Quick-reference card
| Field | Value |
|---|---|
| Control ID | CP-06 |
| Control Name | Alternate Storage Site |
| Framework | NIST SP 800-53 Revision 5 |
| Control Family | Contingency Planning |
| Baselines | Moderate, High |
| Implementation Level | Organization |
| Relevance | First Party and Third Party |
| Risk Severity | Medium |
What this control requires
CP-06 requires organizations to establish and maintain an alternate storage site for backup data that can be retrieved when the primary site is unavailable. This means establishing formal agreements that define storage terms, retrieval procedures, and the security protections the alternate site must uphold.
The requirement goes beyond selecting a remote location. Your alternate storage site must enforce controls equivalent to those at your primary site, covering physical access, environmental protections, and coordination of backup media delivery and retrieval. Without that equivalence, your backup data may be accessible but insufficiently protected, which undermines the entire purpose of maintaining a separate site.
In practice, organizations operating under NIST SP 800-53 Moderate and High baselines must treat this control as a foundational element of their contingency planning program. The Contingency Planning family includes several related controls that work together to protect mission-critical operations. Geographically distributed architectures, including cloud-based storage regions, can satisfy CP-06 requirements when they meet the equivalence standard. The control connects directly to your contingency plan, ensuring that essential mission and business functions survive disruption at the primary site.
Why it matters
Most organizations treat alternate storage as a checkbox in their contingency plan, choosing a second location and assuming the work is done. The real risk emerges when that alternate site lacks equivalent protections or when retrieval agreements haven’t been tested under realistic conditions.
Failure to maintain CP-06 introduces direct audit risk. Federal agencies and contractors undergoing Federal Information Security Management Act (FISMA) assessments or Authorization to Operate (ATO) reviews will face findings if assessors cannot verify that an alternate storage site exists with documented agreements and equivalent controls. For organizations pursuing Federal Risk and Authorization Management Program (FedRAMP) authorization, a gap here can delay or block certification.
Beyond audit consequences, weak alternate storage arrangements create operational fragility. If your primary site experiences a natural disaster, infrastructure failure, or targeted attack, your ability to recover depends entirely on whether backup data is retrievable from a protected alternate location within your defined recovery time objectives (RTO) and recovery point objectives (RPO).
Vendor supply chain risk compounds this problem. When your third-party service providers lack verified alternate storage capabilities, a single disruption can cascade across your operations and theirs simultaneously.
What attackers exploit
- Single points of failure in storage architecture, where primary and backup data share the same physical facility, network segment, or cloud availability zone
- Weak or untested retrieval agreements that prevent timely data recovery when an incident forces failover
- Insufficient environmental controls at the alternate site, leaving backup media vulnerable to physical theft, water damage, or temperature degradation
- Lack of geographic separation between primary and alternate sites, so a regional event affects both simultaneously
- Absent encryption or access controls on backup media during transport or at the alternate facility
How to implement
Establishing a reliable alternate storage site requires more than selecting a secondary location. The challenge is maintaining equivalent protections across two environments while ensuring retrieval actually works when you need it.
For your organization
Start by documenting your alternate storage requirements in your contingency plan. Define the geographic separation you need based on a risk assessment of regional threats, including natural disasters, power grid dependencies, and network infrastructure overlap. The alternate site should be far enough away that a single event cannot affect both locations.
Documentation alone isn’t enough — you must also formalize agreements with the alternate storage provider. These agreements must specify access rules, physical security requirements, environmental protections (temperature, humidity, fire suppression), and coordination procedures for delivering and retrieving backup media. If you use cloud storage regions as your alternate site, verify that the provider’s controls meet your equivalence standard through independent audit reports such as SOC 2 Type II.
Once agreements are in place, implement the following controls at the alternate site to achieve equivalence with your primary facility:
- Physical access controls restricting entry to authorized personnel
- Environmental monitoring and protections matching your primary site
- Encryption of data at rest and in transit between sites
- Logging and monitoring of access to backup media
- Regular testing of retrieval procedures, including timed recovery drills aligned with your RTO and RPO
Where programs most often fall short is in maintenance, not initial setup. Teams fail to update alternate site agreements when primary site controls change, neglect to test retrieval under realistic failure conditions, and assume cloud replication alone satisfies CP-06 without verifying the provider’s physical and environmental controls. Document every test result as evidence for assessors.
For your vendors
When evaluating whether a third-party provider maintains adequate alternate storage, go beyond self-attestation. Request and verify the following:
Questionnaire questions to include:
- Does the vendor maintain an alternate storage site geographically separate from the primary site?
- What formal agreements govern storage and retrieval at the alternate site?
- Are controls at the alternate site equivalent to those at the primary site, and how is equivalence verified?
- What is the vendor’s documented RTO and RPO for data stored at the alternate site?
- When was the last retrieval test performed, and what were the results?
Evidence to request:
- Alternate storage site agreements or contracts
- Most recent contingency plan with alternate storage provisions
- Results from the last retrieval or failover test
- SOC 2 Type II or equivalent audit report covering the alternate site
- Physical security and environmental control documentation for the alternate facility
Red flags to watch for:
- The vendor cannot produce a current alternate storage site agreement
- Primary and alternate sites are in the same geographic region or share infrastructure dependencies
- No documented retrieval tests within the past 12 months
- The vendor relies solely on cloud replication without independent verification of the provider’s controls
- Alternate site access controls are less restrictive than primary site controls
Red flags in any of these areas warrant deeper scrutiny. Verify claims by cross-referencing the vendor’s contingency plan with their alternate site agreements. If the vendor uses a cloud provider, request the cloud provider’s SOC 2 report and confirm that the specific storage region serves as the designated alternate site.
Evidence examples
| Evidence Type | Example Artifact |
|---|---|
| Contingency planning policy | Organizational policy defining requirements for alternate storage sites, including geographic separation and control equivalence standards |
| Alternate storage site agreement | Signed contract with the alternate site provider specifying access rules, environmental protections, retrieval procedures, and security requirements |
| Contingency plan | Current contingency plan identifying the designated alternate storage site, RTO/RPO targets, and failover procedures |
| Retrieval test results | Documentation of the most recent backup retrieval drill, including time-to-recovery measurements and identified gaps |
| Physical security documentation | Access control logs, visitor records, and environmental monitoring reports from the alternate storage facility |
| System security plan | System security plan sections describing how alternate storage site controls meet equivalence requirements relative to the primary site |
Cross-framework mapping
| Framework | Control(s) | Coverage |
|---|---|---|
| ISO 27001:2022 | 5.29 Information security during disruption | Partial |
| ISO 27001:2022 | 7.5 Protecting against physical and environmental threats | Partial |
| ISO 27001:2022 | 8.14 Redundancy of information processing facilities | Partial |
Related controls
- CP-02 — Contingency Plan: defines the overarching plan that CP-06 supports by designating where backup data resides during a disruption
- CP-07 — Alternate Processing Site: addresses the processing counterpart to alternate storage, ensuring compute capacity survives a primary site failure
- CP-08 — Telecommunications Services: covers the communication links needed to access and retrieve data from the alternate storage site
- CP-09 — System Backup: governs the creation of the backup data that CP-06 protects at the alternate location
- CP-10 — System Recovery and Reconstitution: defines how systems are restored using data retrieved from the alternate storage site
- MP-04 — Media Storage: specifies protections for storage media at both primary and alternate locations
- MP-05 — Media Transport: addresses security of backup media during transit between primary and alternate sites
- PE-03 — Physical Access Control: establishes the physical access requirements that the alternate site must match for control equivalence
- SC-36 — Distributed Processing and Storage: covers architectures that distribute data across multiple sites, which may satisfy CP-06 when properly configured
- SI-13 — Predictable Failure Prevention: supports proactive measures that reduce the likelihood of needing to failover to the alternate site
Frequently asked questions
What is NIST SP 800-53 CP-06
CP-06 requires organizations to establish an alternate storage site with formal agreements that permit the storage and retrieval of system backup information, while maintaining controls equivalent to the primary site. The control falls within the Contingency Planning family and applies to Moderate and High baselines. Your alternate storage site agreements must address physical access, environmental protections, and coordination of backup media delivery to satisfy assessor requirements.
What happens if CP-06 is not implemented
Without an established alternate storage site, your organization cannot recover critical data if the primary storage location becomes unavailable due to a disaster, infrastructure failure, or attack. Assessors evaluating your system under FISMA or FedRAMP will issue findings for the absence of documented alternate storage site agreements and equivalent controls. The resulting audit risk can delay authorization decisions and weaken your overall contingency planning posture.
How do you audit CP-06
Auditing CP-06 starts with verifying that an alternate storage site exists and that formal agreements are in place governing storage, retrieval, and security protections. Assessors review the contingency plan to confirm it references the alternate site and defines retrieval procedures. They then compare the controls at the alternate site against those at the primary site to verify equivalence, examining physical access control documentation, environmental monitoring records, and the results of the most recent retrieval test.
What is the difference between an alternate storage site and an alternate processing site
An alternate storage site holds duplicate copies of backup data and system information, while an alternate processing site provides the compute capacity to run systems when the primary processing location is unavailable. CP-06 governs the storage side, and CP-07 governs the processing side. In practice, your contingency plan needs both, because retrievable backup data is only useful if you also have a functioning environment to restore and run those systems.