nerdexam
CompTIA

CAS-002 · Question #847

A bank has decided to outsource some existing IT functions and systems to a third party service provider. The third party service provider will manage the outsourced systems on their own premises…

The correct answer is A. ISA. When two organizations interconnect their IT systems, an Interconnection Security Agreement (ISA) defines the security requirements governing that connection.

Integration of Computing, Communications and Business Disciplines

Question

A bank has decided to outsource some existing IT functions and systems to a third party service provider. The third party service provider will manage the outsourced systems on their own premises and will continue to directly interface with the bank's other systems through dedicated encrypted links. Which of the following is critical to ensure the successful management of system security concerns between the two organizations?

Options

  • AISA
  • BBIA
  • CMOU
  • DSOA
  • EBPA

How the community answered

(65 responses)
  • A
    88% (57)
  • B
    5% (3)
  • D
    2% (1)
  • E
    6% (4)

Why each option

When two organizations interconnect their IT systems, an Interconnection Security Agreement (ISA) defines the security requirements governing that connection.

AISACorrect

An ISA (Interconnection Security Agreement) is a formal document specifically designed to govern the security of interconnected IT systems between two organizations. It defines the technical and operational security requirements, roles, and responsibilities for the connection - exactly the scenario described with the bank and third-party provider communicating over dedicated encrypted links.

BBIA

A BIA (Business Impact Analysis) is used to identify the impact of disruptions to business operations for continuity planning, not to govern inter-organizational security of system connections.

CMOU

An MOU (Memorandum of Understanding) is a general non-binding agreement that outlines intentions between parties but lacks the technical security specificity required for managing interconnected system security.

DSOA

A SOA (Statement of Applicability) is used within the ISO 27001 framework to document which security controls apply to an organization, not to govern security between two interconnected organizations.

EBPA

A BPA (Business Partnership Agreement) defines the terms of a business relationship but does not address the technical security requirements for interconnected IT systems.

Concept tested: Interconnection Security Agreement for third-party IT connections

Source: https://csrc.nist.gov/glossary/term/interconnection_security_agreement

Topics

#ISA#third-party security#outsourcing agreements#interconnection security

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice