# CP-07 (01) Separation from Primary Site — NIST 800-53 Rev5 control

> FedRAMP Consolidated Rules for 2026 v2026.07.14.01 · updated 2026-07-14
> Canonical page: /control/cp-7.1

Canonical id: `cp-7.1` · family `CP`

> Identify an alternate processing site that is sufficiently separated from the primary processing site to reduce susceptibility to the same threats.

_Control title and statement: NIST SP 800-53 Rev5 catalog (the pinned commit is in `/api` under `control_text`). The FedRAMP rules reference these controls by id only; everything below is what FedRAMP says about this id._

## Rev5 baseline membership

- certification class C
- certification class D

## Key Security Indicators that reach it

- `KSI-RPL-ARP` — Aligning Recovery Plan (Recovery Planning)
  The alignment of recovery plans with defined recovery objectives is persistently reviewed.

## FedRAMP guidance

{
  "guidance": [
    "The service provider may determine what is considered a sufficient degree of separation between the primary and alternate processing sites, based on the types of threats that are of concern. For one particular type of threat (i.e., hostile cyber attack), the degree of separation between sites will be less relevant."
  ]
}
