OR-09 IT Operations & Resilience

Capacity & Performance Management

Resources scale to demand.

Domain
IT Operations & Resilience
Control type
Preventive/Detective
Automated / manual
Hybrid
Frequency
Periodic
Framework reference
COBIT BAI04

What good looks like

Capacity planning meets demand; thresholds trigger scaling/action.

Risk if it fails

Performance degradation/outage from exhaustion.

How Tess tests it

2 tests — each concludes only on cited evidence.

Capacity-management process defined

Design
Procedure
Inspect the process.
Expected
Thresholds and planning defined.
Sample
1 (design inspection)
Evidence
Capacity reports, scaling/auto-scaling config.

Capacity reviewed; scaling actioned

Operating
Procedure
Inspect reports/actions.
Expected
Action taken on threshold breaches.
Sample
Judgmental, by population (e.g. 10–25)
Evidence
Capacity reports, scaling/auto-scaling config.

Evidence Tess looks for

Capacity reports, scaling/auto-scaling config.

More in IT Operations & Resilience

Want Tess to test OR-09 against your evidence?

Book a demo