Skip to content
Singahi

Compliance · guide

ISO 27001 A.7.13: Equipment Maintenance

44 min read

Share
On this page

Quick Reference (60 Seconds)

Figure · At a glance

A.7.13 at a glance

Control ID
A.7.13
Control Name
Equipment Maintenance
ISO 27002:2022 Section
7.13
Primary Purpose
Ensure equipment is maintained to preserve
Key Activities
Schedule maintenance
Typical Owners
IT Operations, Facility Management
The essentials before reading further. The full reference table follows.
AspectSummary
Control IDA.7.13
Control NameEquipment Maintenance
ISO 27002:2022 Section7.13
Primary PurposeEnsure equipment is maintained to preserve information integrity, availability, and security
Key ActivitiesSchedule maintenance, perform authorized maintenance only, protect data during maintenance, verify integrity after maintenance
Typical OwnersIT Operations, Facility Management, Asset Management
Implementation EffortMedium (4–8 weeks)
Main cost driversMaintenance contracts (IT and facilities), a maintenance schedule and log (often in the ITSM tool), escorts for on-site work, and data protection for equipment sent away
ISO 27002 attributesControl type: Preventive · Properties: Confidentiality, Integrity, Availability · Concepts: Protect · Capabilities: Physical security, Asset management · Domains: Protection, Resilience

Bottom Line: Equipment maintenance is not just about keeping things running, it is about ensuring that maintenance activities do not introduce security vulnerabilities, data loss, or unauthorized access. Proper maintenance preserves both availability and security.


What the Control Asks For

In short:

ISO 27001:2022 Annex A 7.13 asks organizations to maintain equipment properly to keep information available and intact.

Do you need this control?

A.7.13 is not mandatory in itself: under clause 6.1.3 you include it if your risk assessment calls for it, and record the decision in your Statement of Applicability. Include it if you own equipment that needs maintenance. It matters most where maintenance staff could access sensitive data, such as servers, storage and medical or industrial devices.

What ISO 27002:2022 Adds

27002 7.13 (paraphrased) suggests:

  • (a) maintaining equipment to the supplier's recommended service intervals and specifications
  • (b) an organisation-run maintenance programme that is monitored
  • (c) only authorised maintenance personnel carrying out repairs and maintenance
  • (d) records of all suspected or actual faults and of all preventive and corrective maintenance
  • (e) controls suited to whether maintenance is on site or external, with maintenance personnel under a suitable confidentiality agreement
  • (f) supervising maintenance personnel on site
  • (g) authorising and controlling remote maintenance access
  • (h) applying off-premises protections (7.9) when equipment holding information leaves for maintenance
  • (i) complying with maintenance requirements set by insurance policies
  • (j) inspecting equipment before it returns to operation to make sure it has not been tampered with and works correctly
  • (k) applying secure disposal or re-use (7.14) when equipment is to be disposed of

27002 notes that "equipment" includes information processing components and supporting facilities: UPS and batteries, generators, alternators and converters, physical intrusion detection systems and alarms, smoke detectors, fire extinguishers, air conditioning and lifts. Many pages treat maintenance as an IT-only topic; auditors also ask about the facilities kit.

Why Equipment Maintenance Matters

The Maintenance-Security Connection

Maintenance is often viewed as an operational activity separate from security. In reality, maintenance activities create significant security exposure: maintenance personnel have physical access to equipment, may bypass security controls, and may inadvertently or intentionally compromise data.

Typical Ways Maintenance Goes Wrong

Third-party involvement is common in breaches: the Verizon DBIR 2025 found a third party involved in 30% of breaches (that covers all suppliers, not only maintenance). Hypothetical maintenance-specific patterns:

  • A technician resets firmware settings and silently disables disk encryption or Secure Boot.
  • A vendor keeps a failed drive that still holds readable data.
  • A firmware update applied without testing takes down network switches.
  • Nobody can say which vendor had access to a system during an incident, because no log was kept.
  • Remote support access is left permanently open "for convenience".

Regulatory and Business Drivers

  • DPDP Act 2023: reasonable security safeguards (s.8(5)) apply while equipment is maintained, and processor contracts (s.8(2)) cover vendors who handle personal data
  • Sector regulators (RBI IT Outsourcing Master Direction 2023, SEBI CSCRF 2024, IRDAI 2023) expect regulated entities to control vendor access and keep records
  • PCI DSS v4.0.1 9.5.1.2 asks for periodic inspection of point-of-interaction devices for tampering, including after maintenance
  • SOC 2 CC6.4 and CC7.1 cover physical access and detecting unauthorised changes
  • ISO 55000 (Asset Management) provides a framework for systematic equipment maintenance

Scope and Applicability

What Is Covered

  • All information processing equipment (servers, workstations, storage, network devices)
  • All peripheral equipment (printers, scanners, kiosks, ATMs)
  • All security equipment (firewalls, IDS/IPS, CCTV, access control systems)
  • All utility equipment (UPS, generators, HVAC, fire suppression)
  • All cabling infrastructure (patch panels, switches, routers)
  • All mobile and endpoint devices (laptops, tablets, smartphones)
  • All maintenance activities, whether performed by internal staff or external vendors

What Is Not Covered

  • Non-IT equipment not associated with information processing (e.g., general office furniture, kitchen appliances)
  • Personal devices not used for work (though BYOD policies may extend coverage)

Applicability by Organization Type

Organization TypeApplicabilityKey Maintenance Concerns
IT/Software ServicesHighServer farms, dev environments, network infrastructure, cloud hardware
BFSICriticalATMs, core banking servers, trading infrastructure, security systems
HealthcareCriticalMedical devices, patient record systems, imaging equipment, life support IT
ManufacturingHighSCADA/ICS systems, production control servers, IoT devices
Government/DefenseCriticalClassified systems, citizen data servers, secure communications
EducationMediumCampus networks, lab equipment, student systems, research compute
SaaS/CloudCriticalData center infrastructure, customer-facing servers, network equipment
Retail/E-commerceHighPOS systems, inventory servers, payment terminals, warehouse automation

Key Definitions and Terminology

TermDefinition
Preventive MaintenanceScheduled maintenance activities designed to prevent equipment failures before they occur
Corrective MaintenanceMaintenance performed in response to an equipment failure or malfunction
Predictive MaintenanceMaintenance based on condition monitoring and data analysis to predict when maintenance is needed
Authorized MaintenanceMaintenance performed by personnel who have been approved and authorized by the organization
Maintenance WindowA scheduled period of time during which maintenance activities are performed, typically with reduced service impact
Change ManagementA formal process for managing changes to IT systems, including maintenance-related changes
Service Level Agreement (SLA)A contract between the organization and a maintenance vendor defining response times, service levels, and responsibilities
Mean Time Between Failures (MTBF)The average time between equipment failures, used to schedule preventive maintenance
Mean Time to Repair (MTTR)The average time required to repair equipment after a failure
FirmwareSoftware embedded in hardware devices that controls their operation
BIOS/UEFIThe firmware interface between a computer's hardware and its operating system
SanitizationThe process of removing data from equipment before disposal or repurposing
Spare Parts InventoryA stock of critical components kept on-site to minimize repair time
Maintenance LogA record of all maintenance activities performed on a piece of equipment

Relationship to Other Controls

ControlRelationship
A.5.9 Inventory of information and other assetsMaintenance must be tracked against the asset inventory
A.5.33 Protection of recordsMaintenance records must be protected
A.7.2 Physical entry controlsMaintenance personnel require controlled access to equipment areas
A.7.6 Working in secure areasMaintenance in secure areas requires additional controls
A.7.8 Equipment siting and protectionEquipment siting affects maintenance accessibility and safety
A.7.11 Supporting utilitiesUtility maintenance is essential for equipment operation
A.7.14 Secure disposal or re-use of equipment27002 7.13(k): apply when equipment is disposed of
A.7.9 Security of assets off-premises27002 7.13(h): equipment sent away for repair
A.5.19–A.5.22 Supplier relationshipsMaintenance vendors are suppliers
A.8.8 Management of technical vulnerabilitiesFirmware and patch maintenance
A.8.32 Change managementMaintenance windows and changes
A.8.1 User endpoint devicesEndpoint devices require maintenance and patch management
A.8.9 Configuration managementMaintenance may change configurations; must be managed
A.8.13 Information backupBackups before maintenance protect against data loss
A.5.14 Information transferMaintenance may involve data transfer for remote support
A.8.24 Use of cryptographyMaintenance must not disable or compromise encryption
A.8.25 Secure development life cycleMaintenance may involve software updates and patches
A.5.29 Information security during disruptionMaintenance windows are planned disruptions that must be managed

Implementation Roadmap (Week-by-Week)

Week 1: Equipment Inventory and Maintenance Assessment

  • Inventory all equipment requiring maintenance
  • Identify manufacturer maintenance recommendations for each asset
  • Review current maintenance practices and identify gaps
  • Identify all maintenance vendors and contracts
  • Assess maintenance personnel authorization and training
  • Review maintenance records and documentation quality
  • Identify critical equipment with no maintenance plan

Week 2: Policy and Procedure Development

  • Draft equipment maintenance policy
  • Define maintenance scheduling standards (preventive, predictive, corrective)
  • Define authorization requirements for internal and external maintenance personnel
  • Create maintenance procedures for different equipment types
  • Define data protection requirements during maintenance
  • Create maintenance logging and documentation standards
  • Define post-maintenance verification requirements
  • Create maintenance window and change management procedures

Week 3: Maintenance Scheduling System Implementation

  • Implement maintenance scheduling system (CMMS, ITSM, or calendar-based)
  • Create maintenance schedules for all equipment based on manufacturer recommendations and criticality
  • Define maintenance windows (low-impact times for different systems)
  • Set up automated reminders and escalations for overdue maintenance
  • Create maintenance calendar and communicate to stakeholders
  • Integrate maintenance scheduling with change management

Week 4: Vendor Management and Authorization

  • Vet all maintenance vendors (security background, insurance, certifications)
  • Establish SLAs with all maintenance vendors
  • Create vendor access procedures (escort, badging, access limitations)
  • Require NDAs and security agreements for all external maintenance vendors
  • Create vendor performance monitoring process
  • Define vendor authorization and de-authorization procedures

Week 5: Data Protection During Maintenance

  • Create pre-maintenance checklist (backup verification, data protection measures)
  • Define data handling requirements for maintenance personnel (no data removal, no photography, etc.)
  • Create post-maintenance verification checklist (functionality, security settings, data integrity)
  • Define requirements for maintenance of encrypted devices (key management, decryption procedures)
  • Create procedures for maintenance involving component replacement (hard drives, memory, etc.)
  • Define secure disposal requirements for components replaced during maintenance

Week 6: Maintenance Execution and Logging

  • Perform first scheduled maintenance using new procedures
  • Log all maintenance activities in the maintenance system
  • Document any issues, deviations, or lessons learned
  • Verify post-maintenance functionality and security
  • Collect feedback from maintenance personnel and equipment owners
  • Refine procedures based on practical experience

Week 7: Training and Communication

  • Train all IT staff on maintenance procedures and documentation
  • Train all maintenance vendors on organizational requirements
  • Create quick reference guides for common maintenance tasks
  • Communicate maintenance windows and schedules to all stakeholders
  • Train security staff on maintenance monitoring and incident response
  • Create maintenance awareness materials for general staff

Week 8: Audit and Validation

  • Conduct internal audit of maintenance controls
  • Verify all equipment has maintenance schedules
  • Verify all maintenance is being logged and documented
  • Verify post-maintenance verification is occurring
  • Verify vendor authorization and access controls
  • Prepare documentation for external audit
  • Plan for continuous improvement

Detailed Implementation Guidance

Maintenance Types and Scheduling

Preventive Maintenance (PM):

Equipment TypePM FrequencyTypical Activities
ServersMonthlyDust cleaning, fan inspection, temperature check, log review, firmware check
Storage arraysMonthlyHealth check, SMART review, cache battery check, firmware update
Network switchesQuarterlyPort inspection, firmware update, configuration backup, log review
FirewallsQuarterlyRule review, firmware update, log review, performance check
UPSMonthlyBattery test, voltage check, fan inspection, alarm test
GeneratorMonthlyStart test, fuel check, coolant check, battery check
HVACQuarterlyFilter replacement, coil cleaning, refrigerant check, airflow check
PrintersMonthlyCleaning, consumable check, firmware update, security setting review
Laptops/WorkstationsQuarterlyDisk cleanup, malware scan, patch check, physical inspection
CCTVQuarterlyCamera cleaning, lens check, recording review, storage check
Access controlQuarterlyReader test, card check, log review, backup test
Fire suppressionAnnuallyDetector test, suppression test, pressure check, inspection certificate

Predictive Maintenance (PdM):

  • Use sensor data and analytics to predict failures before they occur
  • Monitor: temperature trends, vibration, power consumption, error rates, performance degradation
  • Use tools: IPMI, SNMP monitoring, SMART data, BMS/DCIM analytics, AI-powered prediction
  • Schedule maintenance based on predicted failure probability, not fixed intervals

Corrective Maintenance (CM):

  • Respond to failures, alarms, or detected issues
  • Document root cause for all corrective maintenance
  • Analyze trends to identify systemic issues
  • Update preventive maintenance schedules based on corrective findings

Maintenance Personnel Authorization

Internal Maintenance Staff:

  • Must be employees with appropriate technical skills and certifications
  • Must have background verification completed
  • Must sign confidentiality and security agreements
  • Must be trained on organizational security policies and maintenance procedures
  • Must have access rights limited to the equipment they maintain
  • Must be supervised when working in secure areas

External Maintenance Vendors:

  • Must be security-vetted before engagement (background checks, financial checks, reference checks)
  • Must sign NDAs and security agreements
  • Must provide proof of insurance and certifications
  • Must be escorted when working in secure areas (unless pre-approved and security-cleared)
  • Must have access limited to the specific equipment being maintained
  • Must not be left unattended with equipment containing sensitive data
  • Must return all replaced components to the organization (for secure disposal)
  • Must not photograph, record, or remove data from equipment

Authorization Process:

  1. Vendor/staff submits application with credentials, certifications, and references
  2. Security team conducts background verification
  3. Legal/Procurement reviews and signs NDA/security agreement
  4. IT Operations reviews technical qualifications
  5. CISO or designated authority approves authorization
  6. Authorization is time-limited (typically 1 year, renewable)
  7. Authorization is revoked immediately upon contract termination or security incident
  8. Authorized list is reviewed quarterly

Data Protection During Maintenance

Pre-Maintenance Checklist:

StepActionResponsibility
1Verify recent backup of all data on the equipmentIT Operations
2Verify backup integrity (restore test if possible)IT Operations
3Document current security settings (encryption, authentication, access controls)IT Security
4Remove or secure sensitive data if maintenance does not require access to itData Owner
5Disable remote access and network connectivity if not required for maintenanceIT Security
6Assign maintenance escort for secure areasSecurity
7Verify maintenance personnel authorizationSecurity
8Brief maintenance personnel on data protection requirementsIT Operations
9Record maintenance start time and personnel in maintenance logIT Operations

During Maintenance:

RequirementDescription
No data removalMaintenance personnel must not remove data, media, or components containing data without authorization
No photography/recordingPhotography, video recording, or audio recording of equipment, screens, or documents is prohibited without authorization
SupervisionMaintenance in secure areas must be supervised by an authorized employee
Access limitationMaintenance personnel must only access the specific equipment being maintained
Tool controlPersonal tools may be subject to inspection; organization may provide approved tools
Network isolationEquipment under maintenance should be isolated from production networks if possible
Encryption preservationMaintenance must not disable, bypass, or compromise encryption without authorization and documentation

Post-Maintenance Checklist:

StepActionResponsibility
1Verify equipment powers on and functions correctlyIT Operations
2Verify all security settings are restored (encryption, authentication, access controls)IT Security
3Verify network connectivity and security configurationsIT Security
4Verify data integrity (checksums, database consistency, file integrity)IT Operations
5Verify no unauthorized software or configurations were installedIT Security
6Collect all replaced components for secure disposal or inventoryIT Operations
7Verify maintenance area is cleared and secureSecurity
8Record maintenance completion, activities performed, and verification resultsIT Operations
9Close change request and maintenance ticketIT Operations

Component Replacement and Sanitization

Hard Drive Replacement:

  • Failed hard drives must be returned to the organization, not retained by the vendor
  • Failed hard drives must be sanitized (degaussed or physically destroyed) before disposal
  • New hard drives must be encrypted before data is written (if encryption is required)
  • RAID rebuild must be monitored and verified after replacement
  • Data must be restored from backup if the failed drive was not in a redundant array

Memory Replacement:

  • Memory modules may retain data for a short period after power loss
  • For sensitive environments, memory must be cleared before removal (power off, wait, discharge)
  • Replaced memory modules should be inventoried and securely disposed of if faulty

Motherboard/BIOS Replacement:

  • BIOS settings must be documented before replacement
  • TPM/encryption keys must be backed up or recovered if the motherboard contains the TPM
  • Secure boot settings must be reconfigured after replacement
  • BitLocker recovery keys must be available if the motherboard is replaced

Network Component Replacement:

  • Configuration must be backed up before replacement
  • New component must be configured with the same security settings as the old one
  • Firmware must be updated to the latest secure version
  • Default passwords must be changed immediately
  • Component must be tested for proper security operation before being placed into production

Maintenance in Secure Areas

Additional Requirements for Secure Areas:

  • Maintenance personnel must be escorted at all times
  • Maintenance personnel must surrender personal devices (phones, cameras) before entering
  • Maintenance must be scheduled during supervised hours
  • Security personnel must be present during maintenance of security-critical equipment (firewalls, access control, CCTV)
  • All tools and equipment brought into secure areas must be inspected and logged
  • All replaced components must be inspected and logged before leaving the secure area
  • Maintenance activities must be recorded in the secure area access log

Tools, Technologies, and Solutions

Computerized Maintenance Management Systems (CMMS)

VendorProductKey FeaturesPricing model
FiixCMMSCloud-based, preventive maintenance, reportingCommercial
UpKeepCMMSMobile-first, work orders, asset managementCommercial
Hippo CMMSCMMSEasy to use, preventive maintenance, vendor managementCommercial
eMaintCMMSEnterprise, complete, integrationCommercial
Limble CMMSCMMSGrowing companies, intuitive, mobileCommercial

IT Service Management (ITSM) Tools with Maintenance

VendorProductKey FeaturesPricing model
ServiceNowITSMEnterprise, complete, CMDB, change managementCommercial
FreshserviceITSMGrowing companies, asset management, CMDB, change managementCommercial
ManageEngineServiceDesk PlusIndian market, efficient, ITSM, asset managementCommercial
Jira Service ManagementITSMDevelopment-focused, agile, integrationCommercial

Remote Maintenance and Monitoring Tools

VendorProductKey FeaturesPricing model
SolarWindsNPM/SAMNetwork and server monitoring, remote diagnosticsCommercial
NagiosNagios XIOpen-source monitoring, alerting, remote checksFree or Commercial
PRTGPRTG Network MonitorComplete monitoring, remote probesCommercial
DatadogInfrastructure MonitoringCloud-native, AI-powered, predictive analyticsCommercial
ZabbixZabbixOpen-source, scalable, remote monitoringFree or Commercial

Asset Management and Inventory Tools

VendorProductKey FeaturesPricing model
Snipe-ITOpen Source Asset ManagementFree, web-based, maintenance trackingFree (self-hosted)
Wasp BarcodeAssetCloudBarcode/RFID, maintenance tracking, reportingCommercial
ServiceNowIT Asset ManagementEnterprise, CMDB, lifecycle managementCommercial
ManageEngineAssetExplorerGrowing companies, feature-rich, maintenance historyCommercial
FreshserviceAsset ManagementCloud-based, integrated with ITSMCommercial

Policy and Procedure Templates

Equipment Maintenance Policy Template

Template

Maintenance Log Template

Template


Risk Assessment and Treatment

Risk Assessment Matrix for Equipment Maintenance

Risk IDThreatVulnerabilityLikelihoodImpactRisk LevelTreatment
R1Unauthorized vendor accesses sensitive dataNo vendor vetting; no supervisionMediumHighHighVendor vetting; NDAs; escort; access limitation
R2Maintenance disables encryptionUntrained personnel; poor proceduresLowHighHighPre/post verification; training; encryption monitoring
R3Data lost during maintenanceNo backup; no verificationMediumHighHighPre-maintenance backup; post-maintenance integrity check
R4Replaced components contain recoverable dataComponents not returned; not sanitizedMediumHighHighComponent return; secure disposal; inventory
R5Maintenance introduces malwareUntrusted tools; unauthorized softwareLowHighMediumTool control; software whitelist; post-scan verification
R6Equipment failure due to missed maintenanceNo maintenance schedule; no trackingHighHighCriticalCMMS/ITSM; automated scheduling; reminders; escalation
R7Maintenance window causes business disruptionUnscheduled maintenance; no rollbackMediumMediumMediumChange management; maintenance windows; rollback procedures
R8Secure area breached during maintenanceNo escort; no access controlMediumHighHighEscort requirement; access logs; CCTV; device surrender
R9Configuration drift after maintenanceNo configuration backup; no verificationMediumMediumMediumConfiguration backup; baseline comparison; automated verification
R10Maintenance vendor contract terminated but access not revokedPoor access managementLowHighMediumQuarterly access review; immediate revocation on termination

Audit and Compliance Checklist

Internal Audit Checklist (30 Questions)

Policy and Documentation (5 Questions)

  1. Is an equipment maintenance policy documented and approved?
  2. Are maintenance schedules defined for all critical equipment?
  3. Are maintenance authorization procedures documented?
  4. Are data protection procedures during maintenance documented?
  5. Is the policy reviewed annually?

Maintenance Scheduling (5 Questions)

  1. Is all equipment in a maintenance scheduling system?
  2. Are preventive maintenance schedules aligned with manufacturer recommendations?
  3. Are maintenance windows defined and communicated?
  4. Are overdue maintenance items tracked and escalated?
  5. Is maintenance integrated with change management?

Authorization and Vendors (5 Questions)

  1. Are all maintenance vendors security-vetted?
  2. Do all vendors have signed NDAs and security agreements?
  3. Are vendor authorizations time-limited and reviewed annually?
  4. Is vendor access controlled and logged?
  5. Are vendors escorted in secure areas?

Data Protection (5 Questions)

  1. Is backup verified before maintenance of critical equipment?
  2. Are security settings documented before maintenance?
  3. Is post-maintenance verification performed and documented?
  4. Are replaced components collected and securely disposed of?
  5. Is encryption preserved during maintenance?

Logging and Records (5 Questions)

  1. Are all maintenance activities logged?
  2. Do maintenance logs include personnel, activities, and verification?
  3. Are maintenance logs protected from tampering?
  4. Are maintenance logs retained for the required period?
  5. Are maintenance logs reviewed periodically?

Secure Area Maintenance (5 Questions)

  1. Is maintenance in secure areas supervised?
  2. Do maintenance personnel surrender devices in secure areas?
  3. Are tools and components logged in and out of secure areas?
  4. Is maintenance in secure areas recorded in the access log?
  5. Are security personnel present during maintenance of security equipment?

Audit Scoring

  • 30–27: Excellent (Green), Full compliance
  • 26–22: Good (Yellow), Minor gaps, address within 30 days
  • 21–15: Needs Improvement (Orange), Significant gaps, address within 60 days
  • 14–0: Critical (Red), Major non-compliance, immediate action required

Metrics and KPIs

Figure · Measures

The measures that show A.7.13 is working

  • Maintenance Schedule Compliance>= 95%Monthly
  • Overdue Maintenance Rate<= 5%Monthly
  • Vendor Authorization Currency100%Quarterly
  • Pre-Maintenance Backup Compliance100%Monthly
  • Post-Maintenance Verification Rate100%Monthly
Targets and reporting cadence as defined in the table below, where the formula for each is given.

Key Performance Indicators

KPIFormulaTargetMeasurement Frequency
Maintenance Schedule Compliance(On-time maintenance / Total scheduled maintenance) x 100>= 95%Monthly
Overdue Maintenance Rate(Overdue items / Total scheduled items) x 100<= 5%Monthly
Vendor Authorization Currency(Current authorizations / Total active vendors) x 100100%Quarterly
Pre-Maintenance Backup Compliance(Backups verified before maintenance / Total maintenance events) x 100100%Monthly
Post-Maintenance Verification Rate(Verification completed / Total maintenance events) x 100100%Monthly
Component Secure Disposal Rate(Securely disposed components / Total replaced components) x 100100%Monthly
Encryption Preservation Rate(Encryption maintained / Total maintenance events on encrypted devices) x 100100%Monthly
Equipment Uptime(Available hours / Total hours) x 100>= 99.5%Monthly
Mean Time Between Failures (MTBF)Average time between equipment failuresTrending upwardQuarterly
Mean Time to Repair (MTTR)Average time to repair after failureTrending downwardQuarterly
Maintenance-Related Security IncidentsCount of security incidents caused by maintenance0Monthly
Corrective Maintenance Ratio(Corrective maintenance / Total maintenance) x 100<= 30%Quarterly
Vendor Escort Compliance(Escorted vendors in secure areas / Total vendors in secure areas) x 100100%Monthly
Policy Review Cycle Adherence(Reviews on time / Required reviews) x 100100%Annually
Audit Finding Closure Rate(Closed findings / Total findings) x 100100% within 60 daysPer audit

Common Pitfalls and How to Avoid Them

Pitfall 1: Maintenance as an Afterthought

Problem: Maintenance is reactive, not proactive. Equipment fails, then maintenance is called. There is no schedule, no tracking, and no accountability. Solution: Implement a CMMS or ITSM system with automated scheduling. Start with critical equipment and expand. Set maintenance calendars. Assign ownership. Escalate overdue items. Make maintenance a KPI, not an afterthought.

Pitfall 2: "Trusted Vendor" Syndrome

Problem: Vendors who have worked with the organization for years are given unrestricted access without ongoing verification, background checks, or access reviews. Solution: Vet all vendors, regardless of tenure. Require annual re-authorization. Review access rights quarterly. Do not allow vendors to work unsupervised in secure areas. Trust but verify, continuously.

Pitfall 3: No Backup Before Maintenance

Problem: Maintenance is performed without verifying backups, assuming "nothing will go wrong." When something does go wrong, data is lost. Solution: Make pre-maintenance backup verification a mandatory step. Automate backup verification where possible. Include it in the maintenance checklist. Do not allow maintenance to proceed without verified backup. This is non-negotiable.

Pitfall 4: Post-Maintenance Verification Skipped

Problem: After maintenance, equipment is assumed to be "fine" because it powers on. Security settings, data integrity, and configurations are not verified. Solution: Create a post-maintenance verification checklist. Verify functionality, security settings, data integrity, and configurations. Compare against pre-maintenance baselines. Automate verification where possible (e.g., configuration compliance tools). Document verification results.

Pitfall 5: Replaced Components Not Secured

Problem: Failed hard drives, memory, or other components are given to the vendor for disposal or "recycling" without verification of secure destruction. Solution: All replaced components must be returned to the organization. Inventory them. Sanitize or destroy them securely. Obtain certificates of destruction. Do not trust vendors to dispose of components containing your data. This is a direct data protection issue.

Pitfall 6: Maintenance Windows Not Scheduled

Problem: Maintenance is performed during business hours without planning, causing unexpected disruptions, service outages, and user complaints. Solution: Define maintenance windows for different systems. Schedule maintenance during low-impact times. Communicate maintenance windows to stakeholders. Use change management to coordinate. Have rollback procedures. Plan for worst-case scenarios.

Pitfall 7: Insecure Remote Maintenance

Problem: Vendors access equipment remotely for maintenance without proper controls, logging, or supervision. Remote access credentials are shared or not revoked. Solution: Use secure remote access tools (VPN, jump servers, session recording). Limit remote access to specific equipment and time windows. Monitor and record all remote sessions. Require multi-factor authentication. Revoke remote access immediately after maintenance. Do not share credentials.

Pitfall 8: Maintenance Logs Not Maintained

Problem: No records are kept of who performed maintenance, what was done, or what components were replaced. When an incident occurs, there is no audit trail. Solution: Maintain detailed maintenance logs for all equipment. Log who, what, when, where, and why. Use electronic systems to prevent tampering. Retain logs for the required period. Review logs periodically for anomalies. Logs are not just compliance documents, they are security evidence.


Illustrative Scenarios

Illustrative scenario, a composite example for guidance, not a specific Singahi engagement or a verified outcome.

Illustrative Scenario 1: Indian SaaS Company, Maintenance Transformation (Growing company)

Organization: A 350-employee SaaS company in Hyderabad with 200+ servers, 500+ endpoints, and a small data center Challenge: The company had grown rapidly from 50 to 350 employees in 2 years. The IT team was focused on scaling and feature delivery, with maintenance treated as a low priority. Servers were never proactively maintained. A vendor replacing a failed hard drive in a database server was not supervised, did not verify backups, and did not return the failed drive. The failed drive was later found for sale online with recoverable customer data. The company faced a DPDP Act investigation and potential penalty. Before State:

  • No maintenance policy or schedule
  • No vendor vetting process; vendors were hired based on price alone
  • No maintenance logs; no one could say when a server was last serviced
  • No pre-maintenance backup verification
  • No post-maintenance verification
  • Replaced components were given to vendors for "disposal"
  • No CMMS or ITSM system
  • Secure area maintenance was unsupervised

Implementation: Month 1: Emergency response to the data breach. Engaged forensic investigators. Notified affected customers. Began remediation. Month 2: Developed and approved equipment maintenance policy. Defined all procedures. Month 3: Implemented Freshservice ITSM for maintenance scheduling, logging, and vendor management. Month 4: Vetted all existing vendors. Terminated 3 vendors who could not meet security requirements. Signed NDAs with all remaining vendors. Month 5: Implemented pre-maintenance and post-maintenance checklists. Enforced backup verification. Month 6: Deployed configuration management tools (Ansible) for automated post-maintenance verification. Month 7: Implemented secure component disposal process with certificates. Month 8: Trained all IT staff and vendors on new procedures. Month 9: Conducted internal audit. Addressed findings.

Results (After 12 Months):

  • 100% maintenance schedule compliance for critical equipment
  • 100% vendor vetting and authorization coverage
  • 100% pre-maintenance backup verification
  • 100% post-maintenance verification
  • 100% secure component disposal with certificates
  • Zero maintenance-related security incidents
  • DPDP Act investigation resolved with no fine (demonstrated corrective action)
  • Customer trust recovered; only 2% customer churn (vs. projected 15%)

Investment: (ITSM, CMMS, vendor vetting, training, disposal process, forensic investigation)

Key Lesson: Maintenance is a security control, not just an operational task. The "failed hard drive" incident was entirely preventable with basic maintenance security procedures. The cost of prevention is always lower than the cost of a breach.


Illustrative Scenario 2: Large Indian Manufacturing Conglomerate, Industrial Equipment Maintenance Standardization

Organization: A manufacturing conglomerate with 12 plants across India, 20,000+ employees, 5,000+ industrial devices including SCADA, PLCs, IoT sensors, and traditional IT Challenge: The conglomerate had grown through decades of organic growth and acquisition. Each plant managed its own maintenance independently. A maintenance vendor at another plant replaced a network switch and left the default password active, which was later exploited by an attacker who gained access to the SCADA network. The board mandated standardization of maintenance across all plants within 18 months. Before State:

  • 12 plants with completely different maintenance maturity
  • No corporate maintenance policy or standards
  • 3 plants with no maintenance logs
  • Vendor management: ad-hoc, no vetting, no NDAs at 4 plants
  • No pre/post maintenance verification at 6 plants
  • SCADA and IT maintenance were managed by different teams with no coordination
  • No centralized visibility into maintenance status

Implementation: Phase 1 (Months 1–2): Developed corporate maintenance policy and standards for all equipment types (IT, SCADA, industrial, security). Phase 2 (Months 3–4): Assessed all 12 plants. Created maturity scorecards. Prioritized by risk. Phase 3 (Months 5–10): Deployed standardized CMMS (eMaint) across all plants. Implemented maintenance schedules for all 5,000+ devices. Trained plant staff. Phase 4 (Months 11–13): Standardized vendor management. Vetted all vendors. Implemented NDAs and access controls. Implemented escort procedures for secure areas. Phase 5 (Months 14–16): Implemented pre/post maintenance verification. Deployed configuration management for IT and SCADA devices. Implemented secure component disposal. Phase 6 (Months 17–18): Conducted corporate internal audit. All plants passed. Board review.

Results (After 18 Months):

  • 100% of plants compliant with corporate maintenance standards
  • 5,000+ devices in maintenance scheduling system
  • Maintenance schedule compliance: 94% (up from 45%)
  • Unplanned downtime due to equipment failure: reduced by 70%
  • Vendor authorization: 100% coverage
  • Maintenance-related security incidents: zero (down from 2/year)
  • PLC and SCADA maintenance: standardized and coordinated with IT

Outcome: The kind of PLC failure that had caused lost production did not recur. Standardized maintenance across 12 plants improved operational efficiency and security. The network switch incident would have been prevented by the new verification procedures.

Key Lesson: Industrial and OT (Operational Technology) maintenance is often separated from IT maintenance, creating security gaps. Standardization across a distributed manufacturing enterprise requires strong corporate policy, centralized tools, and local accountability. Maintenance is not just about uptime, it is about security.


Multi-Framework Mapping

ISO 27001:2022 A.7.13 to Other Frameworks

FrameworkReferenceHow it relates to A.7.13
NIST SP 800-53 Rev 5MA-2 Controlled maintenance; MA-3 Maintenance tools; MA-4 Nonlocal maintenance; MA-5 Maintenance personnel; MA-6 Timely maintenanceDirect
PCI DSS v4.0.19.5.1.2 Periodic inspection of POI devices for tamperingPayment devices
SOC 2 (2017 TSC)CC6.4 Physical access; CC7.1 Detection of configuration changesSupports
CIS Controls v84.1 Secure configuration process; 7.4 Automated application patch managementSupports
COBIT 2019BAI09.02 Manage critical assets; BAI09.03 Manage the asset life cycleDirect
ISO 55000Asset managementMaintenance programme design

Regulatory and Industry Context

India-Specific Regulatory Requirements

Digital Personal Data Protection Act 2023: reasonable security safeguards (s.8(5)) while equipment holding personal data is maintained; vendors processing personal data need a contract (s.8(2)); breaches are intimated to the Board and affected people without delay once the Rules apply (s.8(6)).

Information Technology Act 2000: s.43A (until DPDP s.44(2) commences) and s.72A (disclosure in breach of a lawful contract) apply to vendors who mishandle personal information.

Sector regulators: RBI's Master Direction on Outsourcing of IT Services (2023), SEBI CSCRF (2024) and IRDAI (2023) expect due diligence, access control and records for vendors, including maintenance providers. They do not prescribe maintenance windows or patch timelines in the way some guides claim; set yours by risk and follow any specific direction that applies to you.

Safety rules: lifts, pressure vessels, electrical installations and fire equipment have their own statutory inspection regimes (state lift rules, CEA Safety Regulations 2023, fire NOC conditions, OSH Code 2020 for factories).

Industry-Specific Context

  • BFSI: ATM and branch equipment maintenance by vetted vendors with logged access; post-maintenance tamper checks on ATMs and POS devices.
  • Healthcare: medical device maintenance follows the manufacturer and the Medical Device Rules 2017 where they apply; legacy systems that cannot be patched need isolation. The 2017 WannaCry attack, which disrupted NHS England (about 19,000 appointments cancelled, according to the UK National Audit Office), showed the cost of unmaintained systems.
  • Manufacturing: OT maintenance coordinated with IT; test changes before applying them to control systems.
  • SaaS and cloud: providers maintain the hardware; you maintain images, configurations and patches, and watch provider maintenance notices.

Roles and Responsibilities (RACI)

ActivityCISOIT OperationsFacility MgmtSecurityAsset OwnerMaintenance Vendor
Policy DevelopmentARCCCI
Maintenance SchedulingCACICI
Preventive MaintenanceIRRICR
Corrective MaintenanceIRRICR
Vendor VettingACCRIC
Vendor AuthorizationACCRIC
Maintenance ExecutionIRRICR
Data Protection (Pre)CRICRI
Data Protection (Post)CRICRI
Secure DisposalARICIC
Logging and DocumentationCRIICC
Change ManagementCACICI
Audit and ComplianceACCRII
Continuous ImprovementARCCCI

Documentation and Evidence Requirements

DocumentPurposeRetention PeriodOwner
Equipment Maintenance PolicyDefines requirementsDuration + 3 yearsCISO
Maintenance SchedulesPreventive maintenance calendarDuration + 3 yearsIT Operations
Maintenance LogsActivity recordsLife of equipment + 3 yearsIT Operations
Vendor Authorization RecordsVendor approval documentationDuration + 3 yearsSecurity
Vendor NDAs and AgreementsContractual security requirementsDuration + 3 yearsLegal
Pre-Maintenance ChecklistsBackup and security verification1 yearIT Operations
Post-Maintenance ChecklistsVerification records1 yearIT Operations
Component Disposal RecordsSecure disposal evidenceDuration + 3 yearsIT Security
Configuration BackupsPre-maintenance configurationDuration + 3 yearsIT Operations
Change RecordsMaintenance change documentationDuration + 3 yearsIT Operations
Test ResultsMaintenance verificationDuration + 3 yearsIT Operations
Incident ReportsMaintenance-related incidentsDuration + 3 yearsSecurity
Audit Checklist and ResultsAudit evidenceDuration + 3 yearsInternal Audit
Risk AssessmentRisk treatmentDuration + 3 yearsCISO

Continuous Improvement

Figure · Tiers

Maturity levels for equipment maintenance

Maturity levels for ISO 27001 A.7.13, equipment maintenance, from most to least mature: Optimized, fully automated; Managed, metrics-driven; predictive maintenance; Defined, full schedules; complete documentation; Developing, basic schedules; some documentation; Initial, reactive maintenance; no schedule.
Where most organisations sit, and what the next level asks for. Full characteristics per level are in the table below.

Maturity Model for A.7.13

LevelNameCharacteristicsEvidence
1InitialReactive maintenance; no schedule; no documentation; vendors unvettedNo policy; no logs; no CMMS; ad-hoc fixes
2DevelopingBasic schedules; some documentation; informal vendor managementCalendar-based scheduling; paper logs; basic vendor contracts
3DefinedFull schedules; complete documentation; vetted vendors; verified proceduresCMMS/ITSM; preventive maintenance; vendor NDAs; pre/post verification
4ManagedMetrics-driven; predictive maintenance; automated scheduling; vendor performance monitoringAutomated CMMS; predictive analytics; SLA monitoring; trend analysis
5OptimizedFully automated; AI-powered predictive maintenance; self-healing systems; integrated with enterprise systemsIoT-based condition monitoring; AI failure prediction; automated vendor dispatch; zero incidents

Continuous Improvement Activities

Monthly:

  • Maintenance schedule compliance review
  • Overdue maintenance escalation and resolution
  • Vendor performance review
  • Maintenance log review for anomalies

Quarterly:

  • Preventive maintenance effectiveness analysis
  • Corrective maintenance trend analysis
  • Vendor re-authorization and access review
  • Internal audit of maintenance controls
  • Configuration drift detection

Annually:

  • Full policy review
  • Complete maintenance program review
  • Technology and tool evaluation
  • Benchmark against industry standards
  • External audit preparation
  • Maturity assessment against target level

Trigger-Based:

  • After any maintenance-related security incident
  • Upon equipment failure that maintenance should have prevented
  • Upon vendor contract change or termination
  • After significant audit findings
  • Upon new equipment technology adoption

FAQ

Q1: What types of equipment need maintenance under A.7.13? A: All information processing equipment: servers, workstations, storage, network devices, security devices, printers, peripherals, and utility equipment (UPS, generators, HVAC). If it processes, stores, or transmits information, it needs maintenance.

Q2: How often should we maintain servers? A: At minimum, monthly preventive maintenance (dust cleaning, log review, temperature check, fan inspection). Quarterly for firmware updates and deep inspection. Annually for complete hardware assessment. Follow manufacturer recommendations (e.g., Dell, HP, Cisco provide specific maintenance schedules). Adjust based on criticality and environment (dusty environments need more frequent cleaning).

Q3: Do we need to supervise all vendor maintenance? A: Supervision is required for all maintenance in secure areas and for all maintenance of sensitive or critical equipment. For routine maintenance of non-critical equipment in general areas, supervision may be reduced to periodic checks rather than continuous escort. However, the vendor must still be authorized, vetted, and their activities logged. Use risk-based judgment: the more sensitive the equipment or data, the more supervision required.

Q4: What if a vendor insists on keeping a failed component for warranty or analysis? A: The vendor can analyze the component on-site or in your presence. If the component must leave the site, the data must be sanitized first (degaussed, wiped, or physically destroyed). If the component cannot be sanitized (e.g., a failed SSD that cannot be erased), document the risk acceptance, require the vendor to sign a data protection agreement, and verify their disposal process. Better yet, choose vendors who do not require component retention.

Q5: How do we maintain equipment in a remote office with no IT staff? A: Use remote monitoring and management (RMM) tools for remote diagnostics and software maintenance. Schedule on-site vendor visits for hardware maintenance. Use cloud-managed devices that can be remotely maintained. Train a local employee (even non-IT) to perform basic tasks (checking lights, rebooting, checking cables). Have a "remote hands" vendor for physical intervention. Ship replacement equipment with pre-configuration for swap-out maintenance.

Q6: What is predictive maintenance and how do we implement it? A: Predictive maintenance uses data (sensor readings, performance metrics, error logs) to predict when equipment will fail, allowing maintenance just before failure. Implementation: (1) Deploy monitoring tools (IPMI, SNMP, SMART, BMS), (2) Collect and analyze data for trends, (3) Set thresholds for intervention, (4) Use AI/ML tools for advanced prediction, (5) Schedule maintenance based on predictions rather than fixed intervals. Predictive maintenance reduces costs and downtime compared to traditional preventive maintenance.

Q7: How do we handle emergency maintenance when there is no time for backup? A: Emergency maintenance is a risk. If the equipment is failing and immediate action is needed: (1) Assess if the data is already backed up (most organizations have automated backups), (2) If no recent backup, take a quick backup if possible, (3) Document the emergency and why normal procedures could not be followed, (4) After emergency maintenance, perform full verification, (5) Update procedures to prevent similar emergencies. Do not let "emergency" become an excuse for skipping security.

Q8: What about firmware updates? Are they maintenance? A: Yes, firmware updates are maintenance. They are critical for security (firmware often contains security patches). Treat firmware updates as high-priority maintenance: (1) Verify the update is from the manufacturer (checksum verification), (2) Test in a non-production environment first, (3) Have a rollback plan, (4) Schedule during a maintenance window, (5) Verify functionality and security after update, (6) Document the update in the maintenance log. Never apply firmware updates without planning and verification.

Q9: How do we maintain legacy equipment that the manufacturer no longer supports? A: Legacy unsupported equipment is a security risk. Options: (1) Replace with modern equipment, (2) If replacement is not possible, implement compensating controls (air-gap, additional monitoring, restricted access), (3) Maintain the equipment yourself using available documentation and spare parts, (4) Consider third-party maintenance vendors who specialize in legacy equipment, (5) Document the risk and accept it with management approval. Legacy equipment should be on a retirement plan, do not let it become permanent.

Q10: What is the most common audit finding for A.7.13? A: Incomplete maintenance records and lack of vendor management. Auditors will check: Are maintenance schedules documented? Are they being followed? Are maintenance logs complete? Are vendors vetted? Are components securely disposed of? The most common failure is having no evidence of maintenance, no logs, no schedules, no vendor records.

Q11: Do we need to maintain employee personal devices (BYOD)? A: BYOD devices used for work should be included in maintenance policy, but the organization typically cannot perform physical maintenance on personal devices. Instead: (1) Require employees to keep devices updated and patched, (2) Use MDM to enforce security updates, (3) Include device maintenance requirements in BYOD policy, (4) Prohibit use of unsupported or unmaintained devices for work. The organization maintains control over what devices can access corporate data, even if it does not maintain the devices themselves.

Q12: How do we track maintenance for equipment in the cloud? A: Cloud infrastructure (IaaS, PaaS) maintenance is typically the provider's responsibility for the underlying hardware. However, the organization is responsible for: (1) VM and application maintenance, (2) Configuration management, (3) Security patching, (4) Monitoring and alerting. Use cloud-native tools (AWS Systems Manager, Azure Update Manager, Google Cloud OS Patch Management) to schedule and track maintenance. Include cloud maintenance in your CMDB/ITSM. Verify cloud provider maintenance windows and security practices via SOC 2 reports and audit rights.

Q13: How much does implementing A.7.13 cost for a growing company? A: Mostly time rather than tools. Many organisations use their existing ITSM tool for the maintenance schedule and log. The main costs are maintenance contracts, escort time for on-site work, and secure handling of equipment that leaves for repair.

Q14: Can we use the same maintenance vendor for all equipment? A: Using a single vendor is simpler but creates risk: vendor lock-in, single point of failure, and potential compromise if the vendor is breached. Best practice: use multiple vendors for different equipment types (one for servers, one for network, one for facilities). Ensure all vendors meet your security standards. Diversify to reduce risk while maintaining efficiency.

Q15: What is the difference between maintenance and repair? A: Maintenance is proactive (preventive, predictive) or scheduled (corrective). Repair is reactive, fixing something that has already broken. ISO 27001 A.7.13 covers both. The goal is to move from reactive repair to proactive maintenance. Proactive maintenance reduces failures, improves security, and provides better audit evidence.

Industry-Specific Maintenance Requirements

See Industry-Specific Context above. Set maintenance windows, patch timelines and vendor checks from your risk assessment and any direction that actually applies to you; avoid copying figures (for example "72-hour notice to RBI" or "48-hour patching") that no regulator has set.

Maturity Model for A.7.13

LevelNameMaintenance ApproachToolsDocumentationVendor Management
1InitialReactive (break-fix)NoneAd hocNo vetting
2ManagedScheduled preventiveSpreadsheetBasic logsBasic contracts
3DefinedPreventive + predictiveCMMS/ITSMFull SOPsSecurity clauses
4QuantitativePredictive + automatedCMMS + analyticsAutomated reportsContinuous monitoring
5OptimizedAI-driven, self-healingAI/ML platformReal-time dashboardsIntegrated risk management

Progression Guidance:

  • Level 1 → 2: Implement scheduled maintenance, basic CMDB, and maintenance contracts.
  • Level 2 → 3: Deploy CMMS/ITSM, add security vetting to vendor contracts, implement full documentation.
  • Level 3 → 4: Add predictive maintenance, automated monitoring, and continuous vendor assessment.

Additional FAQ

Q16: How do we handle maintenance for legacy equipment that vendors no longer support? A: Legacy equipment is a common challenge. Options: (1) Extended support contracts (expensive but available), (2) Third-party maintenance providers (ensure security vetting), (3) Upgrade/replacement (best long-term solution), (4) Compensating controls (network isolation, enhanced monitoring, strict access controls). Document the risk and obtain management acceptance. Plan for replacement within a defined timeline.

Q17: What is predictive maintenance and how does it improve security? A: Predictive maintenance uses sensors, IoT, and analytics to predict equipment failures before they occur. It improves security by: (1) Reducing unexpected failures that create vulnerabilities, (2) Enabling planned maintenance windows with proper security controls, (3) Identifying anomalies that may indicate tampering or cyber-physical attacks, (4) Optimizing equipment lifespan to reduce emergency replacements. Typical tools: vibration analysis, thermal imaging, oil analysis, and electrical signature analysis.

Q18: How do we maintain security during vendor maintenance visits? A: Implement a vendor access protocol: (1) Pre-visit notification and approval, (2) Background check verification, (3) Escorted access at all times, (4) Signed NDA and security briefing, (5) Restricted network access (guest WiFi only), (6) Tool and device inspection (no unauthorized USB drives, cameras), (7) Activity logging (what was accessed, what was changed), (8) Post-visit review and sign-off. Use temporary badges that expire automatically.

Q19: How do we balance maintenance costs with security requirements? A: Prioritize based on risk: critical systems (core banking, patient monitors) get the highest maintenance priority and budget. Use risk assessment to justify spending. Consider vendor support (overall value), cheap equipment with poor maintenance costs more in the long run. Use leasing or managed service models to convert CapEx to OpEx. Group maintenance contracts for volume discounts. Negotiate SLAs that include security requirements at no extra cost.

Q20: How do we document maintenance for ISO 27001 audit evidence? A: Maintain these records: (1) Equipment inventory with maintenance schedules, (2) Maintenance contracts with security clauses, (3) Vendor vetting records, (4) Maintenance logs (date, technician, work performed, parts replaced), (5) Test results after maintenance, (6) Patch management records, (7) Configuration change records, (8) Security review records after maintenance, (9) Incident records related to maintenance failures, (10) Management review of maintenance program. Store for at least 3 years (or longer per regulatory requirements).

Illustrative Scenario (hypothetical): Bengaluru IT Company, Maintenance Failure to Security Incident

Background

A 500-employee software company in Bangalore outsourced server maintenance to a third-party vendor. The vendor had access to the server room, performed quarterly maintenance, and replaced faulty hardware. The company had no formal vendor vetting process, no escort requirements, and no activity logging.

The Incident

A maintenance technician (contracted through the vendor) installed a hardware monitoring tool on three production servers. The tool was legitimate but was downloaded from an unofficial source and contained a backdoor. The backdoor allowed remote access to the servers, which the attacker used to exfiltrate customer data over 6 weeks. The breach affected 12,000 customer records, including names, email addresses, and partial payment data.

Root Cause Analysis

  1. No Vendor Vetting: The vendor was selected based on price alone. No background checks, no security questionnaire, no reference verification.
  2. Unescorted Access: The technician was given unsupervised access to the server room during after-hours maintenance.
  3. No Device Inspection: The technician's laptop and USB drives were not inspected. The unauthorized software was installed via USB.
  4. No Activity Logging: The company had no logs of what the technician did during the maintenance window. The backdoor installation was not detected until the data exfiltration triggered a DLP alert.
  5. No Post-Maintenance Review: After maintenance, no one verified what was changed or installed. The backdoor persisted for 6 weeks.

Impact

  • Data Exfiltration: 12,000 customer records stolen and sold on dark web forums
  • Regulatory: exposure to DPDP Act penalties once the fiduciary duties commence
  • Customer Notification: Mandatory breach notification to affected customers and the Data Protection Board
  • Reputational: Customer churn increased 18%, new sales dropped 30% for 2 quarters
  • Legal: Class action lawsuit filed by affected customers
  • Total cost: legal fees, notification, remediation and lost business

Remediation

After the incident, the company implemented a complete maintenance security program:

  1. Vendor Vetting: All maintenance vendors now undergo security questionnaires, background checks, and reference verification. Contracts include security clauses and liability for breaches caused by vendor actions.
  2. Escorted Access: All vendor personnel are escorted by an internal employee at all times. No unsupervised access to critical areas.
  3. Device Inspection: All vendor devices (laptops, USB drives, tools) are inspected before and after maintenance. Unauthorized devices are prohibited.
  4. Activity Logging: Maintenance activities are logged in real-time. Network monitoring captures all traffic during maintenance windows. Screen recording is used for remote maintenance sessions.
  5. Post-Maintenance Review: Every maintenance session is followed by a security review: verify installed software against approved list, scan for malware, review configuration changes, and sign off.
  6. Network Segmentation: Vendor maintenance is performed on an isolated VLAN with no access to production data. Remote access is through a bastion host with MFA and session recording.
  7. Incident Response: The company developed a maintenance-specific incident response playbook. Maintenance windows are treated as high-risk periods with enhanced monitoring.

Key Lessons

  1. Trust but Verify: Even trusted vendors can be compromised. Always verify vendor actions.
  2. Maintenance Windows are High-Risk: The time when external personnel have physical access is the most vulnerable period. Implement enhanced controls during maintenance.
  3. Log Everything: Without logs, you cannot detect, investigate, or prove what happened. Logging is essential for both security and compliance.
  4. Vendor Security is Your Security: A vendor breach is your breach. Vendor security standards must match your own.
  5. Post-Maintenance Verification: Always verify what was done. The cost of verification is minimal compared to the cost of a breach.

Maintenance Security Metrics and KPIs

MetricFormulaTargetFrequency
Preventive Maintenance Completion Rate(Completed PM tasks / Scheduled PM tasks) × 100> 95%Monthly
Mean Time Between Failures (MTBF)Total operational hours / Number of failuresIncreasingQuarterly
Vendor Security Score(Vendors meeting security standards / Total vendors) × 100100%Quarterly
Maintenance-Related IncidentsNumber of security incidents caused by maintenance0Monthly
Patch Compliance Rate(Systems patched on time / Total systems) × 100> 98%Monthly
Vendor Access ReviewsNumber of vendor access reviews conductedAll vendors reviewedQuarterly
Equipment Uptime(Total uptime / Total time) × 100> 99.5%Monthly
Maintenance Cost per AssetTotal maintenance cost / Number of assetsOptimizedQuarterly
Post-Maintenance Verification Rate(Verified maintenance sessions / Total sessions) × 100100%Monthly
Legacy Equipment Risk ScoreRisk rating of unsupported equipmentDecreasingQuarterly

References and Further Reading

Standards and Frameworks

  • ISO/IEC 27001:2022, Information Security, Cybersecurity and Privacy Protection, Information Security Management Systems, Requirements
  • ISO/IEC 27002:2022, Information Security, Cybersecurity and Privacy Protection, Information Security Controls
  • NIST SP 800-53 Rev 5, Security and Privacy Controls for Information Systems and Organizations
  • ISO 55000, Asset Management, Overview, Principles and Terminology
  • PCI DSS v4.0.1, Payment Card Industry Data Security Standard
  • CIS Controls v8, CIS Controls Version 8

Indian Regulations

  • Digital Personal Data Protection Act, 2023 (India)
  • Information Technology Act, 2000 (as amended)
  • RBI Cyber Security Framework for Banks
  • SEBI Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities, circular of 20 August 2024
  • OSH Code 2020 (replaced the Factories Act 1948) (India)

Books and Publications

  • ISO 27001/27002: A Pocket Guide by Alan Calder
  • The Manager's Handbook for Corporate Security by Gerald L. Kovacich and Edward P. Halibozek
  • Maintenance Engineering Handbook by Lindley R. Higgins

Indian Regulatory Context for Equipment Maintenance

In India, maintenance is often outsourced through annual maintenance contracts (AMCs). Write security into the AMC: named and verified technicians, confidentiality terms, escorted on-site work, remote access only when approved, "keep your drive" (defective media retention) clauses so failed disks stay with you, and post-maintenance checks before equipment returns to service. Facilities equipment (UPS, generators, fire systems, lifts) has its own statutory inspections; keep those certificates with your maintenance records.

How Singahi can help

Singahi is one team for compliance, assessment and managed security. We help growing companies implement and certify ISO 27001:2022, and stay secure afterward.


Continue the toolkit

How we can help

Working toward this?

If a certification or a customer's security questionnaire is what brought you here, tell us where you are. We'll give you an honest read on the work and the timeline, with no obligation.

What happens next

  1. Tell us the trigger

    A questionnaire, an audit date or an investor ask. The short form or a call both work.

  2. A practitioner replies

    A senior practitioner, not a bot, within four business hours.

  3. You get a scoped next step

    An honest view of what the work involves. No pressure, no theatre.