Match each third-party risk management document or agreement to its primary organizational security purpose.
- Service Level Agreement (SLA)Defines specific vendor performance metrics, availability guarantees, and service uptime requirements.
- Non-Disclosure Agreement (NDA)Establishes legally binding confidentiality obligations to protect proprietary enterprise data.
- Interconnection Security Agreement (ISA)Specifies technical and security requirements for establishing a direct network connection between organizations.
- Memorandum of Understanding (MOU)Outlines a general mutual understanding and intent to collaborate without creating a formal contract.
Answer
Service Level Agreement (SLA) matches performance and uptime guarantees; Non-Disclosure Agreement (NDA) matches confidentiality protection; Interconnection Security Agreement (ISA) matches technical network link requirements; Memorandum of Understanding (MOU) matches non-binding intent to collaborate.
Each agreement correctly corresponds to its core security governance function: Service Level Agreements enforce performance and availability standards; Non-Disclosure Agreements maintain data confidentiality; Interconnection Security Agreements define parameters for connecting networks; and Memoranda of Understanding document mutual cooperative intent.
Step-by-Step Solution
Key Concept
Third-Party Risk Management Agreements and Governance Artifacts