CAS-002 · Question #847
A bank has decided to outsource some existing IT functions and systems to a third party service provider. The third party service provider will manage the outsourced systems on their own premises…
The correct answer is A. ISA. When two organizations interconnect their IT systems, an Interconnection Security Agreement (ISA) defines the security requirements governing that connection.
Question
A bank has decided to outsource some existing IT functions and systems to a third party service provider. The third party service provider will manage the outsourced systems on their own premises and will continue to directly interface with the bank's other systems through dedicated encrypted links. Which of the following is critical to ensure the successful management of system security concerns between the two organizations?
Options
- AISA
- BBIA
- CMOU
- DSOA
- EBPA
How the community answered
(65 responses)- A88% (57)
- B5% (3)
- D2% (1)
- E6% (4)
Why each option
When two organizations interconnect their IT systems, an Interconnection Security Agreement (ISA) defines the security requirements governing that connection.
An ISA (Interconnection Security Agreement) is a formal document specifically designed to govern the security of interconnected IT systems between two organizations. It defines the technical and operational security requirements, roles, and responsibilities for the connection - exactly the scenario described with the bank and third-party provider communicating over dedicated encrypted links.
A BIA (Business Impact Analysis) is used to identify the impact of disruptions to business operations for continuity planning, not to govern inter-organizational security of system connections.
An MOU (Memorandum of Understanding) is a general non-binding agreement that outlines intentions between parties but lacks the technical security specificity required for managing interconnected system security.
A SOA (Statement of Applicability) is used within the ISO 27001 framework to document which security controls apply to an organization, not to govern security between two interconnected organizations.
A BPA (Business Partnership Agreement) defines the terms of a business relationship but does not address the technical security requirements for interconnected IT systems.
Concept tested: Interconnection Security Agreement for third-party IT connections
Source: https://csrc.nist.gov/glossary/term/interconnection_security_agreement
Topics
Community Discussion
No community discussion yet for this question.