Quick-reference card
| Field | Value |
|---|---|
| Control ID | CP-11 |
| Control Name | Alternate Communications Protocols |
| Framework | NIST SP 800-53, Revision 5 |
| Control Family | Contingency Planning |
| Baselines | None assigned |
| Implementation Level | Organization |
| Relevance | Organization (First Party and Third Party) |
| Risk Severity | Low |
What this control requires
CP-11 requires your organization to establish and maintain the capability to use alternate communications protocols to support continuity of operations. When primary communication channels fail or become compromised, you need pre-planned alternatives ready to activate without delay.
In practice, this means your contingency planning program must go beyond listing backup tools. CP-11 specifically targets the communications layer within the broader NIST SP 800-53 framework, recognizing that even the most robust contingency plan falls apart if teams can’t coordinate their response.
Specifically, your contingency plan must document which alternate protocols your organization will use, how personnel will switch to them, and what operational impacts that switch may introduce. The control also requires you to assess potential side effects before implementation, since changing communications protocols can affect software applications, network configurations, and day-to-day workflows.
Why it matters
Communications infrastructure is often the first casualty during a significant disruption. Whether the cause is a natural disaster, a ransomware attack that takes down email servers, or a targeted denial-of-service campaign against your primary channels, the inability to coordinate a response compounds every other problem your team faces.
The compliance consequence is direct. Failing to maintain this control introduces audit risk and may result in certification withdrawal or regulatory findings. Assessors look for documented alternate communications capabilities as part of contingency planning reviews, and the absence of this control signals a gap in your organization’s resilience posture.
Where this breaks down in practice is even more concerning. Without alternate protocols, your incident response team can’t communicate during the exact moments when communication matters most. Response times increase, decisions get delayed, and the blast radius of any disruption grows.
What attackers exploit
- Single points of failure in communications infrastructure. If all coordination happens over one platform, compromising that platform silences your entire response capability.
- Lack of out-of-band communication channels. Attackers who gain access to your primary network often monitor internal communications, making it critical to have channels they can’t observe.
- Untested failover procedures. Organizations that haven’t practiced switching protocols fumble the transition during real incidents, creating windows of uncoordinated response.
- Dependency on internet-based communications during outages. When connectivity is the problem, internet-dependent backup channels provide no actual redundancy.
How to implement
Implementing CP-11 requires you to identify, document, test, and maintain alternate communications protocols that your teams can activate when primary channels become unavailable. The challenge isn’t selecting a backup tool; it’s building the organizational muscle memory to switch protocols under pressure.
For your organization
Start by inventorying your current communications dependencies. Map out every protocol and platform your teams rely on for day-to-day operations, incident response coordination, and executive decision-making. This inventory becomes the foundation for identifying what needs a backup.
But inventory alone doesn’t close the gap. You need to select alternate protocols that provide genuine redundancy. If your primary communications run over your corporate network, your alternates should function independently of that network. Examples include satellite phones for voice communications, cellular-based messaging applications for text coordination, high-frequency radio for environments where all digital infrastructure may be unavailable, and out-of-band management interfaces for critical systems administration.
But identifying alternatives isn’t enough without documented activation procedures. Your contingency plan must specify a clear trigger condition for each alternate protocol, a step-by-step activation procedure, a list of personnel who need access, and pre-configured credentials or equipment. Don’t assume people will figure it out during a crisis.
In practice, switching protocols also introduces side effects you need to assess before a real incident. Changing communications protocols can affect automated alerting systems, integration workflows between security tools, and the ability to share files or screen data. Document these impacts and develop workarounds.
Take testing as a concrete example of where organizations fall short. Tabletop exercises should simulate scenarios where primary channels are unavailable, forcing participants to practice the switch. Your disaster recovery plan testing should validate that alternate protocols actually work from your recovery sites. Use your NIST 800-53 compliance checklist to verify that testing documentation captures the results.
The result is that training becomes the final link in the chain. All relevant personnel need to know when and how to activate alternate protocols, including not just the IT team but also executives, communications staff, and any role involved in incident response.
For your vendors
Assess whether your critical vendors have documented alternate communications protocols as part of their own contingency plans. Request evidence that they’ve identified backup channels for coordinating with your organization during disruptions.
Specifically, you should establish pre-agreed alternate communication methods with each critical vendor. During a vendor’s outage or security incident, you need a way to reach their incident response team that doesn’t depend on the infrastructure that may be affected. Document these agreements and include contact details for out-of-band channels.
In practice, this means including alternate communications capabilities in your third-party risk assessment criteria. Ask vendors to demonstrate that they’ve tested their alternate protocols and can provide evidence of those tests. Vendors that rely entirely on a single communications platform represent a concentration risk to your own continuity of operations.
Specifically, this obligation doesn’t end at onboarding. As your organization’s requirements evolve, ensure that vendor agreements reflect current expectations for alternate communications capabilities. This is particularly important for vendors who provide critical services or have access to sensitive data.
Where this often breaks down is ongoing monitoring. A protocol that was tested two years ago and never revisited provides limited assurance. Include communications resilience in your ongoing vendor monitoring program.
Evidence examples
| Evidence Type | Example Artifact |
|---|---|
| Policy and procedures | Contingency planning policy that addresses alternate communications requirements, with supporting procedures for protocol activation and deactivation |
| Contingency and continuity plans | Contingency plan and continuity of operations plan sections that document specific alternate protocols, trigger conditions, and activation steps |
| System documentation | System design documentation and configuration settings showing how alternate communications protocols integrate with existing infrastructure |
| Protocol inventory | Documented list of alternate communications protocols with assigned use cases, coverage areas, and responsible personnel |
| Testing records | Contingency plan test results demonstrating successful activation and use of alternate communications protocols |
| Security plan | System security plan sections addressing communications resilience and alternate protocol risk assessments |
Cross-framework mapping
| Framework | Control(s) | Coverage |
|---|---|---|
| ISO 27001:2022 | 5.29 Information security during disruption | Partial |
Related controls
- CP-02 — Contingency Plan: CP-11’s alternate communications protocols are a component of the broader contingency plan that CP-02 requires organizations to develop and maintain.
- CP-08 — Telecommunications Services: While CP-08 addresses the availability of telecommunications services themselves, CP-11 focuses on the protocols and methods used over those services.
- CP-13 — Alternative Security Mechanisms: CP-13 addresses backup security mechanisms more broadly, complementing CP-11’s specific focus on communications protocols.
Frequently asked questions
What is NIST SP 800-53 CP-11?
CP-11 is a NIST SP 800-53 control that requires organizations to provide the capability to employ alternate communications protocols in support of maintaining continuity of operations. It ensures that when primary communication channels fail, pre-planned alternatives are available for coordination during disruptions.
This control falls within the Contingency Planning family and applies at the organizational level. Unlike controls that address the availability of telecommunications infrastructure itself, CP-11 focuses on the protocols and methods your teams use to communicate, ensuring redundancy exists at the application layer.
What happens if CP-11 is not implemented?
Failure to implement CP-11 creates a gap in your contingency planning posture that assessors will flag during compliance audits. Organizations without documented alternate communications protocols risk audit findings, delayed certification, or regulatory scrutiny, particularly in regulated industries where continuity of operations is a compliance requirement.
The operational consequence is equally significant. Without alternate protocols, your incident response team loses coordination capability during the exact scenarios where communication is most critical. This extends response times and increases the potential impact of any disruption.
How do you audit CP-11?
Auditors assess CP-11 by examining your contingency plan for documented alternate communications protocols and verifying that those protocols have been tested. They’ll review your contingency planning policy, procedures for activating alternate protocols, system design documentation, and test results.
Key evidence includes a current list of alternate communications protocols, configuration settings showing how those protocols integrate with your systems, and records demonstrating that personnel have been trained on activation procedures. Auditors also look for evidence that your organization assessed the potential side effects of switching protocols before implementation.
What are examples of alternate communications protocols?
Alternate communications protocols span a range of technologies depending on your organization’s risk profile and operational environment. Common examples include satellite phone systems for voice communications independent of terrestrial networks, encrypted messaging applications operating over cellular networks, high-frequency or very-high-frequency radio systems for environments where all digital infrastructure may be unavailable, and out-of-band management interfaces such as dedicated management networks for critical systems administration.
The key principle is genuine redundancy. Your alternate protocols should not share failure modes with your primary channels. If your primary communications depend on corporate network connectivity, your alternates should function without it.