Skip to main content
Dark green background, "Weak Application Security Can Cost You Millions," 3 slanted images of fingers pointing to digital locks, and a "Learn the Basics" button
Category: Business Continuity & Resilience

Alternate Processing

Also known as: Alternate Processing Site, CP-7
Simply put

Alternate processing refers to having a backup location or capability that can take over an organization's essential information system operations if the primary site becomes unavailable. This may be a separate physical facility or an alternative such as failover to a cloud-based service provider. The goal is to allow critical business functions to resume when the main processing site cannot operate.

Formal definition

In the context of contingency planning, alternate processing (addressed by control CP-7, Alternate Processing Site, in the NIST SP 800-53 Rev. 5 Contingency Planning family) is the identification and preparation of an alternate processing capability, together with necessary agreements, to permit resumption of information system operations supporting essential mission and business functions when the primary processing site is unavailable. Alternate processing sites are typically geographically distinct from the primary site to reduce shared susceptibility to the same disruptive event, and the alternate capability may be realized through a physical site or alternatives such as failover to a cloud-based service provider. Leading practice, as reflected in these control descriptions, calls for the alternate site to provide information security safeguards equivalent to those of the primary site. Specific requirements, applicability, and implementation detail vary by framework edition, regulatory regime, and organizational context, and framework language evolves across editions; primary sources should be verified for exact parameters.

Why it matters

Information systems that support essential mission and business functions can be rendered unavailable by a wide range of disruptive events, from natural disasters and power failures to cyber incidents affecting a primary data center. Without a prepared capability to shift processing elsewhere, an organization may face prolonged interruption of the functions that depend on those systems. Alternate processing addresses this by identifying and preparing a backup location or capability, along with the agreements needed to invoke it, so that critical operations can resume when the primary processing site cannot operate.

A distinguishing feature reflected in the control descriptions is that alternate processing sites are typically geographically distinct from the primary site. This separation is intended to reduce the likelihood that a single event affects both locations at once, since co-located or nearby facilities may share susceptibility to the same regional disruption. The capability may be realized through a physical facility or through alternatives such as failover to a cloud-based service provider, giving organizations flexibility in how they meet their resilience objectives.

Equally important is that the alternate capability should not become a weaker point in the organization's security posture. Leading practice, as reflected in these control descriptions, calls for the alternate site to provide information security safeguards equivalent to those of the primary site, so that resuming operations elsewhere does not trade availability for a degradation in confidentiality or integrity. It should be noted that specific requirements, applicability, and implementation detail vary by framework edition, regulatory regime, and organizational context, and exact parameters should be verified against primary sources.

Who it's relevant to

Business Continuity and Contingency Planning Teams
Those responsible for contingency planning use alternate processing as a core element of preparing for primary site unavailability. They identify the alternate capability, establish the agreements needed to invoke it, and prepare the site so it can support essential mission and business functions during a disruption.
Risk Managers
Risk professionals treat alternate processing as a measure that modifies availability-related risk to essential functions. They assess whether the geographic separation and readiness of the alternate capability adequately address the potential for a single event to affect both primary and backup sites, recognizing that no such measure eliminates risk entirely.
Information Security and Compliance Officers
Security and compliance staff verify that the alternate site provides information security safeguards equivalent to those of the primary site, so that resilience is not achieved at the expense of protection. Where alternate processing is realized through a cloud-based service provider, they also consider the associated third-party and shared-responsibility implications.
Organizations Subject to Frameworks Referencing CP-7
Entities operating under NIST SP 800-53, FedRAMP, or sector-specific control catalogs that incorporate CP-7 must interpret and implement alternate processing according to the applicable edition and regulatory regime. Because requirements and parameters vary by context and evolve across framework editions, these organizations should confirm exact obligations against the governing primary source and seek professional advice where legal interpretation is involved.

Inside Alternate Processing

Alternate Processing Site
A designated facility or environment where critical business operations or IT processing can be resumed when the primary location is unavailable. Such sites are commonly categorized by readiness level, often described as hot, warm, or cold sites, reflecting the degree to which infrastructure and data are pre-positioned and available for use.
Recovery Objectives
Parameters that typically govern alternate processing arrangements, most notably the Recovery Time Objective (RTO), which reflects the targeted duration for restoring processing, and the Recovery Point Objective (RPO), which reflects the acceptable extent of data loss measured back from the point of disruption. These objectives are usually derived from a business impact analysis.
Contingency and Continuity Linkage
Alternate processing is generally a component of broader business continuity and IT disaster recovery planning. It functions as a control that modifies the risk of prolonged operational disruption, and is often addressed in continuity frameworks and information security guidance, though specific requirements vary by jurisdiction, sector, and organization.
Activation and Failover Procedures
Documented processes describing the conditions, authority, and steps required to switch operations from the primary to the alternate environment, and to return afterward. Clear decision rights over activation connect this operational control to governance structures.
Data Replication and Synchronization
The mechanisms by which data is copied or mirrored to the alternate environment so that processing can resume with acceptable currency. The chosen approach typically influences the achievable RPO, and arrangements vary widely across organizations.

Common questions

Answers to the questions practitioners most commonly ask about Alternate Processing.

Is alternate processing the same as having a backup of your data?
No. Alternate processing refers to the capability to continue or resume processing operations at a different site or by different means when a primary facility or system is unavailable, whereas data backup concerns the copying and retention of data so it can be restored. Backups are typically a prerequisite for effective alternate processing, but they are not equivalent: having recoverable data does not by itself provide the processing environment, infrastructure, or personnel needed to run operations. In many business continuity and IT contingency frameworks these are treated as distinct, complementary controls.
Does establishing an alternate processing site guarantee that operations will continue without interruption?
Not necessarily. An alternate processing capability is a control intended to reduce the impact of a disruption, but it does not eliminate the risk of interruption or guarantee an outcome. The degree of continuity achievable depends on factors such as the type of alternate arrangement, how current the replicated data and configurations are, the time required to activate the site, and whether staff can reach or access it. Residual risk typically remains, and the effectiveness of the arrangement is generally demonstrated through testing rather than assumed.
What types of alternate processing arrangements are commonly distinguished?
Practitioners often distinguish arrangements by their readiness and cost, commonly described along a spectrum. So-called hot sites are typically fully equipped and kept current so they can be activated quickly; warm sites usually have some infrastructure in place but require additional configuration or data loading; and cold sites generally provide basic facilities that must be substantially provisioned before use. Cloud-based, reciprocal, and mobile arrangements are also used. The appropriate choice generally depends on recovery objectives, cost tolerance, and the criticality of the affected processes, and terminology can vary across organizations and frameworks.
How does an organization decide which processes require alternate processing capability?
This decision is typically informed by a business impact analysis, which assesses how the disruption of particular processes would affect objectives over time and helps establish recovery priorities and target timeframes. Processes assessed as more critical, or those with lower tolerance for downtime, generally warrant more robust and readily available alternate arrangements. The analysis is often aligned with the organization's risk appetite and tolerance, since more capable arrangements usually carry higher cost. Applicability and rigor vary by sector, size, and any regulatory expectations that apply.
How is the effectiveness of an alternate processing arrangement validated?
Effectiveness is commonly validated through testing and exercises, which may range from walkthroughs and tabletop discussions to partial or full failover tests that actually shift processing to the alternate capability. Testing is generally intended to confirm that recovery objectives can be met, that data and configurations are sufficiently current, and that personnel understand their roles. Results typically feed back into updates of the arrangement. The frequency and depth of testing vary by organization and may be shaped by internal policy, leading practice, or applicable regulatory expectations.
How does alternate processing relate to broader business continuity and disaster recovery planning?
Alternate processing is generally one component within broader business continuity and disaster recovery planning rather than a standalone control. Business continuity typically addresses sustaining critical functions across people, processes, facilities, and technology, while disaster recovery often focuses more specifically on restoring IT systems and infrastructure. Alternate processing capability supports both by providing the means to run operations when primary resources are unavailable, but it typically needs to be coordinated with data backup, communications plans, staffing arrangements, and vendor dependencies to function as intended.

Common misconceptions

Having an alternate processing site guarantees that operations will continue without interruption.
An alternate processing arrangement is a control that reduces the impact of a disruption; it does not eliminate the underlying risk. Its effectiveness depends on factors such as data currency, activation procedures, staffing, and regular testing, and residual risk typically remains.
Alternate processing and backup are the same thing.
Data backup preserves copies of information for restoration, whereas alternate processing concerns the capacity to resume operational processing at a different location or environment. Backups often support alternate processing but do not by themselves provide a running operational capability.
A single readiness tier is appropriate for every process.
Readiness levels such as hot, warm, or cold sites represent trade-offs between cost and recovery speed. The appropriate tier typically depends on recovery objectives derived from a business impact analysis, so different processes may warrant different arrangements.

Best practices

Derive alternate processing arrangements from a business impact analysis, aligning the chosen readiness tier with defined RTO and RPO for each critical process.
Test failover and return-to-primary procedures on a regular basis, and document lessons learned to keep the capability effective rather than assuming it works.
Define clear decision rights and activation authority so that the choice to invoke alternate processing connects to appropriate governance and escalation paths.
Verify that data replication or synchronization approaches support the intended RPO, and confirm the currency and integrity of data available at the alternate environment.
Address people and access dependencies, including staffing, remote connectivity, and credentials needed to operate from the alternate environment.
Confirm that alternate processing arrangements are consistent with applicable continuity, security, and regulatory expectations for your jurisdiction and sector, seeking professional advice where obligations are unclear.
Promotional banner for the Penetration Report Template Kit