nerdexam
CompTIA

CAS-003 · Question #932

An organization is a subsidiary of a larger firm that provides managed IT and human resources controls to the subsidiary. The subsidiary determines the contract in place between the two firms does…

The correct answer is C. Interoperability agreement F. Interconnection security agreement. An Interconnection Security Agreement (ISA) (F) is a formal document used when two organizations connect their IT systems. It specifies the security requirements, controls, roles, and responsibilities that govern the technical interconnection-exactly what is needed when a…

Risk Management

Question

An organization is a subsidiary of a larger firm that provides managed IT and human resources controls to the subsidiary. The subsidiary determines the contract in place between the two firms does not define and apply terms appropriate relating to the controls provided by the larger firm. Which of the following would be MOST appropriate for both firms to formally document the controls to be provided? (Select TWO.)

Options

  • AService-level agreement
  • BNon-disclosure agreement
  • CInteroperability agreement
  • DMaster service agreement
  • EBusiness impact analysis
  • FInterconnection security agreement

How the community answered

(28 responses)
  • A
    4% (1)
  • B
    4% (1)
  • C
    86% (24)
  • D
    7% (2)

Explanation

An Interconnection Security Agreement (ISA) (F) is a formal document used when two organizations connect their IT systems. It specifies the security requirements, controls, roles, and responsibilities that govern the technical interconnection-exactly what is needed when a parent firm is providing managed IT controls to a subsidiary. An Interoperability Agreement (C) formally defines how the systems and processes of two separate organizations will work together, covering compatibility, data exchange standards, and operational procedures. Together, these two documents address both the technical security controls (ISA) and the operational interoperability (Interoperability Agreement). An SLA (A) defines service performance levels but does not detail specific security controls. An NDA (B) covers confidentiality. An MSA (D) is a general contractual framework. A BIA (E) assesses business impact, not control documentation.

Topics

#interoperability agreement#ISA#third-party contracts#managed services

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice