GASP: AICF

Search controls

Search by control ID, name or domain

BCM-007 Alternate Processing and Communications

Tier 2+

Description

Documented provisions exist for processing critical workloads from an alternate site or cloud region if the primary environment is unavailable. Communication channels for crisis coordination — including out-of-band contacts — are identified and tested. Dependencies on primary-site telecommunications are documented.

Rationale

A DRP that requires the primary site to activate is self-defeating. Tested alternate processing and out-of-band communication channels ensure the plan works when it is most needed.

Framework Mappings (4)

BCR-07Communicationfull
5.30ICT readiness for business continuitypartial
CP-7Alternate Processing Sitefull
CP-8Telecommunications Servicespartial

Evidence (2)

policymanual

Alternate processing and communications plan documenting alternate site or cloud region provisions, out-of-band communication channels, and activation procedures.

Example: BCM Communication Plan and Alternate Processing Plan (section of the BCP or DRP, version-controlled) listing the alternate cloud region or site, activation steps, out-of-band contact numbers and channels, and dependency documentation

Test: Request the alternate processing and communications provisions within the BCP/DRP. Verify: (1) an alternate processing site or region is named and its capacity is documented; (2) out-of-band communication channels are listed with current contact information; (3) dependencies on primary-site telecommunications are documented; (4) activation procedures do not require access to primary-site systems.

recordmanual

Alternate processing and communication channel test record showing the alternate site or region was validated and out-of-band contacts were verified.

Example: DR exercise record or dedicated alternate processing test record showing the alternate cloud region was activated or traffic was redirected during the test, with measured failover time and confirmation of communication channel availability

Test: Request the most recent alternate processing test record. Verify: (1) a test of alternate processing capability was conducted within the last 12 months; (2) the test confirmed workloads could be operated from the alternate site or region; (3) out-of-band communication channels were verified (contacts reachable, channels accessible); (4) measured activation time was within the documented RTO.

Questions (2)

boolean

Do documented provisions exist for processing critical workloads from an alternate site or cloud region, and are out-of-band communication channels identified and tested for crisis coordination?

Alternate processing provisions must not depend on access to the primary site or primary-site telecommunications. Out-of-band channels (e.g. personal mobile numbers, separate messaging platform) should be verified annually.

multi

Which alternate processing and communication provisions are documented and tested?

Named alternate cloud region or site with documented capacityActivation procedures that do not require access to primary-site systemsOut-of-band communication channels (e.g. personal mobile contacts, alternate messaging platform)Contact list verified within the last 12 monthsAlternate processing tested as part of the most recent DR exercisePrimary-site telecommunications dependencies documented

All six elements are expected for a robust alternate processing and communications posture. Untested alternate provisions or unverified contact lists are common gaps.