Capacity planning shall ensure adequate resources for organization's critical system information processing, networking, telecommunications, and data storage.
Audit data from the organization's critical systems shall be moved to an alternative system.
The organization’s critical systems shall be protected against denial-of-service attacks or at least the effect of such attacks will be limited.