Equipment does not usually fail suddenly.
It fails because maintenance was inconsistent, unauthorised, or overlooked.
Annex A 7.13 exists to ensure organisations maintain equipment securely and correctly, so information assets are not compromised through degradation, failure, or insecure maintenance activity.
This control treats maintenance as a preventative security activity, not just an operational task.

Annex A 7.13 of ISO 27001:2022 focuses on secure equipment maintenance.
At a practical level, this means:
The control does not dictate maintenance schedules or tools. It expects organisations to apply planned, authorised, and secure maintenance practices.
Information security depends on reliable equipment, including:
Poorly maintained equipment increases risk of:
Annex A 7.13 ensures organisations do not treat maintenance as neutral activity, recognising that maintenance introduces both operational and security risk.
A pragmatic approach to Annex A 7.13 typically includes the following elements.
Organisations should define a structured approach to maintenance, covering:
A defined programme supports consistency and predictability.
Equipment should be maintained:
Ignoring manufacturer guidance is a common cause of avoidable failure.
Maintenance should only be performed by:
Authorisation ensures accountability and reduces insider and third-party risk.
Annex A 7.13 explicitly recognises supervision as a control.
Organisations may:
Supervision reduces risk of accidental or deliberate compromise.
Where maintenance is performed remotely:
Remote maintenance bypasses physical controls and therefore requires additional attention.
Organisations should record:
Records support accountability, trend analysis, and audit evidence.
Maintenance activities may expose information.
Organisations should consider:
Maintenance should not become a data exposure event.
After maintenance, organisations should verify that:
Post-maintenance checks close the loop on risk.
If equipment is removed from premises for maintenance:
Removal from site significantly increases exposure.
Maintenance activities may trigger:
Organisations should align with:
Maintenance and disposal are often linked operationally.
Annex A 7.13 does not require:
It does require organisations to:
Unmanaged maintenance is a common root cause of incidents.
Equipment failure rarely starts with attack — it starts with neglect.
Annex A 7.13 is about keeping security intact while equipment is touched, repaired, or changed.
When equipment maintenance is managed effectively:
Systems age.
Annex A 7.13 ensures they do so securely, not unpredictably.
We can help you understand your actual security needs and even if we cant help we can point you in the right direction
Talk to a security expert today