Soru

Zorluk: OrtaThird-Party Risk Management and Supply Chain Oversight

An organization plans to establish a direct network link with a key business partner to facilitate automated data synchronization. Before enabling the connection, the security team must document the specific technical security controls, interface configurations, and encryption standards governing the direct link. Which of the following agreements should be established to define these technical parameters?

  1. Interconnection Security Agreement (ISA)Cevap
  2. B
    Memorandum of Understanding (MOU)
  3. C
    Business Partners Agreement (BPA)
  4. D
    Service Level Agreement (SLA)

Cevap

Interconnection Security Agreement (ISA)
An Interconnection Security Agreement (ISA) specifies the technical and security requirements for establishing a dedicated connection between two distinct organizations' networks, including protocol requirements, encryption, and security boundaries.

Adım Adım Çözüm

1
Analyze the operational requirement described in the scenario.
The goal is to document technical security controls, encryption, and interface requirements for a direct network connection between two enterprise networks.
Establishing direct network links introduces third-party connectivity risks that require dedicated technical documentation.
2
Evaluate agreement types against the requirement.
An Interconnection Security Agreement (ISA) is designed specifically to define technical parameters and security controls for interconnecting distinct networks.
Other agreement types address general intent, financial partnerships, or service performance metrics.

Anahtar Kavram

Interconnection Security Agreement (ISA) for Third-Party Risk Management
Bu soruyu puanla