Question

Difficulty: MediumThird-Party Risk Management and Supply Chain Oversight

An enterprise organization plans to establish a direct network link and federated single sign-on integration with a strategic partner to facilitate real-time data exchange between their respective data centers. Before configuring the VPN tunnel and enabling communication between the two distinct networks, security administrators from both entities must establish a formal document specifying the technical interface standards, security control requirements, and data transfer protocols governing the network connection itself. Which of the following agreements is most appropriate to satisfy this requirement?

  1. Interconnection Security Agreement (ISA)Answer
  2. B
    Memorandum of Understanding (MOU)
  3. C
    Service Level Agreement (SLA)
  4. D
    Master Services Agreement (MSA)

Answer

The Interconnection Security Agreement (ISA) is the correct choice because it establishes the precise technical specifications, encryption mandates, and operational security requirements for connecting two distinct organization networks.
An Interconnection Security Agreement (ISA) is a specialized document created when two organizations connect their IT systems. It outlines technical requirements (such as VPN protocols, IP address ranges, and encryption algorithms), operational security rules, and data handling procedures specifically for the network connection.

Step-by-Step Solution

1
Analyze the scenario requirement
The requirement focuses on formalizing technical security controls and connection specifications for a direct network link between two entities.
Identifying the core focus (technical network connection vs. operational metrics or legal intent) narrows down the required agreement type.
2
Evaluate third-party agreement types
An Interconnection Security Agreement (ISA) is designed specifically to document system interface parameters, security requirements, and data movement controls for interconnected systems.
Standards such as NIST SP 800-47 dictate using an ISA to mandate security provisions between connected organizations.

Key Concept

Interconnection Security Agreement (ISA)
Rate this question