Dynamic Resource Scaling for Demand Spikes
Cloud services must be able to scale resources quickly to handle sudden increases in demand.
Plain language
Imagine running a popular online sale. If your cloud service can't handle the extra traffic, your website might crash, leading to lost sales and unhappy customers. This control ensures your cloud services can quickly ramp up resources to meet sudden demand, keeping your business running smoothly.
Framework
ASD Information Security Manual (ISM)
Control effect
Proactive
Classifications
NC, OS, P, S, TS
ISM last updated
June 2026
Control Stack last updated
18 June 2026
E8 maturity levels
N/A
Guideline
Guidelines for networkingOfficial control statement
Cloud service providers' ability to scale resources dynamically in response to genuine spikes in demand is discussed and verified as part of capacity and availability planning for online services.
Why it matters
Without dynamic scaling, your service could crash under pressure, leading to lost sales or reputational damage.
Operational notes
Regularly review demand patterns and adjust automation rules to ensure resource scaling is in line with current business needs.
Implementation tips
- IT team should evaluate peak times: Identify common periods when demand spikes, such as during sales or marketing campaigns, to prepare resource allocation proactively.
- Management should work with cloud service providers: Establish clear agreements on resource scaling capabilities and costs. Make sure they can support your business needs without delay.
- Procurement should review contracts: Ensure cloud service contracts include clauses for scalable resources without excessive costs or delays to prevent website downtime during peak periods.
- Operations team should monitor performance: Use simple dashboards to keep an eye on server loads during peak times. Adjust resources quickly based on real-time data to avoid slowdowns.
- Staff should be trained: Provide training for key personnel on how to manually adjust or request additional cloud resources if automated scaling isn't sufficient.
Audit / evidence tips
- Askthe cloud service agreement: Request documentation detailing scaling capabilities and response timesLook atspecifics on how quickly resources can be scaledGoodincludes a clear and reasonable timeframe for scaling
- Askpeak traffic analysis reportsLook athistorical data showing traffic patterns and how resources were adjustedGoodshows a clear pattern of timely scaling actions taken
- Askmonitoring tool outputs: Request logs or dashboards showing resource usage during demand spikesLook atconsistency in monitoringGoodshows real-time data being effectively used
- Askscaling policy documents: Request documents outlining the procedures for scalingLook atclarity and practicality in stepsGoodincludes step-by-step instructions used by the team
- Askstaff training records: Request records of training sessions focused on manual scaling proceduresLook atevidence of staff attendance and comprehensionGoodincludes recent training dates and attendee lists
Cross-framework mappings
How ISM-1579 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
sync_altPartially overlaps(2)expand_less | ||
| Annex A 8.6 | Annex A 8.6 requires monitoring of resource use and adjustment in line with current and expected capacity requirements | |
| Annex A 8.21 | Annex A 8.21 focuses on defining and meeting security mechanisms and service levels for network services, including reliability and perfo... | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in Networking
See all Guidelines for networking controls, or browse the full ASD ISM library.