
| Applicable (Y)es / (N)o | (C)onfidentiality | (I)ntegrity | (A)vailability | RPN (C+I+A) | (S)atisfactory | ||||||
| L1 | M2 | H3 | L1 | M2 | H3 | L1 | M2 | H3 | (O)ther than satisfactory +## | ||
| 
 | 
 | 
 | 
 | 
 | 
 | 
 | 
 | 
 | 
 | 
 | 
 | 
###
| cp-6 | alternate storage site | |
| 
 | assessment objective: Determine if the organization: | |
| cp-6[1] | establishes an alternate storage site including necessary agreements to permit the storage and retrieval of information system backup information; and | |
| cp-6[2] | ensures that the alternate storage site provides information security safeguards equivalent to that of the primary site. | |
| potential assessment methods and objects: Examine: [select from: Contingency planning policy; procedures addressing alternate storage sites; contingency plan; alternate storage site agreements; primary storage site agreements; other relevant documents or records]. Interview: [select from: Organizational personnel with contingency plan alternate storage site responsibilities; organizational personnel with information system recovery responsibilities; organizational personnel with information security responsibilities]. Test: [SELECT FROM: Organizational processes for storing and retrieving information system backup information at the alternate storage site; automated mechanisms supporting and/or implementing storage and retrieval of information system backup information at the alternate storage site]. | ||