← Controls / CP

CP-07 Alternate Processing Site

Contingency Planning

Moderate High

Description

a. Establish an alternate processing site, including necessary agreements to permit the transfer and resumption of [Assignment: organization-defined system operations] for essential mission and business functions within [Assignment: organization-defined time period consistent with recovery time and recovery point objectives] when the primary processing capabilities are unavailable; b. Make available at the alternate processing site, the equipment and supplies required to transfer and resume operations or put contracts in place to support delivery to the site within the organization-defined time period for transfer and resumption; and c. Provide controls at the alternate processing site that are equivalent to those at the primary site.

Supplemental Guidance

Alternate processing sites are geographically distinct from primary processing sites and provide processing capability if the primary processing site is not available. The alternate processing capability may be addressed using a physical processing site or other alternatives, such as failover to a cloud-based service provider or other internally or externally provided processing service. Geographically distributed architectures that support contingency requirements may also be considered alternate processing sites. Controls that are covered by alternate processing site agreements include the environmental conditions at alternate sites, access rules, physical and environmental protection requirements, and the coordination for the transfer and assignment of personnel. Requirements are allocated to alternate processing sites that reflect the requirements in contingency plans to maintain essential mission and business functions despite disruption, compromise, or failure in organizational systems.

Changes from Rev 4

Control text changes from 'information security safeguards' to 'controls' Discussion expands on controls that are covered by alternate processing site agreements

Enhancements (5)

What NIST adds to this control. Select one to read its statement.

CP-07(01) Separation from Primary Site ModerateHigh

Identify an alternate processing site that is sufficiently separated from the primary processing site to reduce susceptibility to the same threats.

CP-07(02) Accessibility ModerateHigh

Identify potential accessibility problems to alternate processing sites in the event of an area-wide disruption or disaster and outlines explicit mitigation actions.

CP-07(03) Priority of Service ModerateHigh

Develop alternate processing site agreements that contain priority-of-service provisions in accordance with availability requirements (including recovery time objectives).

CP-07(04) Preparation for Use High

Prepare the alternate processing site so that the site can serve as the operational site supporting essential mission and business functions.

CP-07(06) Inability to Return to Primary Site

Plan and prepare for circumstances that preclude returning to the primary processing site.

Withdrawn by NIST:

  • CP-07(05) Equivalent Information Security Safeguards, now in CP-07

Patterns that use this control (3)

Grouped by the emphasis each pattern gives it.

Compliance Mappings

ISO 27001:2022

A.5.29A.5.30A.7.5A.8.14

ISO 27002:2022

5.295.308.14

COBIT 2019

BAI04DSS04

NIST CSF 2.0

PR.IR-03PR.IR-04

SOC 2 TSC

A1.2

CSA CCM v4

BCR-03BCR-11

CSA AICM v1

BCR-03BCR-11

ISO 42001:2023

A.4.5

NIS2 Directive

Art. 21(2)(c)

PRA Operational Resilience

SS1/21-5.3SS2/21-10.1

MAS TRM

8

BSI IT-Grundschutz

DER.4

ANSSI

Hygiene.30SecNumCloud.18.3

FINMA Circular 2023/1

IV.E(89)IV.E(90)IV.E(91)

OSFI B-13

B-13.2.6

EU GDPR

Art.32(1)(c)

EU DORA

Art.11(3)Art.12(2)Art.12(5)

BIO2

5.295.308.14

RBI CSF

ITGRCA.29

FISC Security Guidelines

FISC.F5FISC.O5

LGPD + BCB 4893

BCB.Art.3

HKMA TM-E-1

TME1.6.2TME1.6.4

MLPS 2.0

8.1.4.9

DNB Good Practice

DNB.11.1DNB.18.1

EU CRA

CRA.I.2h

NCA ECC

3-13-2

UAE IA

T12

CBB TM

TM-14

Qatar NIA

BC

CBUAE

CR-13

CBE CSF

OVM-2

SA JS2

JS2-7.5

CBN CSF

Part3.7

BoG CISD

CISD-BCMCISD-XII

BoM CTRM

5.2

IOSCO Cyber Resilience

PFMI-17RR-2

BCBS 239

Principle 2Principle 5

CPMI-IOSCO PFMI

CG.RRPFMI.P17

NYDFS 500

500.16

HIPAA Security Rule

§164.308(a)(7)(i)§164.308(a)(7)(ii)(B)§164.310(a)(2)(i)

ECB CROE

CROE.2.5.2

EBA ICT Guidelines

3.7.2

SEBI CSCRF

BCP-DRRC.RP

BOT Cyber Resilience

Ch4.2

API 1164

Sec 11

Solvency II

DR.266-BCPEIOPA-ICT-4.10

Lloyd's Minimum Standards

MS8.6

NAIC Insurance Data Security

4F-b

PRA SS1/23

P-IT.3

FCA SYSC 13

SYSC 13.8.1SYSC 13.8.2

HITRUST CSF v11

12.b

ISO 27799

17.217.3

NHS DSPT

NDG-7.1NDG-7.2

MiCA

Art.62(5)Art.62(6)Art.68(5)

Basel SCO60

SCO60.53SCO60.65

BSSC Standards

NOS-07

SEC Custody (Digital Assets)

SEC-CD-12

India DPDPA

Rules.6(1)(d)

ISO 17799 (legacy)

14.1.4

COBIT 4.1 (legacy)

DS4.1DS4.8