CP-8: Telecommunications Services

CP-08 requires organizations to establish alternate telecommunications services that keep essential operations running when primary voice

Quick-reference card

FieldValue
Control IDCP-08
Control NameTelecommunications Services
FrameworkNIST SP 800-53, Revision 5
Control FamilyContingency Planning
BaselinesMODERATE HIGH
Implementation LevelOrganization
RelevanceOrganization (First Party and Third Party)
Risk SeverityMedium

What this control requires

CP-08 requires organizations to establish alternate telecommunications services that keep essential operations running when primary voice or data connections fail. That means identifying every telecom dependency across primary and alternate processing and storage sites, then securing contractual agreements for backup connectivity that meet your contingency plan’s recovery timelines.

In practice, this control forces a conversation most organizations avoid until it’s too late. You need to map which contingency planning functions depend on which telecom circuits, determine how long each function can tolerate an outage, and negotiate alternate service agreements that close those gaps.

Specifically, the scope covers both data and voice services, so a plan that only addresses network connectivity while ignoring phone systems doesn’t satisfy the requirement. When you define alternate telecom services, you’re selecting from options like redundant ground-based circuits, network-based failover paths, or satellite links. Your choice depends on three factors that your contingency plan should document explicitly: availability guarantees, quality of service requirements, and access conditions during a disruption.

Why it matters

Most organizations treat telecommunications redundancy as an infrastructure concern rather than a compliance obligation, and that gap creates real audit exposure. When assessors evaluate CP-08, they’re looking for documented agreements with alternate telecom providers and evidence that those agreements align with recovery time objectives in your contingency plan.

The result is direct audit risk that can escalate quickly. For organizations operating at MODERATE or HIGH baselines, a missing or undocumented alternate telecom agreement is a clear deficiency that assessors will flag during authorization assessments, potentially resulting in certification withdrawal or regulatory findings.

In practice, this means telecom disruption doesn’t just affect your own operations. If your organization provides services to other agencies or handles data for downstream partners, a prolonged telecom outage cascades into third-party impacts that attract additional scrutiny. Organizations subject to NIST SP 800-53 requirements often discover this dependency mapping exercise reveals more critical telecom paths than originally assumed.

Where this breaks down in practice is during natural disasters and regional infrastructure events. A single weather event or construction accident can sever telecom lines serving multiple facilities simultaneously. Organizations that haven’t verified the physical routing of their primary and alternate circuits often discover both paths share the same conduit or last-mile connection, and when that shared segment fails, the “alternate” service fails with it.

Specifically, the control enhancements for CP-08 address each of these vulnerabilities. Enhancement CP-8(1) requires priority-of-service provisions in telecom agreements, CP-8(2) targets single points of failure, and CP-8(3) mandates separation between primary and alternate providers. For HIGH baseline systems, CP-8(4) requires that providers themselves maintain contingency plans.

What attackers exploit

  • Single-provider dependency, where an organization routes all voice and data through one carrier, creating a single point of failure that targeted denial-of-service attacks or physical sabotage can exploit
  • Undocumented failover paths, where alternate circuits exist on paper but haven’t been tested, leaving recovery teams unable to activate backup connectivity during an actual disruption
  • Co-located primary and backup circuits, where both the primary and alternate telecom lines follow the same physical route or enter the same facility through the same conduit, meaning a single cable cut disables both
  • Expired service-level agreements, where organizations negotiated alternate telecom contracts years ago but never reviewed whether the terms still cover current bandwidth, latency, and availability needs
  • Uncoordinated recovery priorities, where the alternate telecom activation sequence doesn’t align with the contingency plan’s recovery order, causing lower-priority functions to consume available bandwidth before critical systems reconnect

How to implement

Telecom redundancy planning fails most often when organizations treat it as a one-time procurement exercise rather than an ongoing alignment between contingency requirements and service agreements.

For your organization

Under the hood, implementation starts with inventorying every telecommunications service your organization depends on for essential mission and business functions. Document the provider, circuit type, bandwidth, and termination points for each connection at both primary and alternate processing sites.

In practice, this means mapping each telecom service to the specific contingency plan functions it supports. Your contingency plan should define recovery time objectives for these functions, and your alternate telecom agreements need to meet or exceed those timelines. If your contingency plan says a function must resume within four hours, an alternate telecom agreement with a 24-hour activation window creates a gap you’ll need to close.

The result is a set of requirements that feed directly into negotiating alternate telecommunications service agreements that specify activation procedures, service-level commitments, and escalation paths. These agreements should address availability guarantees, quality of service minimums, and access conditions during regional disruptions.

Take geographic diversity as a specific example. If your primary circuits run through a specific exchange or cable path, your alternate should follow a physically separate route. Many organizations discover during testing that their “alternate” provider leases capacity on the same last-mile infrastructure as the primary.

But in most environments, the agreements are only as good as their testing — exercise your alternate telecom services at least annually as part of contingency plan testing. Document the results, including activation time, achieved bandwidth, and any degradation in voice or data quality.

Where this breaks down is in the details that teams overlook. These include assuming that a second internet connection from the same provider constitutes an alternate service (it often doesn’t, since both may share upstream infrastructure), failing to update agreements when bandwidth requirements change, and neglecting to include voice services in the scope of your alternate telecom arrangements. Organizations using business continuity management tools or telecom monitoring platforms can automate parts of the inventory and testing process.

Specifically, produce and maintain these artifacts: an inventory of primary and alternate telecom services, copies of all alternate service agreements, test results from failover exercises, and records showing that agreements align with contingency plan recovery objectives. Organizations subject to regulatory frameworks like IRS Publication 1075 should also verify that their alternate telecom services meet any additional requirements for handling sensitive data during failover.

For your vendors

When evaluating vendors who process or store your data, you need to verify that their telecom redundancy meets your continuity requirements. A vendor’s telecom failure can disrupt your operations just as effectively as your own, which is why information security during disruption is a cross-framework concern.

Specifically, in security questionnaires, ask vendors to describe their alternate telecommunications arrangements for both primary and alternate processing sites. Request documentation of their alternate telecom service agreements, including provider names, activation timelines, and service-level commitments.

Where this breaks down for most vendors is untested failover. Request evidence that vendors test their alternate telecom services regularly and look for failover test reports that show actual activation times and performance metrics during the test. A vendor who can produce an agreement but has never tested activation is a red flag worth investigating.

In practice, this means verifying that your vendors’ telecom recovery timelines align with the service-level agreements you hold with them. If your contract requires four-hour recovery and their alternate telecom takes 12 hours to activate, you have an unmitigated dependency that should be documented in your risk register. You should also confirm that your vendors’ incident reporting processes include notification procedures for telecom outages affecting your data or services.

But in most vendor assessments, the real warning signs are structural. Red flags to watch for include vendors who list the same carrier for primary and alternate services, vendors whose alternate telecom agreements reference facilities in the same geographic area as their primary site, and vendors who cannot produce evidence of failover testing within the past 12 months. Vendor risk management tools that aggregate questionnaire responses can help you identify these patterns across your vendor portfolio.

Evidence examples

Evidence TypeExample Artifact
Contingency planning policyPolicy document defining telecommunications redundancy requirements, alternate service selection criteria, and review cadence
Alternate telecom proceduresProcedures for activating alternate telecommunications services, including step-by-step failover instructions and escalation contacts
Contingency planContingency plan sections mapping essential functions to primary and alternate telecom services with recovery time objectives
Telecom service agreementsPrimary and alternate telecommunications service contracts specifying activation timelines, bandwidth commitments, and geographic diversity
Failover test recordsTest reports documenting alternate telecom activation results, achieved performance metrics, and identified gaps
System security planSystem security plan sections describing telecom architecture, redundancy design, and CP-08 implementation status

Cross-framework mapping

FrameworkControl(s)Coverage
ISO 27001:20225.29 Information security during disruptionPartial
ISO 27001:20227.11 Supporting utilitiesPartial
  • CP-02 — Contingency Plan: defines the overarching continuity strategy that CP-08’s alternate telecom services must support and align with
  • CP-06 — Alternate Storage Site: establishes the alternate storage locations whose telecom connectivity CP-08 must cover
  • CP-07 — Alternate Processing Site: identifies alternate processing facilities that require the telecom services addressed by CP-08
  • CP-11 — Alternate Communications Protocols: provides fallback communication methods when both primary and alternate telecom services are unavailable
  • SC-07 — Boundary Protection: governs the network boundary controls that apply to both primary and alternate telecom connections

Frequently asked questions

What is NIST SP 800-53 CP-08?

CP-08 requires organizations to establish alternate telecommunications services, including contractual agreements with backup providers, that allow essential mission and business functions to resume within defined time periods when primary voice or data connections become unavailable. The control applies at MODERATE and HIGH baselines and covers both primary and alternate processing and storage sites. Your alternate telecom arrangements must reflect the recovery priorities documented in your contingency plan.

What happens if CP-08 is not implemented?

Without alternate telecommunications service agreements in place, your organization faces a direct compliance deficiency that assessors will document during authorization evaluations. Beyond the audit finding, a telecom outage without pre-negotiated backup services means your contingency plan cannot execute as designed, leaving essential functions offline for an indeterminate period. For organizations at MODERATE or HIGH baselines, this gap can delay or prevent authorization decisions.

How do you audit CP-08?

Auditors verify CP-08 by examining your alternate telecommunications service agreements and confirming they include activation timelines, service-level commitments, and coverage for both primary and alternate processing sites. They then compare those agreements against the recovery time objectives in your contingency plan to confirm alignment. Assessors also review failover test records to verify that alternate telecom services have been activated and validated within the past testing cycle.

What are alternate telecommunications services under NIST 800-53?

Alternate telecommunications services are backup voice and data connections that organizations arrange in advance to maintain essential operations when primary telecom capabilities fail. These services include additional ground-based circuits or lines from geographically diverse providers, network-based failover approaches that route traffic through separate infrastructure, and satellite-based communications for locations where terrestrial options are limited. The selection of alternate services should account for three factors: availability guarantees, quality of service requirements, and access conditions during widespread disruptions.

Experience superior visibility and a simpler approach to cyber risk management