CAS-001 · Question #420
An organization is finalizing a contract with a managed security services provider (MSSP) that is responsible for primary support of all security technologies. Which of the following should the…
The correct answer is B. An interconnection security agreement. When an MSSP is granted access to an organization's security infrastructure, an Interconnection Security Agreement (ISA) formally defines the security requirements and controls governing that system-to-system connection.
Question
An organization is finalizing a contract with a managed security services provider (MSSP) that is responsible for primary support of all security technologies. Which of the following should the organization require as part of the contract to ensure the protection of the organization's technology?
Options
- AAn operational level agreement
- BAn interconnection security agreement
- CA non-disclosure agreement
- DA service level agreement
How the community answered
(38 responses)- A3% (1)
- B87% (33)
- C3% (1)
- D8% (3)
Why each option
When an MSSP is granted access to an organization's security infrastructure, an Interconnection Security Agreement (ISA) formally defines the security requirements and controls governing that system-to-system connection.
An Operational Level Agreement (OLA) is an internal agreement between departments within the same organization, not between separate legal entities.
An ISA is a formal document that establishes the security requirements, roles, and responsibilities when two organizations interconnect their IT systems. Because the MSSP will have direct access to and support of the organization's security technologies, an ISA ensures that the protection standards for those systems are contractually defined and enforced.
A Non-Disclosure Agreement protects confidential information from being shared externally but does not govern the technical security requirements of a system interconnection.
A Service Level Agreement defines performance metrics and uptime expectations but does not address the specific security controls and requirements for protecting the connected technology.
Concept tested: Interconnection Security Agreement for third-party access
Source: https://csrc.nist.gov/glossary/term/interconnection_security_agreement
Topics
Community Discussion
No community discussion yet for this question.