{"data":{"id":"CP-06","name":"Alternate Storage Site","family":"CP","family_name":"Contingency Planning","withdrawn":false,"description":"a. Establish an alternate storage site, including necessary agreements to permit the storage and retrieval of system backup information; and\nb. Ensure that the alternate storage site provides controls equivalent to that of the primary site.","supplemental_guidance":"Alternate storage sites are geographically distinct from primary storage sites and maintain duplicate copies of information and data if the primary storage site is not available. Similarly, alternate processing sites provide processing capability if the primary processing site is not available. Geographically distributed architectures that support contingency requirements may be considered alternate storage sites. Items covered by alternate storage site agreements include environmental conditions at the alternate sites, access rules for systems and facilities, physical and environmental protection requirements, and coordination of delivery and retrieval of backup media. Alternate storage sites reflect the requirements in contingency plans so that organizations can maintain essential mission and business functions despite compromise, failure, or disruption in organizational systems.","enhancements":[{"id":"CP-06(01)","name":"Separation from Primary Site","statement":"Identify an alternate storage site that is sufficiently separated from the primary storage site to reduce susceptibility to the same threats.","baselines":["moderate","high"]},{"id":"CP-06(02)","name":"Recovery Time and Recovery Point Objectives","statement":"Configure the alternate storage site to facilitate recovery operations in accordance with recovery time and recovery point objectives.","baselines":["high"]},{"id":"CP-06(03)","name":"Accessibility","statement":"Identify potential accessibility problems to the alternate storage site in the event of an area-wide disruption or disaster and outline explicit mitigation actions.","baselines":["moderate","high"]}],"baseline_low":false,"baseline_moderate":true,"baseline_high":true,"nist_800_53":{"rev5":{"id":"CP-06","name":"Alternate Storage Site","description":"a. Establish an alternate storage site, including necessary agreements to permit the storage and retrieval of system backup information; and\nb. Ensure that the alternate storage site provides controls equivalent to that of the primary site.","discussion":"Alternate storage sites are geographically distinct from primary storage sites and maintain duplicate copies of information and data if the primary storage site is not available. Similarly, alternate processing sites provide processing capability if the primary processing site is not available. Geographically distributed architectures that support contingency requirements may be considered alternate storage sites. Items covered by alternate storage site agreements include environmental conditions at the alternate sites, access rules for systems and facilities, physical and environmental protection requirements, and coordination of delivery and retrieval of backup media. Alternate storage sites reflect the requirements in contingency plans so that organizations can maintain essential mission and business functions despite compromise, failure, or disruption in organizational systems.","related_controls":["CP-02","CP-07","CP-08","CP-09","CP-10","MP-04","MP-05","PE-03","SC-36","SI-13"],"baseline_low":false,"baseline_moderate":true,"baseline_high":true,"baseline_privacy":false,"new_in_rev5":false,"changes_from_rev4":""}},"compliance_mappings":{"iso_27001_2022":["A.5.29","A.7.5","A.8.13","A.8.14"],"iso_27002_2022":["5.29","8.13","8.14"],"cobit_2019":["DSS04"],"pci_dss_v4":[],"nist_csf_2":["PR.DS-11","PR.IR-04"],"cis_controls_v8":["CIS 11","CIS 11.3","CIS 11.4"],"soc2_tsc":["A1.2"],"finos_ccc":["CCC-C13"],"iso_42001_2023":[],"iec_62443":["3-3 SR 7.3"],"asd_e8":["E8-8","E8-8 ML2"],"nis2":["Art. 21(2)(c)"],"apra_cps_234":[],"mas_trm":["8"],"pra_op_resilience":["SS1/21-5.3","SS2/21-10.1"],"bsi_grundschutz":["CON.3","DER.4"],"anssi":["Hygiene.30","SecNumCloud.18.3"],"osfi_b13":["B-13.2.6"],"finma_circular":["IV.E(89)","IV.E(90)","IV.E(91)"],"gdpr":["Art.32(1)(c)"],"dora":["Art.12(2)","Art.12(5)"],"bio2":["5.29","8.13","8.14"],"rbi_csf":["ITGRCA.29"],"fisc":["FISC.F5","FISC.O5"],"lgpd_bcb":["BCB.Art.3"],"hkma_tme1":["TME1.6.2","TME1.6.4"],"mlps_2":["8.1.4.9"],"dnb_good_practice":["DNB.11.3"],"cra":[],"swift_cscf":[],"cbb_tm":["TM-14"],"cbuae":["CR-13"],"nca_ecc":["2-9","3-1","3-2"],"qatar_nia":["BC"],"uae_ia":["T7","T12"],"bog_cisd":["CISD-BCM","CISD-XII"],"bom_ctrm":["5.2"],"cbe_csf":["OVM-2"],"cbn_csf":["Part3.7"],"sa_js2":["JS2-7.5"],"bot_cyber":["Ch4.2"],"cpmi_pfmi":["CG.RR","PFMI.P17"],"eba_ict":["3.7.2"],"ecb_croe":["CROE.2.5.2"],"hipaa_sr":["§164.308(a)(7)(i)","§164.308(a)(7)(ii)(A)","§164.308(a)(7)(ii)(B)","§164.310(d)(2)(iv)"],"iosco_cyber":["PFMI-17","RR-2"],"nydfs_500":["500.16"],"sebi_cscrf":["BCP-DR","RC.RP"],"nerc_cip":[],"nrc_73_54":[],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":[],"api_1164":["Sec 11"],"awia":[],"iaea_nss":["Sec 8"],"pci_pts":[],"fips_140":[],"cbest":[],"tiber_eu":[],"pci_hsm":[],"common_criteria":[],"isae_3402":[],"fca_sysc_13":["SYSC 13.8.1","SYSC 13.8.2"],"fda_21_cfr_11":["§11.10(c)"],"fda_cyber":[],"hitrust_csf":["09.d","12.b"],"iso_27799":["12.3","17.2","17.3"],"lloyds_ms":["MS8.6"],"naic_ds":["4F-b"],"nhs_dspt":["NDG-7.1","NDG-7.2"],"pra_ss1_23":[],"solvency_ii":["DR.266-BCP","EIOPA-ICT-4.10"],"owasp_masvs_v2":[],"csa_ccm_v4":["BCR-08"],"csa_aicm":["BCR-08"],"ccss_v9":["1.03.4"],"mica":["Art.62(6)","Art.68(5)"],"basel_sco60":["SCO60.63"],"bssc":[],"sec_custody_digital":["SEC-CD-06","SEC-CD-08","SEC-CD-12"],"dpdpa":["Rules.6(1)(d)"]},"attack_techniques":[{"id":"T1070","name":"Indicator Removal","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Alternate storage sites with independently-maintained log archives preserve forensic evidence when adversaries remove indicators from primary storage, enabling investigation from unaffected backup copies."},{"id":"T1119","name":"Automated Collection","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Alternate storage sites maintain independent copies of data that adversaries target with automated collection, ensuring organizational data survives even if primary stores are compromised."},{"id":"T1486","name":"Data Encrypted for Impact","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Alternate storage sites provide offline or immutable data copies that are immune to ransomware encryption affecting the primary environment, enabling data restoration without paying ransom demands."},{"id":"T1565","name":"Data Manipulation","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Alternate storage with independently-verified data copies provides clean recovery baselines when adversaries manipulate data at the primary site, enabling integrity restoration from untampered copies."},{"id":"T1070.001","name":"Clear Windows Event Logs","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Alternate storage sites with replicated Windows Event Log archives preserve security audit evidence when adversaries clear event logs at the primary location to conceal attack activity."},{"id":"T1070.002","name":"Clear Linux or Mac System Logs","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Alternate storage sites with replicated syslog archives preserve Linux and macOS system logs when adversaries clear log files at the primary location to remove forensic evidence."},{"id":"T1070.008","name":"Clear Mailbox Data","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Alternate storage sites with email archive replication preserve mailbox audit data when adversaries clear mailbox content at the primary site to eliminate evidence of email-based operations."},{"id":"T1565.001","name":"Stored Data Manipulation","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Alternate storage with independently-hashed data copies enables detection and recovery from stored data manipulation, since tampered primary data can be compared against clean alternate-site copies."}],"metadata":{"last_reviewed":"2026-10-03","review_notes":"2026-10-03: iso_27001_2022 A.7.5 added from NIST's SP 800-53 Rev 5 to ISO/IEC 27001:2022 crosswalk (OLIR entry 155), which OSA's mapping now takes as its base. 2026-10-03: nist_csf_2 PR.IR-04 added from NIST's CSF 2.0 to SP 800-53 Rev 5.2.0 crosswalk (OLIR entry 186), which OSA's mapping now takes as its base. 2026-10-03: baselines LMH to -MH, from NIST SP 800-53B Release 5.2.0.","mapping_status":"complete"},"function":"corrective","used_by_patterns":["SP-008","SP-034","SP-054"]}}