NIST 800-53 REV 5 • CONTINGENCY PLANNING
CP-6 — Alternate Storage Site
Establish an alternate storage site, including necessary agreements to permit the storage and retrieval of system backup information; and Ensure that the alternate storage site provides controls equivalent to that of the primary site.
Supplemental Guidance
Alternate storage sites are geographically distinct from primary storage sites and maintain duplicate copies of information and data if the primary storage site is not available. Similarly, alternate processing sites provide processing capability if the primary processing site is not available. Geographically distributed architectures that support contingency requirements may be considered alternate storage sites. Items covered by alternate storage site agreements include environmental conditions at the alternate sites, access rules for systems and facilities, physical and environmental protection requirements, and coordination of delivery and retrieval of backup media. Alternate storage sites reflect the requirements in contingency plans so that organizations can maintain essential mission and business functions despite compromise, failure, or disruption in organizational systems.
Practitioner Notes
An alternate storage site is a separate location where you keep copies of your backups and critical data. If your primary location is destroyed, you can recover from the alternate site.
Example 1: Replicate your backups to an Azure Blob Storage account in a different geographic region using geo-redundant storage (GRS) or to an offsite Veeam Cloud Connect repository.
Example 2: Store encrypted backup tapes at a secure offsite facility like Iron Mountain, with documented procedures for retrieving them in an emergency.