Cyber Posture

NIST 800-53 r5 · Controls catalogue · Family CP

CP-7Alternate Processing Site

Establish an alternate processing site, including necessary agreements to permit the transfer and resumption of {{ insert: param, cp-07_odp.01 }} for essential mission and business functions within {{ insert: param, cp-07_odp.02 }} when the primary processing capabilities are unavailable; Make available at the alternate processing site, the equipment and supplies required to transfer and resume operations or put contracts in place to support delivery to the site within the organization-defined time period for transfer and resumption; and Provide controls at the alternate processing site that are equivalent to those at the primary site.

Last updated: 09 May 2026 03:25 UTC

Implementations targeting this control (0)

ATT&CK techniques this control mitigates (16)

Weaknesses this control addresses (6)AI

CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.

CWE Name CVEs Why this control addresses it
CWE-400Uncontrolled Resource Consumption3,324Alternate site allows resumption of operations if resource exhaustion at the primary site is exploited to cause unavailability.
CWE-770Allocation of Resources Without Limits or Throttling1,979Provides continuity when unbounded resource allocation at the primary site leads to exhaustion and downtime.
CWE-835Loop with Unreachable Exit Condition ('Infinite Loop')924Enables transfer to alternate site if an infinite loop at the primary renders processing unavailable.
CWE-674Uncontrolled Recursion442Supports resumption at alternate site when uncontrolled recursion causes primary site failure or crash.
CWE-405Asymmetric Resource Consumption (Amplification)40Reduces impact of amplification attacks that overwhelm the primary site by allowing operations to shift to an equivalent alternate site.
CWE-406Insufficient Control of Network Message Volume (Network Amplification)15Limits attacker success in sustaining network amplification DoS against the primary by providing a ready alternate processing capability.

Top CVEs where this control is the strongest mitigation

CVE Risk CVSS EPSS Match
No CVEs annotated to this control yet — the per-CVE backfill is in progress.

Other controls in family CP

CP-1 CP-10 CP-11 CP-12 CP-13 CP-2 CP-3 CP-4 CP-5 CP-6 CP-8 CP-9