nerdexam
CompTIA

CAS-002 · Question #851

An employee is performing a review of the organization's security functions and noticed that there is some cross over responsibility between the IT security team and the financial fraud team. Which…

The correct answer is C. MOU. An MOU (Memorandum of Understanding) is the appropriate document to clarify shared or overlapping roles and responsibilities between two internal teams or organizations.

Integration of Computing, Communications and Business Disciplines

Question

An employee is performing a review of the organization's security functions and noticed that there is some cross over responsibility between the IT security team and the financial fraud team. Which of the following security documents should be used to clarify the roles and responsibilities between the teams?

Options

  • ABPA
  • BBIA
  • CMOU
  • DOLA

How the community answered

(19 responses)
  • B
    5% (1)
  • C
    89% (17)
  • D
    5% (1)

Why each option

An MOU (Memorandum of Understanding) is the appropriate document to clarify shared or overlapping roles and responsibilities between two internal teams or organizations.

ABPA

A BPA (Business Partnership Agreement) is a formal legal agreement between business partners that governs financial and operational arrangements, not internal team responsibilities.

BBIA

A BIA (Business Impact Analysis) identifies and quantifies the effects of disruptions on business operations and is used for continuity planning, not for defining team roles.

CMOUCorrect

An MOU defines the roles, responsibilities, and mutual expectations between two parties without being a legally binding contract. It is the standard document used to resolve ambiguity or overlap in responsibilities between departments, such as an IT security team and a financial fraud team. It establishes a clear framework for cooperation and accountability without the formality of a legal agreement.

DOLA

An OLA (Operational Level Agreement) defines internal IT service delivery commitments between IT support groups, not for clarifying security responsibilities across different business units.

Concept tested: Memorandum of Understanding for role clarification

Source: https://csrc.nist.gov/publications/detail/sp/800-47/rev-1/final

Topics

#MOU#roles and responsibilities#security governance#cross-team coordination

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice