Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

NIST SP 800-53 Learning Center

CP-8 — Telecommunications Services

Read the official control and assessment content, then use the separately labeled Bare Metal Cyber perspective to connect the requirement to implementation, evidence, and sustained operation.

5Enhancements
2Parameters
2Baseline memberships
3Assessment methods

CP — Contingency Planning · NIST SP 800-53 Release 5.2.0

ModerateHigh
Official NIST control content

Control statement

Establish alternate telecommunications services, including necessary agreements to permit the resumption of [Organization-defined: system operations] for essential mission and business functions within [Organization-defined: time period] when the primary telecommunications capabilities are unavailable at either the primary or alternate processing or storage sites.

Official NIST discussion

Discussion

Telecommunications services (for data and voice) for primary and alternate processing and storage sites are in scope for [CP-8](#cp-8) . Alternate telecommunications services reflect the continuity requirements in contingency plans to maintain essential mission and business functions despite the loss of primary telecommunications services. Organizations may specify different time periods for primary or alternate sites. Alternate telecommunications services include additional organizational or commercial ground-based circuits or lines, network-based approaches to telecommunications, or the use of satellites. Organizations consider factors such as availability, quality of service, and access when entering into alternate telecommunications agreements.

Official OSCAL parameters

Organization-defined parameters

These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.

system operationssystem operations to be resumed for essential mission and business functions are defined;
time periodtime period within which to resume essential mission and business functions when the primary telecommunications capabilities are unavailable is defined;
Original Bare Metal Cyber perspective

From control text to operational evidence

Use Telecommunications Services as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to resilient operations, recovery priorities, alternate capabilities, and tested restoration.

Implementation workflow

  • Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
  • Resolve each organization-defined parameter before declaring the control implemented.
  • Document how the implementation satisfies every clause of the official control statement.
  • Collect evidence as a normal byproduct of operation rather than only before an assessment.
  • Review exceptions, changes, and monitoring results on a risk-based cadence.

Evidence examples

  • contingency and recovery plans
  • backup success and restoration-test records
  • exercise after-action reports
  • alternate processing or communications agreements

Common failure patterns

  • backups never restored in testing
  • recovery priorities not tied to mission impact
  • plans dependent on unavailable people or facilities
  • exercise findings not tracked to closure

Questions practitioners should ask

  • What risk decision is this control intended to support in this system?
  • Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
  • Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
  • What event or threshold requires the implementation to be reviewed or changed?
Official NIST SP 800-53A content

Assessment objectives and methods

Show the assessment objective

alternate telecommunications services, including necessary agreements to permit the resumption of [Organization-defined: system operations] , are established for essential mission and business functions within [Organization-defined: time period] when the primary telecommunications capabilities are unavailable at either the primary or alternate processing or storage sites.

Examine

  • Contingency planning policy
  • procedures addressing alternate telecommunications services
  • contingency plan
  • primary and alternate telecommunications service agreements
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with contingency plan telecommunications responsibilities
  • organizational personnel with system recovery responsibilities
  • organizational personnel with knowledge of requirements for mission and business functions
  • organizational personnel with information security responsibilities
  • organizational personnel with responsibility for acquisitions/contractual agreements

Test

  • Mechanisms supporting telecommunications
Official relationships

Related controls

These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.

Official NIST enhancements

Control enhancements

Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.

Official NIST control enhancement

CP-8(1) — Priority of Service Provisions

ModerateHigh
  1. (a)Develop primary and alternate telecommunications service agreements that contain priority-of-service provisions in accordance with availability requirements (including recovery time objectives); and
  2. (b)Request Telecommunications Service Priority for all telecommunications services used for national security emergency preparedness if the primary and/or alternate telecommunications services are provided by a common carrier.
Official discussion

Organizations consider the potential mission or business impact in situations where telecommunications service providers are servicing other organizations with similar priority of service provisions. Telecommunications Service Priority (TSP) is a Federal Communications Commission (FCC) program that directs telecommunications service providers (e.g., wireline and wireless phone companies) to give preferential treatment to users enrolled in the program when they need to add new lines or have their lines restored following a disruption of service, regardless of the cause. The FCC sets the rules and policies for the TSP program, and the Department of Homeland Security manages the TSP program. The TSP program is always in effect and not contingent on a major disaster or attack taking place. Federal sponsorship is required to enroll in the TSP program.

Assessment objectives and methods
  1. CP-08(01)(a)
    1. CP-08(01)(a)[01]primary telecommunications service agreements that contain priority-of-service provisions in accordance with availability requirements (including recovery time objectives) are developed;
    2. CP-08(01)(a)[02]alternate telecommunications service agreements that contain priority-of-service provisions in accordance with availability requirements (including recovery time objectives) are developed;
  2. CP-08(01)(b)Telecommunications Service Priority is requested for all telecommunications services used for national security emergency preparedness if the primary and/or alternate telecommunications services are provided by a common carrier.

Examine

  • Contingency planning policy
  • procedures addressing primary and alternate telecommunications services
  • contingency plan
  • primary and alternate telecommunications service agreements
  • Telecommunications Service Priority documentation
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with contingency plan telecommunications responsibilities
  • organizational personnel with system recovery responsibilities
  • organizational personnel with information security responsibilities
  • organizational personnel with responsibility for acquisitions/contractual agreements

Test

  • Mechanisms supporting telecommunications
Official NIST control enhancement

CP-8(2) — Single Points of Failure

ModerateHigh

Obtain alternate telecommunications services to reduce the likelihood of sharing a single point of failure with primary telecommunications services.

Official discussion

In certain circumstances, telecommunications service providers or services may share the same physical lines, which increases the vulnerability of a single failure point. It is important to have provider transparency for the actual physical transmission capability for telecommunication services.

Assessment objectives and methods

alternate telecommunications services to reduce the likelihood of sharing a single point of failure with primary telecommunications services are obtained.

Examine

  • Contingency planning policy
  • procedures addressing primary and alternate telecommunications services
  • contingency plan
  • primary and alternate telecommunications service agreements
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with contingency plan telecommunications responsibilities
  • organizational personnel with system recovery responsibilities
  • primary and alternate telecommunications service providers
  • organizational personnel with information security responsibilities
Official NIST control enhancement

CP-8(3) — Separation of Primary and Alternate Providers

High

Obtain alternate telecommunications services from providers that are separated from primary service providers to reduce susceptibility to the same threats.

Official discussion

Threats that affect telecommunications services are defined in organizational assessments of risk and include natural disasters, structural failures, cyber or physical attacks, and errors of omission or commission. Organizations can reduce common susceptibilities by minimizing shared infrastructure among telecommunications service providers and achieving sufficient geographic separation between services. Organizations may consider using a single service provider in situations where the service provider can provide alternate telecommunications services that meet the separation needs addressed in the risk assessment.

Assessment objectives and methods

alternate telecommunications services from providers that are separated from primary service providers are obtained to reduce susceptibility to the same threats.

Examine

  • Contingency planning policy
  • procedures addressing primary and alternate telecommunications services
  • contingency plan
  • primary and alternate telecommunications service agreements
  • alternate telecommunications service provider site
  • primary telecommunications service provider site
  • other relevant documents or records

Interview

  • Organizational personnel with contingency plan telecommunications responsibilities
  • organizational personnel with system recovery responsibilities
  • primary and alternate telecommunications service providers
  • organizational personnel with information security responsibilities
Official NIST control enhancement

CP-8(4) — Provider Contingency Plan

High
  1. (a)Require primary and alternate telecommunications service providers to have contingency plans;
  2. (b)Review provider contingency plans to ensure that the plans meet organizational contingency requirements; and
  3. (c)Obtain evidence of contingency testing and training by providers [Organization-defined: organization-defined frequency].
Official discussion

Reviews of provider contingency plans consider the proprietary nature of such plans. In some situations, a summary of provider contingency plans may be sufficient evidence for organizations to satisfy the review requirement. Telecommunications service providers may also participate in ongoing disaster recovery exercises in coordination with the Department of Homeland Security and state and local governments. Organizations may use these types of activities to satisfy evidentiary requirements related to service provider contingency plan reviews, testing, and training.

Organization-defined parameters (3)
organization-defined frequency
frequencyfrequency at which to obtain evidence of contingency testing by providers is defined;
frequencyfrequency at which to obtain evidence of contingency training by providers is defined;
Assessment objectives and methods
  1. CP-08(04)(a)
    1. CP-08(04)(a)[01]primary telecommunications service providers are required to have contingency plans;
    2. CP-08(04)(a)[02]alternate telecommunications service providers are required to have contingency plans;
  2. CP-08(04)(b)provider contingency plans are reviewed to ensure that the plans meet organizational contingency requirements;
  3. CP-08(04)(c)
    1. CP-08(04)(c)[01]evidence of contingency testing by providers is obtained [Organization-defined: frequency].
    2. CP-08(04)(c)[02]evidence of contingency training by providers is obtained [Organization-defined: frequency].

Examine

  • Contingency planning policy
  • procedures addressing primary and alternate telecommunications services
  • contingency plan
  • provider contingency plans
  • evidence of contingency testing/training by providers
  • primary and alternate telecommunications service agreements
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with contingency planning, plan implementation, and testing responsibilities
  • primary and alternate telecommunications service providers
  • organizational personnel with information security responsibilities
  • organizational personnel with responsibility for acquisitions/contractual agreements
Related controls
Official NIST control enhancement

CP-8(5) — Alternate Telecommunication Service Testing

Test alternate telecommunication services [Organization-defined: frequency].

Official discussion

Alternate telecommunications services testing is arranged through contractual agreements with service providers. The testing may occur in parallel with normal operations to ensure that there is no degradation in organizational missions or functions.

Organization-defined parameters (1)
frequencyfrequency at which alternate telecommunications services are tested is defined;
Assessment objectives and methods

alternate telecommunications services are tested [Organization-defined: frequency].

Examine

  • Contingency planning policy
  • procedures addressing alternate telecommunications services
  • contingency plan
  • evidence of testing alternate telecommunications services
  • alternate telecommunications service agreements
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with contingency planning, plan implementation, and testing responsibilities
  • alternate telecommunications service providers
  • organizational personnel with information security responsibilities

Test

  • Mechanisms supporting testing alternate telecommunications services
Related controls
Source record

Authoritative sources