id: "SC-36" title: "Distributed Processing and Storage" family: "SC" family_name: "System and Communications Protection" sort_id: "sc-36" priority: "P1" implementation_level: "organization" enhancements: - sc-36.1 - sc-36.2
Statement
Distribute the following processing and storage components across multiple {{ insert: param, sc-36_prm_1 }}: {{ insert: param, sc-36_prm_2 }}.
Guidance
Distributing processing and storage across multiple physical locations or logical domains provides a degree of redundancy or overlap for organizations. The redundancy and overlap increase the work factor of adversaries to adversely impact organizational operations, assets, and individuals. The use of distributed processing and storage does not assume a single primary processing or storage location. Therefore, it allows for parallel processing and storage.
Assessment Objective: {{ insert: param, sc-36_odp.01 }} are distributed across {{ insert: param, sc-36_odp.02 }};
Assessment Objective: {{ insert: param, sc-36_odp.03 }} are distributed across {{ insert: param, sc-36_odp.04 }}.
System and communications protection policy
contingency planning policy and procedures
contingency plan
system design documentation
system configuration settings and associated documentation
system architecture
list of system physical locations (or environments) with distributed processing and storage
system facility diagrams
processing site agreements
storage site agreements
system security plan
other relevant documents or records
System/network administrators
organizational personnel with information security responsibilities
organizational personnel installing, configuring, and/or maintaining the system
organizational personnel with contingency planning and plan implementation responsibilities
system developers/integrators
Organizational processes for distributed processing and storage across multiple physical locations
mechanisms supporting and/or implementing the capability to distribute processing and storage across multiple physical locations