IBM Cloud Docs
CP-6 - Alternate Storage Site

CP-6 - Alternate Storage Site

Control requirements

The organization:

CP-6 (a)
Establishes an alternate storage site including necessary agreements to permit the storage and retrieval of information system backup information; and
CP-6 (b)
Ensures that the alternate storage site provides information security safeguards equivalent to that of the primary site.

Implementation guidance

See the resources that follow to learn more about how to implement this control.

IBM Cloud for Financial Services profile

The rules related to this control that follow are part of the IBM Cloud for Financial Services v1.2.0 profile in IBM Cloud® Security and Compliance Center.

Rules for CP-6 in IBM Cloud for Financial Services v1.2.0 profile
Requirement ID Rules
CP-6 (a)
  • Check whether Cloud Object Storage bucket resiliency is set to cross region
  • Check that any Cloud Object Storage buckets used by Activity Tracker Event Routing are configured as cross-region
  • Check that Hyper Protect Crypto Services has failover units in at least 2 different regions that are Financial Services Validated
CP-6 (b)
  • Check whether Cloud Object Storage bucket resiliency is set to cross region
  • Check that any Cloud Object Storage buckets used by Activity Tracker Event Routing are configured as cross-region
  • Check that Hyper Protect Crypto Services has failover units in at least 2 different regions that are Financial Services Validated

NIST supplemental guidance

Alternate storage sites are sites that are geographically distinct from primary storage sites. An alternate storage site maintains duplicate copies of information and data in the event that the primary storage site is not available. Items covered by alternate storage site agreements include, for example, environmental conditions at alternate sites, access rules, physical and environmental protection requirements, and coordination of delivery/retrieval of backup media. Alternate storage sites reflect the requirements in contingency plans so that organizations can maintain essential missions/business functions despite disruption, compromise, or failure in organizational information systems.