About this interactive
Seven scenarios, seven agreement types, one pairing each. The acronyms are easy to memorize and easy to confuse, because several of them describe promises that sound alike until you ask three questions of each: who is on the other side, how long does it last, and is anyone actually bound by it. The SLA is the one most people already half-know — a provider commits to a measurable standard, here 99.9% monthly availability, and attaches a penalty clause so that missing it costs something. What makes it an SLA is not the number but the pairing of a benchmark with a consequence. The OLA makes the same shape of promise and is constantly mistaken for it, but it runs between departments of the same organization: IT owes finance a four-hour first response, no contract, no invoice, no external party. That internal commitment is usually what makes the external one achievable, which is why the two exist alongside each other rather than in competition. MSA and SOW are the other pair worth untangling, and they are layers rather than alternatives. The Master Service Agreement is the umbrella — payment terms, liability limits, insurance, confidentiality — negotiated once and standing for years, so that individual projects do not reopen them. The Statement of Work sits underneath it and covers exactly one engagement: these deliverables, these dates, this cost. An organization signing its first MSA and its first SOW on the same day is normal; signing a fresh MSA per project means someone has misunderstood what the umbrella is for. The NDA is narrower still and is about information rather than work, which is why it so often precedes everything else — the penetration testing firm has to be bound before it is shown the network diagrams, not after, and the obligation outlives the engagement that created it. The ISA is the technical one: two organizations connecting systems directly, writing down the encryption, authentication and division of responsibility that governs the link itself rather than the business relationship around it. And the MOU is the odd one out, deliberately. It records what two parties intend — shared threat intelligence, coordinated incident response — without making any of it enforceable. That is not a weakness in the document; it is the document's purpose, letting a relationship begin before either side is ready to commit legal and budget resources. Its close relative, the MOA, is the version that does carry some legal weight, and the gap between those two is the whole reason both terms exist. Sorted by what they govern, the seven read: two performance commitments split by an organizational boundary, two contract layers split by duration, one about information, one about a network connection, and one about intent.
About TechKnowSurge
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →