{"data":{"id":"CP-07","name":"Alternate Processing Site","family":"CP","family_name":"Contingency Planning","withdrawn":false,"description":"a. Establish an alternate processing site, including necessary agreements to permit the transfer and resumption of [Assignment: organization-defined system operations] for essential mission and business functions within [Assignment: organization-defined time period consistent with recovery time and recovery point objectives] when the primary processing capabilities are unavailable;\nb. Make available at the alternate processing site, the equipment and supplies required to transfer and resume operations or put contracts in place to support delivery to the site within the organization-defined time period for transfer and resumption; and\nc. Provide controls at the alternate processing site that are equivalent to those at the primary site.","supplemental_guidance":"Alternate processing sites are geographically distinct from primary processing sites and provide processing capability if the primary processing site is not available. The alternate processing capability may be addressed using a physical processing site or other alternatives, such as failover to a cloud-based service provider or other internally or externally provided processing service. Geographically distributed architectures that support contingency requirements may also be considered alternate processing sites. Controls that are covered by alternate processing site agreements include the environmental conditions at alternate sites, access rules, physical and environmental protection requirements, and the coordination for the transfer and assignment of personnel. Requirements are allocated to alternate processing sites that reflect the requirements in contingency plans to maintain essential mission and business functions despite disruption, compromise, or failure in organizational systems.","enhancements":[{"id":"CP-07(01)","name":"Separation from Primary Site","statement":"Identify an alternate processing site that is sufficiently separated from the primary processing site to reduce susceptibility to the same threats.","baselines":["moderate","high"]},{"id":"CP-07(02)","name":"Accessibility","statement":"Identify potential accessibility problems to alternate processing sites in the event of an area-wide disruption or disaster and outlines explicit mitigation actions.","baselines":["moderate","high"]},{"id":"CP-07(03)","name":"Priority of Service","statement":"Develop alternate processing site agreements that contain priority-of-service provisions in accordance with availability requirements (including recovery time objectives).","baselines":["moderate","high"]},{"id":"CP-07(04)","name":"Preparation for Use","statement":"Prepare the alternate processing site so that the site can serve as the operational site supporting essential mission and business functions.","baselines":["high"]},{"id":"CP-07(05)","name":"Equivalent Information Security Safeguards","withdrawn":true,"incorporated_into":["CP-07"]},{"id":"CP-07(06)","name":"Inability to Return to Primary Site","statement":"Plan and prepare for circumstances that preclude returning to the primary processing site.","baselines":[]}],"baseline_low":false,"baseline_moderate":true,"baseline_high":true,"nist_800_53":{"rev5":{"id":"CP-07","name":"Alternate Processing Site","description":"a. Establish an alternate processing site, including necessary agreements to permit the transfer and resumption of [Assignment: organization-defined system operations] for essential mission and business functions within [Assignment: organization-defined time period consistent with recovery time and recovery point objectives] when the primary processing capabilities are unavailable;\nb. Make available at the alternate processing site, the equipment and supplies required to transfer and resume operations or put contracts in place to support delivery to the site within the organization-defined time period for transfer and resumption; and\nc. Provide controls at the alternate processing site that are equivalent to those at the primary site.","discussion":"Alternate processing sites are geographically distinct from primary processing sites and provide processing capability if the primary processing site is not available. The alternate processing capability may be addressed using a physical processing site or other alternatives, such as failover to a cloud-based service provider or other internally or externally provided processing service. Geographically distributed architectures that support contingency requirements may also be considered alternate processing sites. Controls that are covered by alternate processing site agreements include the environmental conditions at alternate sites, access rules, physical and environmental protection requirements, and the coordination for the transfer and assignment of personnel. Requirements are allocated to alternate processing sites that reflect the requirements in contingency plans to maintain essential mission and business functions despite disruption, compromise, or failure in organizational systems.","related_controls":["CP-02","CP-06","CP-08","CP-09","CP-10","MA-06","PE-03","PE-11","PE-12","PE-17","SC-36","SI-13"],"baseline_low":false,"baseline_moderate":true,"baseline_high":true,"baseline_privacy":false,"new_in_rev5":false,"changes_from_rev4":"Control text changes from 'information security safeguards' to 'controls' Discussion expands on controls that are covered by alternate processing site agreements"}},"compliance_mappings":{"iso_27001_2022":["A.5.29","A.5.30","A.7.5","A.8.14"],"iso_27002_2022":["5.29","5.30","8.14"],"cobit_2019":["BAI04","DSS04"],"pci_dss_v4":[],"nist_csf_2":["PR.IR-03","PR.IR-04"],"cis_controls_v8":[],"soc2_tsc":["A1.2"],"finos_ccc":[],"iso_42001_2023":["A.4.5"],"iec_62443":[],"asd_e8":[],"nis2":["Art. 21(2)(c)"],"apra_cps_234":[],"mas_trm":["8"],"pra_op_resilience":["SS1/21-5.3","SS2/21-10.1"],"bsi_grundschutz":["DER.4"],"anssi":["Hygiene.30","SecNumCloud.18.3"],"osfi_b13":["B-13.2.6"],"finma_circular":["IV.E(89)","IV.E(90)","IV.E(91)"],"gdpr":["Art.32(1)(c)"],"dora":["Art.11(3)","Art.12(2)","Art.12(5)"],"bio2":["5.29","5.30","8.14"],"rbi_csf":["ITGRCA.29"],"fisc":["FISC.F5","FISC.O5"],"lgpd_bcb":["BCB.Art.3"],"hkma_tme1":["TME1.6.2","TME1.6.4"],"mlps_2":["8.1.4.9"],"dnb_good_practice":["DNB.11.1","DNB.18.1"],"cra":["CRA.I.2h"],"swift_cscf":[],"cbb_tm":["TM-14"],"cbuae":["CR-13"],"nca_ecc":["3-1","3-2"],"qatar_nia":["BC"],"uae_ia":["T12"],"bog_cisd":["CISD-BCM","CISD-XII"],"bom_ctrm":["5.2"],"cbe_csf":["OVM-2"],"cbn_csf":["Part3.7"],"sa_js2":["JS2-7.5"],"bcbs_239":["Principle 2","Principle 5"],"bot_cyber":["Ch4.2"],"cpmi_pfmi":["CG.RR","PFMI.P17"],"eba_ict":["3.7.2"],"ecb_croe":["CROE.2.5.2"],"hipaa_sr":["§164.308(a)(7)(i)","§164.308(a)(7)(ii)(B)","§164.310(a)(2)(i)"],"iosco_cyber":["PFMI-17","RR-2"],"nydfs_500":["500.16"],"sebi_cscrf":["BCP-DR","RC.RP"],"nerc_cip":[],"nrc_73_54":[],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":[],"api_1164":["Sec 11"],"awia":[],"iaea_nss":[],"pci_pts":[],"fips_140":[],"cbest":[],"tiber_eu":[],"pci_hsm":[],"common_criteria":[],"isae_3402":[],"fca_sysc_13":["SYSC 13.8.1","SYSC 13.8.2"],"fda_21_cfr_11":[],"fda_cyber":[],"hitrust_csf":["12.b"],"iso_27799":["17.2","17.3"],"lloyds_ms":["MS8.6"],"naic_ds":["4F-b"],"nhs_dspt":["NDG-7.1","NDG-7.2"],"pra_ss1_23":["P-IT.3"],"solvency_ii":["DR.266-BCP","EIOPA-ICT-4.10"],"owasp_masvs_v2":[],"csa_ccm_v4":["BCR-03","BCR-11"],"csa_aicm":["BCR-03","BCR-11"],"ccss_v9":[],"mica":["Art.62(5)","Art.62(6)","Art.68(5)"],"basel_sco60":["SCO60.53","SCO60.65"],"bssc":["NOS-07"],"sec_custody_digital":["SEC-CD-12"],"dpdpa":["Rules.6(1)(d)"]},"attack_techniques":[{"id":"T1070","name":"Indicator Removal","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Alternate processing sites with independently-maintained audit logs preserve forensic evidence when adversaries remove indicators at the primary site, enabling post-incident investigation from unaffected records."},{"id":"T1119","name":"Automated Collection","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Alternate processing sites maintain independent data copies that preserve collection targets, ensuring adversary automated collection at the primary site does not compromise the organization's only data instance."},{"id":"T1485","name":"Data Destruction","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Maintaining an alternate processing site with replicated data enables rapid failover when adversaries execute data destruction attacks, preserving operational continuity and data availability."},{"id":"T1486","name":"Data Encrypted for Impact","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Alternate processing sites with independent, replicated data stores provide recovery capability when ransomware encrypts primary site data, enabling operations to resume from unaffected infrastructure."},{"id":"T1490","name":"Inhibit System Recovery","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Maintaining alternate processing infrastructure with independent recovery capabilities ensures that adversary efforts to inhibit system recovery at the primary site do not prevent restoration."},{"id":"T1491","name":"Defacement","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Alternate processing sites with independent web hosting enable rapid service restoration when adversaries deface primary site content, minimizing reputational damage and service disruption."},{"id":"T1561","name":"Disk Wipe","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Alternate processing sites with replicated data provide recovery capability when adversaries perform disk wipe operations at the primary location, preserving both data and operational capacity."},{"id":"T1565","name":"Data Manipulation","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Alternate processing sites with independently-verified data copies provide clean baselines for recovery when adversaries manipulate data at the primary site, ensuring data integrity restoration."},{"id":"T1070.001","name":"Clear Windows Event Logs","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Alternate processing sites with replicated Windows Event Logs preserve security audit evidence when adversaries clear event logs at the primary site to conceal their activities."},{"id":"T1070.002","name":"Clear Linux or Mac System Logs","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Alternate processing sites with replicated syslog infrastructure preserve Linux and macOS system logs when adversaries clear logs at the primary site to remove evidence of compromise."},{"id":"T1070.008","name":"Clear Mailbox Data","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Alternate processing sites with replicated email archives preserve mailbox audit data when adversaries clear mailbox data at the primary site to conceal email-based attack evidence."},{"id":"T1491.001","name":"Internal Defacement","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Alternate processing sites enable rapid restoration of internal portals when adversaries deface internal-facing systems, minimizing operational disruption and employee impact."},{"id":"T1491.002","name":"External Defacement","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Alternate processing sites with independent web hosting provide rapid failover when adversaries deface external websites, restoring public-facing services and minimizing reputational damage."},{"id":"T1561.001","name":"Disk Content Wipe","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Alternate processing sites with replicated storage enable data restoration when adversaries wipe disk content at the primary location, providing recovery from content-level destruction."},{"id":"T1561.002","name":"Disk Structure Wipe","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Alternate processing sites with independent disk images enable full system restoration when adversaries wipe disk structures, preserving partition information and boot records."},{"id":"T1565.001","name":"Stored Data Manipulation","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Alternate processing sites with independently-verified data copies enable detection and restoration of stored data that adversaries manipulate at the primary site for integrity attacks."}],"metadata":{"last_reviewed":"2026-10-03","review_notes":"2026-10-03: iso_27001_2022 A.7.5 added from NIST's SP 800-53 Rev 5 to ISO/IEC 27001:2022 crosswalk (OLIR entry 155), which OSA's mapping now takes as its base. 2026-10-03: nist_csf_2 PR.IR-04 added from NIST's CSF 2.0 to SP 800-53 Rev 5.2.0 crosswalk (OLIR entry 186), which OSA's mapping now takes as its base. 2026-10-03: baselines LMH to -MH, from NIST SP 800-53B Release 5.2.0.","mapping_status":"complete"},"function":"corrective","used_by_patterns":["SP-008","SP-034","SP-054"]}}