Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

NIST SP 800-53 Learning Center

CP-6 — Alternate Storage Site

Read the official control and assessment content, then use the separately labeled Bare Metal Cyber perspective to connect the requirement to implementation, evidence, and sustained operation.

3Enhancements
0Parameters
2Baseline memberships
3Assessment methods

CP — Contingency Planning · NIST SP 800-53 Release 5.2.0

ModerateHigh
Official NIST control content

Control statement

  1. a.Establish an alternate storage site, including necessary agreements to permit the storage and retrieval of system backup information; and
  2. b.Ensure that the alternate storage site provides controls equivalent to that of the primary site.
Official NIST discussion

Discussion

Alternate storage sites are geographically distinct from primary storage sites and maintain duplicate copies of information and data if the primary storage site is not available. Similarly, alternate processing sites provide processing capability if the primary processing site is not available. Geographically distributed architectures that support contingency requirements may be considered alternate storage sites. Items covered by alternate storage site agreements include environmental conditions at the alternate sites, access rules for systems and facilities, physical and environmental protection requirements, and coordination of delivery and retrieval of backup media. Alternate storage sites reflect the requirements in contingency plans so that organizations can maintain essential mission and business functions despite compromise, failure, or disruption in organizational systems.

Original Bare Metal Cyber perspective

From control text to operational evidence

Use Alternate Storage Site as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to resilient operations, recovery priorities, alternate capabilities, and tested restoration.

Implementation workflow

  • Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
  • Resolve each organization-defined parameter before declaring the control implemented.
  • Document how the implementation satisfies every clause of the official control statement.
  • Collect evidence as a normal byproduct of operation rather than only before an assessment.
  • Review exceptions, changes, and monitoring results on a risk-based cadence.

Evidence examples

  • contingency and recovery plans
  • backup success and restoration-test records
  • exercise after-action reports
  • alternate processing or communications agreements

Common failure patterns

  • backups never restored in testing
  • recovery priorities not tied to mission impact
  • plans dependent on unavailable people or facilities
  • exercise findings not tracked to closure

Questions practitioners should ask

  • What risk decision is this control intended to support in this system?
  • Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
  • Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
  • What event or threshold requires the implementation to be reviewed or changed?
Official NIST SP 800-53A content

Assessment objectives and methods

Show the assessment objective
  1. CP-06a.
    1. CP-06a.[01]an alternate storage site is established;
    2. CP-06a.[02]establishment of the alternate storage site includes necessary agreements to permit the storage and retrieval of system backup information;
  2. CP-06b.the alternate storage site provides controls equivalent to that of the primary site.

Examine

  • Contingency planning policy
  • procedures addressing alternate storage sites
  • contingency plan
  • alternate storage site agreements
  • primary storage site agreements
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with contingency plan alternate storage site responsibilities
  • organizational personnel with system recovery responsibilities
  • organizational personnel with information security responsibilities

Test

  • Organizational processes for storing and retrieving system backup information at the alternate storage site
  • mechanisms supporting and/or implementing the storage and retrieval of system backup information at the alternate storage site
Official relationships

Related controls

These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.

Official NIST enhancements

Control enhancements

Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.

Official NIST control enhancement

CP-6(1) — Separation from Primary Site

ModerateHigh

Identify an alternate storage site that is sufficiently separated from the primary storage site to reduce susceptibility to the same threats.

Official discussion

Threats that affect alternate storage sites are defined in organizational risk assessments and include natural disasters, structural failures, hostile attacks, and errors of omission or commission. Organizations determine what is considered a sufficient degree of separation between primary and alternate storage sites based on the types of threats that are of concern. For threats such as hostile attacks, the degree of separation between sites is less relevant.

Assessment objectives and methods

an alternate storage site that is sufficiently separated from the primary storage site is identified to reduce susceptibility to the same threats.

Examine

  • Contingency planning policy
  • procedures addressing alternate storage sites
  • contingency plan
  • alternate storage site
  • alternate storage site agreements
  • primary storage site agreements
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with contingency plan alternate storage site responsibilities
  • organizational personnel with system recovery responsibilities
  • organizational personnel with information security responsibilities
Related controls
Official NIST control enhancement

CP-6(2) — Recovery Time and Recovery Point Objectives

High

Configure the alternate storage site to facilitate recovery operations in accordance with recovery time and recovery point objectives.

Official discussion

Organizations establish recovery time and recovery point objectives as part of contingency planning. Configuration of the alternate storage site includes physical facilities and the systems supporting recovery operations that ensure accessibility and correct execution.

Assessment objectives and methods
  1. CP-06(02)[01]the alternate storage site is configured to facilitate recovery operations in accordance with recovery time objectives;
  2. CP-06(02)[02]the alternate storage site is configured to facilitate recovery operations in accordance with recovery point objectives.

Examine

  • Contingency planning policy
  • procedures addressing alternate storage sites
  • contingency plan
  • alternate storage site
  • alternate storage site agreements
  • alternate storage site configurations
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with contingency plan testing responsibilities
  • organizational personnel with responsibilities for testing related plans
  • organizational personnel with information security responsibilities

Test

  • Organizational processes for contingency plan testing
  • mechanisms supporting recovery time and point objectives
Official NIST control enhancement

CP-6(3) — Accessibility

ModerateHigh

Identify potential accessibility problems to the alternate storage site in the event of an area-wide disruption or disaster and outline explicit mitigation actions.

Official discussion

Area-wide disruptions refer to those types of disruptions that are broad in geographic scope with such determinations made by organizations based on organizational assessments of risk. Explicit mitigation actions include duplicating backup information at other alternate storage sites if access problems occur at originally designated alternate sites or planning for physical access to retrieve backup information if electronic accessibility to the alternate site is disrupted.

Assessment objectives and methods
  1. CP-06(03)[01]potential accessibility problems to the alternate storage site in the event of an area-wide disruption or disaster are identified;
  2. CP-06(03)[02]explicit mitigation actions to address identified accessibility problems are outlined.

Examine

  • Contingency planning policy
  • procedures addressing alternate storage sites
  • contingency plan
  • alternate storage site
  • list of potential accessibility problems to alternate storage site
  • mitigation actions for accessibility problems to alternate storage site
  • organizational risk assessments
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with contingency plan alternate storage site responsibilities
  • organizational personnel with system recovery responsibilities
  • organizational personnel with information security responsibilities
Related controls
Source record

Authoritative sources