This page is classified as INTERNAL.
NIST 800-53 (r4) Control:
The organization configures the alternate storage site to facilitate recovery operations in accordance with recovery time and recovery point objectives.
NIST 800-53 (r4) Supplemental Guidance:
None
NIST 800-53 (r5) Discussion:
Organizations establish recovery time and recovery point objectives as part of contingency planning. Configuration of the alternate storage site includes physical facilities and the systems supporting recovery operations that ensure accessibility and correct execution.
38North Guidance:
Meets Minimum Requirement:
CPs must include an alternate storage site configured to facilitate recovery operations that can meet the RTOs and RPOs of the organization and SLA agreements with customers.
Best Practice:
TBD.
Unofficial FedRAMP Guidance: None.
Assessment Evidence:
Alternate storage site agreements.
Data backup and restoration documents including information with how the alternate storage site is configured to support emergency recovery operations.
Backup schedule and configuration showing backups are available at the alternate storage site.
CSP Implementation Tips:
Amazon Web Services (AWS): TBD
Microsoft Azure: TBD
Google Cloud Platform: TBD