Page last updated:

PCF Compliance

When deployed in accordance with the reference architecture, PCF is compliant with this requirement. If the infrastructure supports it, PAS can operate across multiple availability zones (AZs). Applications deployed to the platform inherit this redundancy across availability zones.

PCF applications store their data by binding to data services, and whether these data are stored in multiple sites depends on how these services are configured.

A contingency plan can support an alternate storage site for PCF using the BOSH Backup and Restore tool to recover PCF deployments. See Backing Up Deployments with BBR.

Control Description

The organization:

  1. Establishes an alternate storage site including necessary agreements to permit the storage and retrieval of information system backup information; and
  2. Ensures that the alternate storage site provides information security safeguards equivalent to that of the primary site.

Supplemental Guidance

Alternate storage sites are sites that are geographically distinct from primary storage sites. An alternate storage site maintains duplicate copies of information and data in the event that the primary storage site is not available. Items covered by alternate storage site agreements include, for example, environmental conditions at alternate sites, access rules, physical and environmental protection requirements, and coordination of delivery/retrieval of backup media. Alternate storage sites reflect the requirements in contingency plans so that organizations can maintain essential missions/business functions despite disruption, compromise, or failure in organizational information systems.