Information systems fail quietly when the utilities they depend on fail first.
Annex A 7.11 exists to ensure organisations protect and manage supporting utilities — such as power, water, cooling, and telecommunications — so failures do not compromise information availability, integrity, or continuity.
This control is about infrastructure resilience, not just facilities management.

Annex A 7.11 of ISO 27001:2022 focuses on supporting utilities for information processing facilities.
At a practical level, this means:
The control does not require guaranteed uptime. It expects organisations to understand dependency and manage risk deliberately.
Information systems rely on utilities such as:
When these fail:
Annex A 7.11 ensures organisations treat utilities as part of the information security ecosystem, not as a separate operational concern.
This control replaces ISO 27001:2013 Annex A 11.2.2, with increased emphasis on network separation and secure connectivity.
A pragmatic approach to Annex A 7.11 typically includes the following elements.
Organisations should identify which utilities support:
Dependencies are often broader than initially assumed.
Protection measures should be proportionate to risk and may include:
The goal is to reduce likelihood and impact, not eliminate all risk.
Utilities and supporting equipment should be:
Improper configuration is a common cause of avoidable failure.
Supporting utilities should be:
Unmaintained utilities degrade silently until failure occurs.
Where justified by risk, organisations should consider:
Single points of failure undermine availability objectives quickly.
Where utilities use network connectivity:
This reduces the risk of compromise spreading between operational and information systems.
Internet access for utility equipment should:
Unnecessary connectivity increases attack surface without benefit.
Annex A 7.11 also supports preparedness for failure scenarios.
Organisations should consider:
Response capability matters as much as prevention.
Annex A 7.11 does not require:
It does require organisations to:
Many outages are caused by utilities, not cyber incidents.
Utility failures rarely announce themselves.
Annex A 7.11 is about protecting what information systems rely on to stay operational.
When supporting utilities are managed effectively:
Systems do not fail in isolation.
Annex A 7.11 ensures the foundations they stand on are not ignored.
We can help you understand your actual security needs and even if we cant help we can point you in the right direction
Talk to a security expert today