Control statement
- a.Establish an alternate processing site, including necessary agreements to permit the transfer and resumption of [Organization-defined: system operations] for essential mission and business functions within [Organization-defined: time period] when the primary processing capabilities are unavailable;
- b.Make available at the alternate processing site, the equipment and supplies required to transfer and resume operations or put contracts in place to support delivery to the site within the organization-defined time period for transfer and resumption; and
- c.Provide controls at the alternate processing site that are equivalent to those at the primary site.
Discussion
Alternate processing sites are geographically distinct from primary processing sites and provide processing capability if the primary processing site is not available. The alternate processing capability may be addressed using a physical processing site or other alternatives, such as failover to a cloud-based service provider or other internally or externally provided processing service. Geographically distributed architectures that support contingency requirements may also be considered alternate processing sites. Controls that are covered by alternate processing site agreements include the environmental conditions at alternate sites, access rules, physical and environmental protection requirements, and the coordination for the transfer and assignment of personnel. Requirements are allocated to alternate processing sites that reflect the requirements in contingency plans to maintain essential mission and business functions despite disruption, compromise, or failure in organizational systems.
Organization-defined parameters
These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.
From control text to operational evidence
Use Alternate Processing Site as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to resilient operations, recovery priorities, alternate capabilities, and tested restoration.
Implementation workflow
- Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
- Resolve each organization-defined parameter before declaring the control implemented.
- Document how the implementation satisfies every clause of the official control statement.
- Collect evidence as a normal byproduct of operation rather than only before an assessment.
- Review exceptions, changes, and monitoring results on a risk-based cadence.
Evidence examples
- contingency and recovery plans
- backup success and restoration-test records
- exercise after-action reports
- alternate processing or communications agreements
Common failure patterns
- backups never restored in testing
- recovery priorities not tied to mission impact
- plans dependent on unavailable people or facilities
- exercise findings not tracked to closure
Questions practitioners should ask
- What risk decision is this control intended to support in this system?
- Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
- Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
- What event or threshold requires the implementation to be reviewed or changed?
Assessment objectives and methods
Show the assessment objective
- CP-07a.an alternate processing site, including necessary agreements to permit the transfer and resumption of [Organization-defined: system operations] for essential mission and business functions, is established within [Organization-defined: time period] when the primary processing capabilities are unavailable;
- CP-07b.
- CP-07b.[01]the equipment and supplies required to transfer operations are made available at the alternate processing site or if contracts are in place to support delivery to the site within [Organization-defined: time period] for transfer;
- CP-07b.[02]the equipment and supplies required to resume operations are made available at the alternate processing site or if contracts are in place to support delivery to the site within [Organization-defined: time period] for resumption;
- CP-07c.controls provided at the alternate processing site are equivalent to those at the primary site.
Examine
- Contingency planning policy
- procedures addressing alternate processing sites
- contingency plan
- alternate processing site agreements
- primary processing site agreements
- spare equipment and supplies inventory at alternate processing site
- equipment and supply contracts
- service-level agreements
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with responsibilities for contingency planning and/or alternate site arrangements
- organizational personnel with information security responsibilities
Test
- Organizational processes for recovery at the alternate site
- mechanisms supporting and/or implementing recovery at the alternate processing site
Related controls
These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.
Control enhancements
Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.
CP-7(1) — Separation from Primary Site
Identify an alternate processing site that is sufficiently separated from the primary processing site to reduce susceptibility to the same threats.
Official discussion
Threats that affect alternate processing sites are defined in organizational assessments of risk and include natural disasters, structural failures, hostile attacks, and errors of omission or commission. Organizations determine what is considered a sufficient degree of separation between primary and alternate processing sites based on the types of threats that are of concern. For threats such as hostile attacks, the degree of separation between sites is less relevant.
Assessment objectives and methods
an alternate processing site that is sufficiently separated from the primary processing site to reduce susceptibility to the same threats is identified.
Examine
- Contingency planning policy
- procedures addressing alternate processing sites
- contingency plan
- alternate processing site
- alternate processing site agreements
- primary processing site agreements
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with contingency plan alternate processing site responsibilities
- organizational personnel with system recovery responsibilities
- organizational personnel with information security responsibilities
Related controls
CP-7(2) — Accessibility
Identify potential accessibility problems to alternate processing sites in the event of an area-wide disruption or disaster and outlines explicit mitigation actions.
Official discussion
Area-wide disruptions refer to those types of disruptions that are broad in geographic scope with such determinations made by organizations based on organizational assessments of risk.
Assessment objectives and methods
- CP-07(02)[01]potential accessibility problems to alternate processing sites in the event of an area-wide disruption or disaster are identified;
- CP-07(02)[02]explicit mitigation actions to address identified accessibility problems are outlined.
Examine
- Contingency planning policy
- procedures addressing alternate processing sites
- contingency plan
- alternate processing site
- alternate processing site agreements
- primary processing site agreements
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with contingency plan alternate processing site responsibilities
- organizational personnel with system recovery responsibilities
- organizational personnel with information security responsibilities
Related controls
CP-7(3) — Priority of Service
Develop alternate processing site agreements that contain priority-of-service provisions in accordance with availability requirements (including recovery time objectives).
Official discussion
Priority of service agreements refer to negotiated agreements with service providers that ensure that organizations receive priority treatment consistent with their availability requirements and the availability of information resources for logical alternate processing and/or at the physical alternate processing site. Organizations establish recovery time objectives as part of contingency planning.
Assessment objectives and methods
alternate processing site agreements that contain priority-of-service provisions in accordance with availability requirements (including recovery time objectives) are developed.
Examine
- Contingency planning policy
- procedures addressing alternate processing sites
- contingency plan
- alternate processing site agreements
- service-level agreements
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with contingency plan alternate processing site responsibilities
- organizational personnel with system recovery responsibilities
- organizational personnel with information security responsibilities
- organizational personnel with responsibility for acquisitions/contractual agreements
CP-7(4) — Preparation for Use
Prepare the alternate processing site so that the site can serve as the operational site supporting essential mission and business functions.
Official discussion
Site preparation includes establishing configuration settings for systems at the alternate processing site consistent with the requirements for such settings at the primary site and ensuring that essential supplies and logistical considerations are in place.
Assessment objectives and methods
the alternate processing site is prepared so that the site can serve as the operational site supporting essential mission and business functions.
Examine
- Contingency planning policy
- procedures addressing alternate processing sites
- contingency plan
- alternate processing site
- alternate processing site agreements
- alternate processing site configurations
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with contingency plan alternate processing site responsibilities
- organizational personnel with system recovery responsibilities
- organizational personnel with information security responsibilities
Test
- Mechanisms supporting and/or implementing recovery at the alternate processing site
Related controls
CP-7(5) — Equivalent Information Security Safeguards
This enhancement is marked withdrawn in the official OSCAL catalog. Related-control metadata below may identify where its intent was incorporated.
CP-7(6) — Inability to Return to Primary Site
Plan and prepare for circumstances that preclude returning to the primary processing site.
Official discussion
There may be situations that preclude an organization from returning to the primary processing site such as if a natural disaster (e.g., flood or a hurricane) damaged or destroyed a facility and it was determined that rebuilding in the same location was not prudent.
Assessment objectives and methods
- CP-07(06)[01]circumstances that preclude returning to the primary processing site are planned for;
- CP-07(06)[02]circumstances that preclude returning to the primary processing site are prepared for.
Examine
- Contingency planning policy
- procedures addressing alternate processing sites
- contingency plan
- alternate processing site
- alternate processing site agreements
- alternate processing site configurations
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with system reconstitution responsibilities
- organizational personnel with information security responsibilities
Authoritative sources
Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST. Official control requirements and interpretations remain with NIST and the responsible authorizing organization.