nerdexam
CompTIA

CAS-002 · Question #753

A security manager for a service provider has approved two vendors for connections to the service provider backbone. One vendor will be providing authentication services for its payment card…

The correct answer is B. Interconnection Security Agreement. An Interconnection Security Agreement (ISA) is the appropriate instrument when two organizations establish a technical connection between their systems, defining the security controls and responsibilities for that link.

Integration of Computing, Communications and Business Disciplines

Question

A security manager for a service provider has approved two vendors for connections to the service provider backbone. One vendor will be providing authentication services for its payment card service, and the other vendor will be providing maintenance to the service provider infrastructure sites. Which of the following business agreements is MOST relevant to the vendors and service provider's relationship?

Options

  • AMemorandum of Agreement
  • BInterconnection Security Agreement
  • CNon-Disclosure Agreement
  • DOperating Level Agreement

How the community answered

(30 responses)
  • A
    7% (2)
  • B
    87% (26)
  • C
    3% (1)
  • D
    3% (1)

Why each option

An Interconnection Security Agreement (ISA) is the appropriate instrument when two organizations establish a technical connection between their systems, defining the security controls and responsibilities for that link.

AMemorandum of Agreement

A Memorandum of Agreement establishes general terms of cooperation between parties but does not specifically address the technical security requirements for system interconnections.

BInterconnection Security AgreementCorrect

An ISA formally documents the security requirements, roles, and safeguards that govern a technical interconnection between two organizations' information systems. In this scenario, both vendors are physically or logically connecting to the service provider's backbone, making the ISA the most relevant agreement to define acceptable security postures, data flows, and controls for those connections.

CNon-Disclosure Agreement

A Non-Disclosure Agreement governs the confidentiality of shared information but does not address the security controls required for network or system interconnections.

DOperating Level Agreement

An Operating Level Agreement defines internal service commitments between teams within the same organization, not between separate legal entities connecting to a shared backbone.

Concept tested: Interconnection Security Agreement for vendor system connections

Source: https://csrc.nist.gov/publications/detail/sp/800-47/rev-1/final

Topics

#ISA#third-party agreements#interconnection#service provider

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice