Browse 1,193 controls and enhancements across 20 security and privacy families. Use the GovRAMP crosswalk to locate controls referenced by Security Snapshot, Core, and Moderate.
A shared catalog supports common-control planning; designation as a common, hybrid, or system-specific control depends on your organization’s implementation and inheritance decisions.
Sources and crosswalk scope
NIST OSCAL content 5.1.1+u4, retrieved 2026-09-18. GovRAMP Snapshot v1.4 and Core selection from Moderate v1.06 reference the December 2020 Rev. 5 text. Mappings establish exact identifier correspondence, not identical requirements, inherited implementation, or GovRAMP authorization. GovRAMP parameters and additional requirements remain authoritative for each program. Full Moderate, High, and other programs are not mapped here. Withdrawn controls are retained for reference.
Official pinned NIST sourceSHA-256: 81cf2de45ede9aef3de7ce09d65ea9d32f662c483bbf916f6e346292b22f7763
Contingency Planning · Enhancement
CP-4(5) · Self-challenge
View parent controlControl statement and discussion
NIST control statement
Employ [Assignment: mechanisms] to [Assignment: system or system component] to disrupt and adversely affect the system or system component.
Discussion
Often, the best method of assessing system resilience is to disrupt the system in some manner. The mechanisms used by the organization could disrupt system functions or system services in many ways, including terminating or disabling critical system components, changing the configuration of system components, degrading critical functionality (e.g., restricting network bandwidth), or altering privileges. Automated, on-going, and simulated cyber-attacks and service disruptions can reveal unexpected functional dependencies and help the organization determine its ability to ensure resilience in the face of an actual cyber-attack.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Contingency Planning · Base control
CP-6 · Alternate Storage Site
Control statement and discussion
NIST control statement
a. Establish an alternate storage site, including necessary agreements to permit the storage and retrieval of system backup information; and
b. Ensure that the alternate storage site provides controls equivalent to that of the primary site.
Discussion
Alternate storage sites are geographically distinct from primary storage sites and maintain duplicate copies of information and data if the primary storage site is not available. Similarly, alternate processing sites provide processing capability if the primary processing site is not available. Geographically distributed architectures that support contingency requirements may be considered alternate storage sites. Items covered by alternate storage site agreements include environmental conditions at the alternate sites, access rules for systems and facilities, physical and environmental protection requirements, and coordination of delivery and retrieval of backup media. Alternate storage sites reflect the requirements in contingency plans so that organizations can maintain essential mission and business functions despite compromise, failure, or disruption in organizational systems.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · CP-6 — Direct NIST identifier reference. GovRAMP source matrix
Contingency Planning · Enhancement
CP-6(1) · Separation from Primary Site
View parent controlControl statement and discussion
NIST control statement
Identify an alternate storage site that is sufficiently separated from the primary storage site to reduce susceptibility to the same threats.
Discussion
Threats that affect alternate storage sites are defined in organizational risk assessments and include natural disasters, structural failures, hostile attacks, and errors of omission or commission. Organizations determine what is considered a sufficient degree of separation between primary and alternate storage sites based on the types of threats that are of concern. For threats such as hostile attacks, the degree of separation between sites is less relevant.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · CP-6 (1) — Direct NIST identifier reference. GovRAMP source matrix
Contingency Planning · Enhancement
CP-6(2) · Recovery Time and Recovery Point Objectives
View parent controlControl statement and discussion
NIST control statement
Configure the alternate storage site to facilitate recovery operations in accordance with recovery time and recovery point objectives.
Discussion
Organizations establish recovery time and recovery point objectives as part of contingency planning. Configuration of the alternate storage site includes physical facilities and the systems supporting recovery operations that ensure accessibility and correct execution.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Contingency Planning · Enhancement
CP-6(3) · Accessibility
View parent controlControl statement and discussion
NIST control statement
Identify potential accessibility problems to the alternate storage site in the event of an area-wide disruption or disaster and outline explicit mitigation actions.
Discussion
Area-wide disruptions refer to those types of disruptions that are broad in geographic scope with such determinations made by organizations based on organizational assessments of risk. Explicit mitigation actions include duplicating backup information at other alternate storage sites if access problems occur at originally designated alternate sites or planning for physical access to retrieve backup information if electronic accessibility to the alternate site is disrupted.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · CP-6 (3) — Direct NIST identifier reference. GovRAMP source matrix
Contingency Planning · Base control
CP-7 · Alternate Processing Site
Control statement and discussion
NIST control statement
a. Establish an alternate processing site, including necessary agreements to permit the transfer and resumption of [Assignment: system operations] for essential mission and business functions within [Assignment: time period] when the primary processing capabilities are unavailable;
b. Make available at the alternate processing site, the equipment and supplies required to transfer and resume operations or put contracts in place to support delivery to the site within the organization-defined time period for transfer and resumption; and
c. Provide controls at the alternate processing site that are equivalent to those at the primary site.
Discussion
Alternate processing sites are geographically distinct from primary processing sites and provide processing capability if the primary processing site is not available. The alternate processing capability may be addressed using a physical processing site or other alternatives, such as failover to a cloud-based service provider or other internally or externally provided processing service. Geographically distributed architectures that support contingency requirements may also be considered alternate processing sites. Controls that are covered by alternate processing site agreements include the environmental conditions at alternate sites, access rules, physical and environmental protection requirements, and the coordination for the transfer and assignment of personnel. Requirements are allocated to alternate processing sites that reflect the requirements in contingency plans to maintain essential mission and business functions despite disruption, compromise, or failure in organizational systems.
GovRAMP crosswalk
- GovRAMP Core Readiness — 60 Controls · CP-7 — Direct NIST identifier reference. GovRAMP source matrix
- GovRAMP Moderate Readiness · CP-7 — Direct NIST identifier reference. GovRAMP source matrix
Contingency Planning · Enhancement
CP-7(1) · Separation from Primary Site
View parent controlControl statement and discussion
NIST control statement
Identify an alternate processing site that is sufficiently separated from the primary processing site to reduce susceptibility to the same threats.
Discussion
Threats that affect alternate processing sites are defined in organizational assessments of risk and include natural disasters, structural failures, hostile attacks, and errors of omission or commission. Organizations determine what is considered a sufficient degree of separation between primary and alternate processing sites based on the types of threats that are of concern. For threats such as hostile attacks, the degree of separation between sites is less relevant.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · CP-7 (1) — Direct NIST identifier reference. GovRAMP source matrix
Contingency Planning · Enhancement
CP-7(2) · Accessibility
View parent controlControl statement and discussion
NIST control statement
Identify potential accessibility problems to alternate processing sites in the event of an area-wide disruption or disaster and outlines explicit mitigation actions.
Discussion
Area-wide disruptions refer to those types of disruptions that are broad in geographic scope with such determinations made by organizations based on organizational assessments of risk.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · CP-7 (2) — Direct NIST identifier reference. GovRAMP source matrix
Contingency Planning · Enhancement
CP-7(3) · Priority of Service
View parent controlControl statement and discussion
NIST control statement
Develop alternate processing site agreements that contain priority-of-service provisions in accordance with availability requirements (including recovery time objectives).
Discussion
Priority of service agreements refer to negotiated agreements with service providers that ensure that organizations receive priority treatment consistent with their availability requirements and the availability of information resources for logical alternate processing and/or at the physical alternate processing site. Organizations establish recovery time objectives as part of contingency planning.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · CP-7 (3) — Direct NIST identifier reference. GovRAMP source matrix
Contingency Planning · Enhancement
CP-7(4) · Preparation for Use
View parent controlControl statement and discussion
NIST control statement
Prepare the alternate processing site so that the site can serve as the operational site supporting essential mission and business functions.
Discussion
Site preparation includes establishing configuration settings for systems at the alternate processing site consistent with the requirements for such settings at the primary site and ensuring that essential supplies and logistical considerations are in place.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Contingency Planning · Enhancement
CP-7(6) · Inability to Return to Primary Site
View parent controlControl statement and discussion
NIST control statement
Plan and prepare for circumstances that preclude returning to the primary processing site.
Discussion
There may be situations that preclude an organization from returning to the primary processing site such as if a natural disaster (e.g., flood or a hurricane) damaged or destroyed a facility and it was determined that rebuilding in the same location was not prudent.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Contingency Planning · Base control
CP-8 · Telecommunications Services
Control statement and discussion
NIST control statement
Establish alternate telecommunications services, including necessary agreements to permit the resumption of [Assignment: system operations] for essential mission and business functions within [Assignment: time period] when the primary telecommunications capabilities are unavailable at either the primary or alternate processing or storage sites.
Discussion
Telecommunications services (for data and voice) for primary and alternate processing and storage sites are in scope for [CP-8](#cp-8) . Alternate telecommunications services reflect the continuity requirements in contingency plans to maintain essential mission and business functions despite the loss of primary telecommunications services. Organizations may specify different time periods for primary or alternate sites. Alternate telecommunications services include additional organizational or commercial ground-based circuits or lines, network-based approaches to telecommunications, or the use of satellites. Organizations consider factors such as availability, quality of service, and access when entering into alternate telecommunications agreements.
GovRAMP crosswalk
- GovRAMP Core Readiness — 60 Controls · CP-8 — Direct NIST identifier reference. GovRAMP source matrix
- GovRAMP Moderate Readiness · CP-8 — Direct NIST identifier reference. GovRAMP source matrix
Contingency Planning · Enhancement
CP-8(1) · Priority of Service Provisions
View parent controlControl statement and discussion
NIST control statement
(a) Develop primary and alternate telecommunications service agreements that contain priority-of-service provisions in accordance with availability requirements (including recovery time objectives); and
(b) Request Telecommunications Service Priority for all telecommunications services used for national security emergency preparedness if the primary and/or alternate telecommunications services are provided by a common carrier.
Discussion
Organizations consider the potential mission or business impact in situations where telecommunications service providers are servicing other organizations with similar priority of service provisions. Telecommunications Service Priority (TSP) is a Federal Communications Commission (FCC) program that directs telecommunications service providers (e.g., wireline and wireless phone companies) to give preferential treatment to users enrolled in the program when they need to add new lines or have their lines restored following a disruption of service, regardless of the cause. The FCC sets the rules and policies for the TSP program, and the Department of Homeland Security manages the TSP program. The TSP program is always in effect and not contingent on a major disaster or attack taking place. Federal sponsorship is required to enroll in the TSP program.
GovRAMP crosswalk
- GovRAMP Core Readiness — 60 Controls · CP-8 (1) — Direct NIST identifier reference. GovRAMP source matrix
- GovRAMP Moderate Readiness · CP-8 (1) — Direct NIST identifier reference. GovRAMP source matrix
Contingency Planning · Enhancement
CP-8(2) · Single Points of Failure
View parent controlControl statement and discussion
NIST control statement
Obtain alternate telecommunications services to reduce the likelihood of sharing a single point of failure with primary telecommunications services.
Discussion
In certain circumstances, telecommunications service providers or services may share the same physical lines, which increases the vulnerability of a single failure point. It is important to have provider transparency for the actual physical transmission capability for telecommunication services.
GovRAMP crosswalk
- GovRAMP Core Readiness — 60 Controls · CP-8 (2) — Direct NIST identifier reference. GovRAMP source matrix
- GovRAMP Moderate Readiness · CP-8 (2) — Direct NIST identifier reference. GovRAMP source matrix
Contingency Planning · Enhancement
CP-8(3) · Separation of Primary and Alternate Providers
View parent controlControl statement and discussion
NIST control statement
Obtain alternate telecommunications services from providers that are separated from primary service providers to reduce susceptibility to the same threats.
Discussion
Threats that affect telecommunications services are defined in organizational assessments of risk and include natural disasters, structural failures, cyber or physical attacks, and errors of omission or commission. Organizations can reduce common susceptibilities by minimizing shared infrastructure among telecommunications service providers and achieving sufficient geographic separation between services. Organizations may consider using a single service provider in situations where the service provider can provide alternate telecommunications services that meet the separation needs addressed in the risk assessment.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Contingency Planning · Enhancement
CP-8(4) · Provider Contingency Plan
View parent controlControl statement and discussion
NIST control statement
(a) Require primary and alternate telecommunications service providers to have contingency plans;
(b) Review provider contingency plans to ensure that the plans meet organizational contingency requirements; and
(c) Obtain evidence of contingency testing and training by providers [Assignment: organization-defined frequency].
Discussion
Reviews of provider contingency plans consider the proprietary nature of such plans. In some situations, a summary of provider contingency plans may be sufficient evidence for organizations to satisfy the review requirement. Telecommunications service providers may also participate in ongoing disaster recovery exercises in coordination with the Department of Homeland Security and state and local governments. Organizations may use these types of activities to satisfy evidentiary requirements related to service provider contingency plan reviews, testing, and training.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Contingency Planning · Enhancement
CP-8(5) · Alternate Telecommunication Service Testing
View parent controlControl statement and discussion
NIST control statement
Test alternate telecommunication services [Assignment: frequency].
Discussion
Alternate telecommunications services testing is arranged through contractual agreements with service providers. The testing may occur in parallel with normal operations to ensure that there is no degradation in organizational missions or functions.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Contingency Planning · Base control
CP-9 · System Backup
Control statement and discussion
NIST control statement
a. Conduct backups of user-level information contained in [Assignment: system components] [Assignment: frequency];
b. Conduct backups of system-level information contained in the system [Assignment: frequency];
c. Conduct backups of system documentation, including security- and privacy-related documentation [Assignment: frequency] ; and
d. Protect the confidentiality, integrity, and availability of backup information.
Discussion
System-level information includes system state information, operating system software, middleware, application software, and licenses. User-level information includes information other than system-level information. Mechanisms employed to protect the integrity of system backups include digital signatures and cryptographic hashes. Protection of system backup information while in transit is addressed by [MP-5](#mp-5) and [SC-8](#sc-8) . System backups reflect the requirements in contingency plans as well as other organizational requirements for backing up information. Organizations may be subject to laws, executive orders, directives, regulations, or policies with requirements regarding specific categories of information (e.g., personal health information). Organizational personnel consult with the senior agency official for privacy and legal counsel regarding such requirements.
GovRAMP crosswalk
- GovRAMP Core Readiness — 60 Controls · CP-9 — Direct NIST identifier reference. GovRAMP source matrix
- GovRAMP Moderate Readiness · CP-9 — Direct NIST identifier reference. GovRAMP source matrix
Contingency Planning · Enhancement
CP-9(1) · Testing for Reliability and Integrity
View parent controlControl statement and discussion
NIST control statement
Test backup information [Assignment: organization-defined frequency] to verify media reliability and information integrity.
Discussion
Organizations need assurance that backup information can be reliably retrieved. Reliability pertains to the systems and system components where the backup information is stored, the operations used to retrieve the information, and the integrity of the information being retrieved. Independent and specialized tests can be used for each of the aspects of reliability. For example, decrypting and transporting (or transmitting) a random sample of backup files from the alternate storage or backup site and comparing the information to the same information at the primary processing site can provide such assurance.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · CP-9 (1) — Direct NIST identifier reference. GovRAMP source matrix
Contingency Planning · Enhancement
CP-9(2) · Test Restoration Using Sampling
View parent controlControl statement and discussion
NIST control statement
Use a sample of backup information in the restoration of selected system functions as part of contingency plan testing.
Discussion
Organizations need assurance that system functions can be restored correctly and can support established organizational missions. To ensure that the selected system functions are thoroughly exercised during contingency plan testing, a sample of backup information is retrieved to determine whether the functions are operating as intended. Organizations can determine the sample size for the functions and backup information based on the level of assurance needed.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Contingency Planning · Enhancement
CP-9(3) · Separate Storage for Critical Information
View parent controlControl statement and discussion
NIST control statement
Store backup copies of [Assignment: critical system software and other security-related information] in a separate facility or in a fire rated container that is not collocated with the operational system.
Discussion
Separate storage for critical information applies to all critical information regardless of the type of backup storage media. Critical system software includes operating systems, middleware, cryptographic key management systems, and intrusion detection systems. Security-related information includes inventories of system hardware, software, and firmware components. Alternate storage sites, including geographically distributed architectures, serve as separate storage facilities for organizations. Organizations may provide separate storage by implementing automated backup processes at alternative storage sites (e.g., data centers). The General Services Administration (GSA) establishes standards and specifications for security and fire rated containers.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Contingency Planning · Enhancement
CP-9(5) · Transfer to Alternate Storage Site
View parent controlControl statement and discussion
NIST control statement
Transfer system backup information to the alternate storage site [Assignment: organization-defined time period and transfer rate consistent with the recovery time and recovery point objectives].
Discussion
System backup information can be transferred to alternate storage sites either electronically or by the physical shipment of storage media.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Contingency Planning · Enhancement
CP-9(6) · Redundant Secondary System
View parent controlControl statement and discussion
NIST control statement
Conduct system backup by maintaining a redundant secondary system that is not collocated with the primary system and that can be activated without loss of information or disruption to operations.
Discussion
The effect of system backup can be achieved by maintaining a redundant secondary system that mirrors the primary system, including the replication of information. If this type of redundancy is in place and there is sufficient geographic separation between the two systems, the secondary system can also serve as the alternate processing site.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Contingency Planning · Enhancement
CP-9(7) · Dual Authorization for Deletion or Destruction
View parent controlControl statement and discussion
NIST control statement
Enforce dual authorization for the deletion or destruction of [Assignment: backup information].
Discussion
Dual authorization ensures that deletion or destruction of backup information cannot occur unless two qualified individuals carry out the task. Individuals deleting or destroying backup information possess the skills or expertise to determine if the proposed deletion or destruction of information reflects organizational policies and procedures. Dual authorization may also be known as two-person control. To reduce the risk of collusion, organizations consider rotating dual authorization duties to other individuals.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Contingency Planning · Enhancement
CP-9(8) · Cryptographic Protection
View parent controlControl statement and discussion
NIST control statement
Implement cryptographic mechanisms to prevent unauthorized disclosure and modification of [Assignment: backup information].
Discussion
The selection of cryptographic mechanisms is based on the need to protect the confidentiality and integrity of backup information. The strength of mechanisms selected is commensurate with the security category or classification of the information. Cryptographic protection applies to system backup information in storage at both primary and alternate locations. Organizations that implement cryptographic mechanisms to protect information at rest also consider cryptographic key management solutions.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · CP-9 (8) — Direct NIST identifier reference. GovRAMP source matrix