Employ [organization-defined] for satisfying [organization-defined] when the primary means of implementing the security function is unavailable or com
Scanned 9/3/2026
Install to Claude Code
npx -y skills add CyberStrikeus/CyberStrike --skill CP-13_alternative-security-mechanisms --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of CP 13 Alternative Security Mechanisms?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/cyberstrikeus-cp-13-alternative-security-mechanisms)More formats (shields.io, HTML) on the badges page.
---
name: "CP-13_alternative-security-mechanisms"
description: "Employ [organization-defined] for satisfying [organization-defined] when the primary means of implementing the security function is unavailable or com"
category: "configuration"
version: "5.2.0"
author: "cyberstrike-official"
tags:
- nist
- sp800-53
- rev5
- cp-13
- cp
tech_stack:
- aws
- azure
- gcp
cwe_ids: []
chains_with:
- CP-2
- CP-11
- SI-13
prerequisites: []
severity_boost:
CP-2: "Chain with CP-2 for comprehensive security coverage"
CP-11: "Chain with CP-11 for comprehensive security coverage"
SI-13: "Chain with SI-13 for comprehensive security coverage"
---
# CP-13 Alternative Security Mechanisms
## High-Level Description
**Family:** Contingency Planning (CP)
**Framework:** NIST SP 800-53 Rev 5
Use of alternative security mechanisms supports system resiliency, contingency planning, and continuity of operations. To ensure mission and business continuity, organizations can implement alternative or supplemental security mechanisms. The mechanisms may be less effective than the primary mechanisms. However, having the capability to readily employ alternative or supplemental mechanisms enhances mission and business continuity that might otherwise be adversely impacted if operations had to be curtailed until the primary means of implementing the functions was restored. Given the cost and level of effort required to provide such alternative capabilities, the alternative or supplemental mechanisms are only applied to critical security capabilities provided by systems, system components, or system services. For example, an organization may issue one-time pads to senior executives, officials, and system administrators if multi-factor tokens—the standard means for achieving secure authentication— are compromised.
## What to Check
- [ ] Verify CP-13 Alternative Security Mechanisms is documented in SSP
- [ ] Confirm control is operating effectively
- [ ] Review evidence of continuous monitoring for CP-13
## How to Test
### Step 1: Review Documentation
Examine the System Security Plan (SSP) and related artifacts for CP-13 implementation details. Verify the organization has documented how this control is satisfied.
### Step 2: Validate Implementation
```
# For cloud environments, use cloud-audit-mcp tools
# For on-premises, review system configurations directly
# Example: Check if account management policies exist
grep -r "account.management\|access.control" /etc/security/ 2>/dev/null
```
### Step 3: Test Operating Effectiveness
Verify the control is actively functioning, not just documented. Check logs, configurations, and operational evidence.
## Tools
| Tool | Purpose | Usage |
| ------------- | --------------------------------- | ----- |
| Manual Review | Documentation and interview-based | N/A |
## Remediation Guide
### Control Statement
Employ [organization-defined] for satisfying [organization-defined] when the primary means of implementing the security function is unavailable or compromised.
### Implementation Guidance
Use of alternative security mechanisms supports system resiliency, contingency planning, and continuity of operations. To ensure mission and business continuity, organizations can implement alternative or supplemental security mechanisms. The mechanisms may be less effective than the primary mechanisms. However, having the capability to readily employ alternative or supplemental mechanisms enhances mission and business continuity that might otherwise be adversely impacted if operations had to be curtailed until the primary means of implementing the functions was restored. Given the cost and level of effort required to provide such alternative capabilities, the alternative or supplemental mechanisms are only applied to critical security capabilities provided by systems, system components, or system services. For example, an organization may issue one-time pads to senior executives, officials, and system administrators if multi-factor tokens—the standard means for achieving secure authentication— are compromised.
## Risk Assessment
| Finding | Severity | Impact |
| ----------------------------------------------------- | -------- | ------------------------------- |
| CP-13 Alternative Security Mechanisms not implemented | Medium | Contingency Planning |
| CP-13 partially implemented | Low | Incomplete Contingency Planning |
## CWE Categories
| CWE ID | Title |
| ------ | --------------------- |
| N/A | No direct CWE mapping |
## References
- [NIST SP 800-53 Rev 5 - CP-13](https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=cp-13)
- [NIST SP 800-53A Rev 5 (Assessment Procedures)](https://csrc.nist.gov/pubs/sp/800/53/a/r5/final)
- [NIST SP 800-53 Rev 5 Full Catalog](https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final)
## Checklist
- [ ] Control documented in SSP
- [ ] Implementation evidence collected
- [ ] Operating effectiveness validated
- [ ] Continuous monitoring in place
- [ ] Related controls (CP-2, CP-11, SI-13) reviewed
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!