test/Prod: Maintenance in production requires strict change control. Development environments can be more flexible but should still be maintained.
Manufacturing and Industrial
OT/IT Maintenance Convergence:
- Separate Teams: OT maintenance (PLC, SCADA, DCS) and IT maintenance (servers, networks) should be separate but coordinated.
- Change Control: Any IT change affecting OT (network reconfiguration, firewall rule) must be tested in a non-production environment first.
- Vendor Lock-In: Manufacturing equipment often requires OEM maintenance due to proprietary software. Negotiate maintenance contracts with security requirements included.
- Production Downtime: Maintenance windows must align with production schedules. Many factories run 24/7, making maintenance windows rare and precious.
Maturity Model for A.7.13
| Level | Name | Maintenance Approach | Tools | Documentation | Vendor Management |
|---|---|---|---|---|---|
| 1 | Initial | Reactive (break-fix) | None | Ad hoc | No vetting |
| 2 | Managed | Scheduled preventive | Spreadsheet | Basic logs | Basic contracts |
| 3 | Defined | Preventive + predictive | CMMS/ITSM | Full SOPs | Security clauses |
| 4 | Quantitative | Predictive + automated | CMMS + analytics | Automated reports | Continuous monitoring |
| 5 | Optimized | AI-driven, self-healing | AI/ML platform | Real-time dashboards | Integrated risk management |
Progression Guidance:
- Level 1 → 2: Implement scheduled maintenance, basic CMDB, and maintenance contracts. (Investment: -5 lakhs)
- Level 2 → 3: Deploy CMMS/ITSM, add security vetting to vendor contracts, implement full documentation. (Investment: -15 lakhs)
- Level 3 → 4: Add predictive maintenance, automated monitoring, and continuous vendor assessment. (Investment: -30 lakhs)
- Level 4 → 5: Implement AI-driven maintenance, self-healing systems, and integrated risk management. (Investment: + lakhs)
Additional FAQ
Q16: How do we handle maintenance for legacy equipment that vendors no longer support? A: Legacy equipment is a common challenge. Options: (1) Extended support contracts (premium-tier but available), (2) Third-party maintenance providers (ensure security vetting), (3) Upgrade/replacement (best long-term solution), (4) Compensating controls (network isolation, enhanced monitoring, strict access controls). Document the risk and obtain management acceptance. Plan for replacement within a defined timeline.
Q17: What is predictive maintenance and how does it improve security? A: Predictive maintenance uses sensors, IoT, and analytics to predict equipment failures before they occur. It improves security by: (1) Reducing unexpected failures that create vulnerabilities, (2) Enabling planned maintenance windows with proper security controls, (3) Identifying anomalies that may indicate tampering or cyber-physical attacks, (4) Optimizing equipment lifespan to reduce emergency replacements. Typical tools: vibration analysis, thermal imaging, oil analysis, and electrical signature analysis.
Q18: How do we maintain security during vendor maintenance visits? A: Implement a vendor access protocol: (1) Pre-visit notification and approval, (2) Background check verification, (3) Escorted access at all times, (4) Signed NDA and security briefing, (5) Restricted network access (guest WiFi only), (6) Tool and device inspection (no unauthorized USB drives, cameras), (7) Activity logging (what was accessed, what was changed), (8) Post-visit review and sign-off. Use temporary badges that expire automatically.
Q19: How do we balance maintenance overhead with security requirements? A: Prioritize based on risk: critical systems (core banking, patient monitors) get the highest maintenance priority and budget. Use risk assessment to justify spending. Consider vendor support (overall value), cheap equipment with poor maintenance overhead more in the long run. Use leasing or managed service models to convert CapEx to OpEx. Group maintenance contracts for volume discounts. Negotiate SLAs that include security requirements at no extra overhead.
Q20: How do we document maintenance for ISO 27001 audit evidence? A: Maintain these records: (1) Equipment inventory with maintenance schedules, (2) Maintenance contracts with security clauses, (3) Vendor vetting records, (4) Maintenance logs (date, technician, work performed, parts replaced), (5) Test results after maintenance, (6) Patch management records, (7) Configuration change records, (8) Security review records after maintenance, (9) Incident records related to maintenance failures, (10) Management review of maintenance program. Store for at least 3 years (or longer per regulatory requirements).
Illustrative Scenario: Bangalore IT Company, Maintenance Failure to Security Incident
Background
A 500-employee software company in Bangalore outsourced server maintenance to a third-party vendor. The vendor had access to the server room, performed quarterly maintenance, and replaced faulty hardware. The company had no formal vendor vetting process, no escort requirements, and no activity logging.
The Incident
In January 2025, a maintenance technician (contracted through the vendor) installed a hardware monitoring tool on three production servers. The tool was legitimate but was downloaded from an unofficial source and contained a backdoor. The backdoor allowed remote access to the servers, which the attacker used to exfiltrate customer data over 6 weeks. The breach affected 12,000 customer records, including names, email addresses, and partial payment data.
Root Cause Analysis
- No Vendor Vetting: The vendor was selected based on licensing alone. No background checks, no security questionnaire, no reference verification.
- Unescorted Access: The technician was given unsupervised access to the server room during after-hours maintenance.
- No Device Inspection: The technician's laptop and USB drives were not inspected. The unauthorized software was installed via USB.
- No Activity Logging: The company had no logs of what the technician did during the maintenance window. The backdoor installation was not detected until the data exfiltration triggered a DLP alert.
- No Post-Maintenance Review: After maintenance, no one verified what was changed or installed. The backdoor persisted for 6 weeks.
Impact
- Data Exfiltration: 12,000 customer records stolen and sold on dark web forums
- Regulatory: DPDP Act 2023 violation notice, potential fine of s
- Customer Notification: Mandatory breach notification to affected customers and the Data Protection Board
- Reputational: Customer churn increased 18%, new sales dropped 30% for 2 quarters
- Legal: Class action lawsuit filed by affected customers
- Total overhead: s (fines, legal, notification, remediation, lost business)
Remediation
After the incident, the company implemented a complete maintenance security program:
- Vendor Vetting: All maintenance vendors now undergo security questionnaires, background checks, and reference verification. Contracts include security clauses and liability for breaches caused by vendor actions.
- Escorted Access: All vendor personnel are escorted by an internal employee at all times. No unsupervised access to critical areas.
- Device Inspection: All vendor devices (laptops, USB drives, tools) are inspected before and after maintenance. Unauthorized devices are prohibited.
- Activity Logging: Maintenance activities are logged in real-time. Network monitoring captures all traffic during maintenance windows. Screen recording is used for remote maintenance sessions.
- Post-Maintenance Review: Every maintenance session is followed by a security review: verify installed software against approved list, scan for malware, review configuration changes, and sign off.
- Network Segmentation: Vendor maintenance is performed on an isolated VLAN with no access to production data. Remote access is through a bastion host with MFA and session recording.
- Incident Response: The company developed a maintenance-specific incident response playbook. Maintenance windows are treated as high-risk periods with enhanced monitoring.
Key Lessons
- Trust but Verify: Even trusted vendors can be compromised. Always verify vendor actions.
- Maintenance Windows are High-Risk: The time when external personnel have physical access is the most vulnerable period. Implement enhanced controls during maintenance.
- Log Everything: Without logs, you cannot detect, investigate, or prove what happened. Logging is essential for both security and compliance.
- Vendor Security is Your Security: A vendor breach is your breach. Vendor security standards must match your own.
- Post-Maintenance Verification: Always verify what was done. The impact of verification is minimal compared to the impact of a breach.
Maintenance Security Metrics and KPIs
| Metric | Formula | Target | Frequency |
|---|---|---|---|
| Preventive Maintenance Completion Rate | (Completed PM tasks / Scheduled PM tasks) × 100 | > 95% | Monthly |
| Mean Time Between Failures (MTBF) | Total operational hours / Number of failures | Increasing | Quarterly |
| Vendor Security Score | (Vendors meeting security standards / Total vendors) × 100 | 100% | Quarterly |
| Maintenance-Related Incidents | Number of security incidents caused by maintenance | 0 | Monthly |
| Patch Compliance Rate | (Systems patched on time / Total systems) × 100 | > 98% | Monthly |
| Vendor Access Reviews | Number of vendor access reviews conducted | All vendors reviewed | Quarterly |
| Equipment Uptime | (Total uptime / Total time) × 100 | > 99.5% | Monthly |
| Maintenance overhead per Asset | Total maintenance overhead / Number of assets | Optimized | Quarterly |
| Post-Maintenance Verification Rate | (Verified maintenance sessions / Total sessions) × 100 | 100% | Monthly |
| Legacy Equipment Risk Score | Risk rating of unsupported equipment | Decreasing | Quarterly |
References and Further Reading
Standards and Frameworks
- ISO/IEC 27001:2022, Information Security, Cybersecurity and Privacy Protection, Information Security Management Systems, Requirements
- ISO/IEC 27002:2022, Information Security, Cybersecurity and Privacy Protection, Information Security Controls
- NIST SP 800-53 Rev 5, Security and Privacy Controls for Information Systems and Organizations
- ISO 55000, Asset Management, Overview, Principles and Terminology
- PCI DSS v4.0, Payment Card Industry Data Security Standard
- CIS Controls v8, CIS Controls Version 8
Indian Regulations
- Digital Personal Data Protection Act, 2023 (India)
- Information Technology Act, 2000 (as amended)
- RBI Cyber Security Framework for Banks
- SEBI Circular CIR/ISD/2019 on Cyber Security and Cyber Resilience
- Factories Act, 1948 (India)
Books and Publications
- ISO 27001/27002: A Pocket Guide by Alan Calder
- The Security Handbook by Gerald L. Kovacich and Edward Halibozek
- Maintenance Engineering Handbook by Lindley R. Higgins
Indian Regulatory Context for Cabling Security
India's diverse operating conditions make cabling security a practical concern beyond the data center. Tropical monsoons, rodents and unauthorized digging frequently damage outdoor cables, causing outages for banks, telecom providers and IT parks. The Indian Telegraph Act, 1885 and Telecommunication Act, 2023 impose penalties for damage to telecom infrastructure, including underground fiber. The Factories Act, 1948 requires safe installation of electrical and communication cabling in manufacturing premises. For organizations handling personal data, the DPDP Act 2023 treats cable tapping or exposed cabling that leads to unauthorized access as a potential personal data breach, triggering Section 8(6) intimation obligations. Singahi recommends that Indian organizations use armored fiber for outdoor runs, maintain accurate cable route maps, coordinate with local municipalities for road-digging permits, and conduct quarterly physical inspections of cable trays and manholes.