Soru

Zorluk: ZorThird-Party Risk Management and Supply Chain Oversight

An enterprise organization is conducting a third-party risk assessment of a key managed service provider (MSP). The security evaluation reveals that the MSP routes sensitive telemetry data over a dedicated, persistent network connection to a secondary facility operated by a fourth-party subcontractor. The enterprise security manager requires the technical security controls, data encryption rules, and interface boundaries for this specific direct network connection to be formally documented and enforced. Which of the following agreements should be established between the MSP and the fourth-party provider to meet this requirement?

  1. Interconnection Security Agreement (ISA)Cevap
  2. B
    Service Level Agreement (SLA)
  3. C
    Business Partners Agreement (BPA)
  4. D
    Non-Disclosure Agreement (NDA)

Cevap

Interconnection Security Agreement (ISA)
An Interconnection Security Agreement (ISA) is specifically intended to regulate technical security requirements, data encryption protocols, user access boundaries, and operational procedures for direct electronic connections between separate networks or organizations.

Adım Adım Çözüm

1
Analyze the scenario requirement
Identified the need for a legal and technical document that defines parameters for a direct, persistent network link between distinct organizations.
The enterprise requires explicit documentation of technical security controls, encryption, and interface boundaries across a vendor-to-subcontractor network link.
2
Evaluate agreement types against third-party risk management principles
An Interconnection Security Agreement (ISA) specifically addresses system-to-system connections, technical requirements, security baselines, and data transmission controls.
Other vendor contracts focus on business terms (BPA), uptime/performance metrics (SLA), or confidentiality obligations (NDA) rather than technical network interconnect security.
3
Select the correct third-party risk document
The Interconnection Security Agreement (ISA) is the proper choice for governing persistent network interconnections.
It fulfills security governance requirements for fourth-party supply chain connection oversight.

Anahtar Kavram

Third-Party Interconnection Security Governance
Tahmini Süre:1m 30s
Bu soruyu puanla