Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

NIST SP 800-53 Learning Center

CP-7 — Alternate Processing Site

Read the official control and assessment content, then use the separately labeled Bare Metal Cyber perspective to connect the requirement to implementation, evidence, and sustained operation.

6Enhancements
2Parameters
2Baseline memberships
3Assessment methods

CP — Contingency Planning · NIST SP 800-53 Release 5.2.0

ModerateHigh
Official NIST control content

Control statement

  1. a.Establish an alternate processing site, including necessary agreements to permit the transfer and resumption of [Organization-defined: system operations] for essential mission and business functions within [Organization-defined: time period] when the primary processing capabilities are unavailable;
  2. b.Make available at the alternate processing site, the equipment and supplies required to transfer and resume operations or put contracts in place to support delivery to the site within the organization-defined time period for transfer and resumption; and
  3. c.Provide controls at the alternate processing site that are equivalent to those at the primary site.
Official NIST discussion

Discussion

Alternate processing sites are geographically distinct from primary processing sites and provide processing capability if the primary processing site is not available. The alternate processing capability may be addressed using a physical processing site or other alternatives, such as failover to a cloud-based service provider or other internally or externally provided processing service. Geographically distributed architectures that support contingency requirements may also be considered alternate processing sites. Controls that are covered by alternate processing site agreements include the environmental conditions at alternate sites, access rules, physical and environmental protection requirements, and the coordination for the transfer and assignment of personnel. Requirements are allocated to alternate processing sites that reflect the requirements in contingency plans to maintain essential mission and business functions despite disruption, compromise, or failure in organizational systems.

Official OSCAL parameters

Organization-defined parameters

These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.

system operationssystem operations for essential mission and business functions are defined;
time periodtime period consistent with recovery time and recovery point objectives is defined;
Original Bare Metal Cyber perspective

From control text to operational evidence

Use Alternate Processing Site as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to resilient operations, recovery priorities, alternate capabilities, and tested restoration.

Implementation workflow

  • Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
  • Resolve each organization-defined parameter before declaring the control implemented.
  • Document how the implementation satisfies every clause of the official control statement.
  • Collect evidence as a normal byproduct of operation rather than only before an assessment.
  • Review exceptions, changes, and monitoring results on a risk-based cadence.

Evidence examples

  • contingency and recovery plans
  • backup success and restoration-test records
  • exercise after-action reports
  • alternate processing or communications agreements

Common failure patterns

  • backups never restored in testing
  • recovery priorities not tied to mission impact
  • plans dependent on unavailable people or facilities
  • exercise findings not tracked to closure

Questions practitioners should ask

  • What risk decision is this control intended to support in this system?
  • Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
  • Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
  • What event or threshold requires the implementation to be reviewed or changed?
Official NIST SP 800-53A content

Assessment objectives and methods

Show the assessment objective
  1. CP-07a.an alternate processing site, including necessary agreements to permit the transfer and resumption of [Organization-defined: system operations] for essential mission and business functions, is established within [Organization-defined: time period] when the primary processing capabilities are unavailable;
  2. CP-07b.
    1. CP-07b.[01]the equipment and supplies required to transfer operations are made available at the alternate processing site or if contracts are in place to support delivery to the site within [Organization-defined: time period] for transfer;
    2. CP-07b.[02]the equipment and supplies required to resume operations are made available at the alternate processing site or if contracts are in place to support delivery to the site within [Organization-defined: time period] for resumption;
  3. CP-07c.controls provided at the alternate processing site are equivalent to those at the primary site.

Examine

  • Contingency planning policy
  • procedures addressing alternate processing sites
  • contingency plan
  • alternate processing site agreements
  • primary processing site agreements
  • spare equipment and supplies inventory at alternate processing site
  • equipment and supply contracts
  • service-level agreements
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with responsibilities for contingency planning and/or alternate site arrangements
  • organizational personnel with information security responsibilities

Test

  • Organizational processes for recovery at the alternate site
  • mechanisms supporting and/or implementing recovery at the alternate processing site
Official relationships

Related controls

These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.

Official NIST enhancements

Control enhancements

Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.

Official NIST control enhancement

CP-7(1) — Separation from Primary Site

ModerateHigh

Identify an alternate processing site that is sufficiently separated from the primary processing site to reduce susceptibility to the same threats.

Official discussion

Threats that affect alternate processing sites are defined in organizational assessments of risk and include natural disasters, structural failures, hostile attacks, and errors of omission or commission. Organizations determine what is considered a sufficient degree of separation between primary and alternate processing sites based on the types of threats that are of concern. For threats such as hostile attacks, the degree of separation between sites is less relevant.

Assessment objectives and methods

an alternate processing site that is sufficiently separated from the primary processing site to reduce susceptibility to the same threats is identified.

Examine

  • Contingency planning policy
  • procedures addressing alternate processing sites
  • contingency plan
  • alternate processing site
  • alternate processing site agreements
  • primary processing site agreements
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with contingency plan alternate processing site responsibilities
  • organizational personnel with system recovery responsibilities
  • organizational personnel with information security responsibilities
Related controls
Official NIST control enhancement

CP-7(2) — Accessibility

ModerateHigh

Identify potential accessibility problems to alternate processing sites in the event of an area-wide disruption or disaster and outlines explicit mitigation actions.

Official discussion

Area-wide disruptions refer to those types of disruptions that are broad in geographic scope with such determinations made by organizations based on organizational assessments of risk.

Assessment objectives and methods
  1. CP-07(02)[01]potential accessibility problems to alternate processing sites in the event of an area-wide disruption or disaster are identified;
  2. CP-07(02)[02]explicit mitigation actions to address identified accessibility problems are outlined.

Examine

  • Contingency planning policy
  • procedures addressing alternate processing sites
  • contingency plan
  • alternate processing site
  • alternate processing site agreements
  • primary processing site agreements
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with contingency plan alternate processing site responsibilities
  • organizational personnel with system recovery responsibilities
  • organizational personnel with information security responsibilities
Related controls
Official NIST control enhancement

CP-7(3) — Priority of Service

ModerateHigh

Develop alternate processing site agreements that contain priority-of-service provisions in accordance with availability requirements (including recovery time objectives).

Official discussion

Priority of service agreements refer to negotiated agreements with service providers that ensure that organizations receive priority treatment consistent with their availability requirements and the availability of information resources for logical alternate processing and/or at the physical alternate processing site. Organizations establish recovery time objectives as part of contingency planning.

Assessment objectives and methods

alternate processing site agreements that contain priority-of-service provisions in accordance with availability requirements (including recovery time objectives) are developed.

Examine

  • Contingency planning policy
  • procedures addressing alternate processing sites
  • contingency plan
  • alternate processing site agreements
  • service-level agreements
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with contingency plan alternate processing site responsibilities
  • organizational personnel with system recovery responsibilities
  • organizational personnel with information security responsibilities
  • organizational personnel with responsibility for acquisitions/contractual agreements
Official NIST control enhancement

CP-7(4) — Preparation for Use

High

Prepare the alternate processing site so that the site can serve as the operational site supporting essential mission and business functions.

Official discussion

Site preparation includes establishing configuration settings for systems at the alternate processing site consistent with the requirements for such settings at the primary site and ensuring that essential supplies and logistical considerations are in place.

Assessment objectives and methods

the alternate processing site is prepared so that the site can serve as the operational site supporting essential mission and business functions.

Examine

  • Contingency planning policy
  • procedures addressing alternate processing sites
  • contingency plan
  • alternate processing site
  • alternate processing site agreements
  • alternate processing site configurations
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with contingency plan alternate processing site responsibilities
  • organizational personnel with system recovery responsibilities
  • organizational personnel with information security responsibilities

Test

  • Mechanisms supporting and/or implementing recovery at the alternate processing site
Related controls
Official NIST control enhancement

CP-7(5) — Equivalent Information Security Safeguards

Withdrawn

This enhancement is marked withdrawn in the official OSCAL catalog. Related-control metadata below may identify where its intent was incorporated.

Official NIST control enhancement

CP-7(6) — Inability to Return to Primary Site

Plan and prepare for circumstances that preclude returning to the primary processing site.

Official discussion

There may be situations that preclude an organization from returning to the primary processing site such as if a natural disaster (e.g., flood or a hurricane) damaged or destroyed a facility and it was determined that rebuilding in the same location was not prudent.

Assessment objectives and methods
  1. CP-07(06)[01]circumstances that preclude returning to the primary processing site are planned for;
  2. CP-07(06)[02]circumstances that preclude returning to the primary processing site are prepared for.

Examine

  • Contingency planning policy
  • procedures addressing alternate processing sites
  • contingency plan
  • alternate processing site
  • alternate processing site agreements
  • alternate processing site configurations
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with system reconstitution responsibilities
  • organizational personnel with information security responsibilities
Source record

Authoritative sources