Question

Difficulty: MediumThird-Party Risk Management and Supply Chain Oversight

An enterprise is establishing a dedicated network link with a third-party logistics partner to facilitate real-time inventory database synchronization. Which of the following documents should the security team require to specifically define the technical security controls, communication protocols, and data encryption standards for this direct system-to-system connection?

  1. Interconnection Security Agreement (ISA)Answer
  2. B
    Service Level Agreement (SLA)
  3. C
    Memorandum of Understanding (MOU)
  4. D
    Non-Disclosure Agreement (NDA)

Answer

Interconnection Security Agreement (ISA)
An Interconnection Security Agreement (ISA) is used when two organizations establish a direct technical connection to transmit data. It documents technical security requirements, encryption protocols, network boundaries, and technical roles for both parties.

Step-by-Step Solution

1
Analyze the scenario requirements
Identified the need for technical security controls, protocols, and encryption for a direct system-to-system network link.
Direct connections between partner networks introduce cross-boundary security risks that require precise technical parameters.
2
Evaluate third-party agreement types
Determined that an Interconnection Security Agreement (ISA) specifically governs system-to-system connections.
An ISA outlines security requirements, data ownership, transfer mechanisms, and technical boundaries for interconnected systems.

Key Concept

Third-Party Interconnection Governance and Security Agreements
Rate this question