Question

Difficulty: EasyThird-Party Risk Management and Supply Chain Oversight

An enterprise is contracting with a cloud service provider to host its business-critical applications. The security team needs to establish clear operational requirements regarding system uptime response expectations, scheduled maintenance windows, and financial remedies if performance targets are missed. Which of the following agreements should be implemented to define these specific requirements?

  1. Service Level Agreement (SLA)Answer
  2. B
    Non-Disclosure Agreement (NDA)
  3. C
    Interconnection Security Agreement (ISA)
  4. D
    Business Impact Analysis (BIA)

Answer

Service Level Agreement (SLA)
A Service Level Agreement explicitly establishes measurable performance metrics (such as uptime percentages, response times, and maintenance schedules) along with consequences or credits if the vendor fails to meet those benchmarks.

Step-by-Step Solution

1
Identify the organizational requirement in the scenario.
The organization needs to specify uptime, service availability, maintenance windows, and performance remedies with a third party.
Clear vendor operational metrics must be formalized legally to guarantee expected service levels.
2
Evaluate third-party agreement types against the requirement.
A Service Level Agreement directly defines minimum operational performance expectations and penalties for non-performance.
SLAs are the standard contract components used in vendor management to define measurable service metrics.

Key Concept

Third-Party Service Level Agreements (SLAs)
Rate this question