CAS-003 · Question #40
A company has entered into a business agreement with a business partner for managed human resources services. The Chief Information Security Officer (CISO) has been asked to provide documentation…
The correct answer is A. ISA. When two separate organizations establish a business-to-business VPN connection, an Interconnection Security Agreement (ISA) is the required document. An ISA formally defines the security requirements, roles, responsibilities, and terms governing the technical connection…
Question
A company has entered into a business agreement with a business partner for managed human resources services. The Chief Information Security Officer (CISO) has been asked to provide documentation that is required to set up a business-to-business VPN between the two organizations. Which of the following is required in this scenario?
Options
- AISA
- BBIA
- CSLA
- DRA
How the community answered
(34 responses)- A88% (30)
- B3% (1)
- C6% (2)
- D3% (1)
Explanation
When two separate organizations establish a business-to-business VPN connection, an Interconnection Security Agreement (ISA) is the required document. An ISA formally defines the security requirements, roles, responsibilities, and terms governing the technical connection between the two organizations' networks. It covers data sensitivity, encryption standards, access controls, and monitoring obligations for the interconnection. A Business Impact Analysis (B) assesses the effect of disruptions on business functions and is unrelated to establishing a VPN. A Service Level Agreement (C) defines performance and uptime expectations for a service provider, not the security terms of an interconnection. A Risk Assessment (D) evaluates threats and vulnerabilities but is not the specific documentation required to authorize and govern a B2B network connection.
Topics
Community Discussion
No community discussion yet for this question.