TechKnowSurge
CompTIA Security+ 5.3 CompTIA Security+ 5.1 ISC2 CISSP 1.3 NIST CSF GV.SC-05 NIST 800-53 SA-9 CompTIA Security+ 5.2 NIST 800-53 CA-3 ISC2 CISSP 1.9
InteractiveSecurityFree

Agreement Type Matcher

Match seven vendor scenarios to the agreement type that governs each, and separate the umbrella contracts from the per-project ones, the external commitments from the internal, and the binding from the merely intended.

Complete this interactive to capture a CTF flag worth 5 points.

About this interactive

Seven scenarios, seven agreement types, one pairing each. The acronyms are easy to memorize and easy to confuse, because several of them describe promises that sound alike until you ask three questions of each: who is on the other side, how long does it last, and is anyone actually bound by it. The SLA is the one most people already half-know — a provider commits to a measurable standard, here 99.9% monthly availability, and attaches a penalty clause so that missing it costs something. What makes it an SLA is not the number but the pairing of a benchmark with a consequence. The OLA makes the same shape of promise and is constantly mistaken for it, but it runs between departments of the same organization: IT owes finance a four-hour first response, no contract, no invoice, no external party. That internal commitment is usually what makes the external one achievable, which is why the two exist alongside each other rather than in competition. MSA and SOW are the other pair worth untangling, and they are layers rather than alternatives. The Master Service Agreement is the umbrella — payment terms, liability limits, insurance, confidentiality — negotiated once and standing for years, so that individual projects do not reopen them. The Statement of Work sits underneath it and covers exactly one engagement: these deliverables, these dates, this cost. An organization signing its first MSA and its first SOW on the same day is normal; signing a fresh MSA per project means someone has misunderstood what the umbrella is for. The NDA is narrower still and is about information rather than work, which is why it so often precedes everything else — the penetration testing firm has to be bound before it is shown the network diagrams, not after, and the obligation outlives the engagement that created it. The ISA is the technical one: two organizations connecting systems directly, writing down the encryption, authentication and division of responsibility that governs the link itself rather than the business relationship around it. And the MOU is the odd one out, deliberately. It records what two parties intend — shared threat intelligence, coordinated incident response — without making any of it enforceable. That is not a weakness in the document; it is the document's purpose, letting a relationship begin before either side is ready to commit legal and budget resources. Its close relative, the MOA, is the version that does carry some legal weight, and the gap between those two is the whole reason both terms exist. Sorted by what they govern, the seven read: two performance commitments split by an organizational boundary, two contract layers split by duration, one about information, one about a network connection, and one about intent.

What you'll learn

Aligned to

CompTIA Security+
5.3 Explain the processes associated with third-party risk assessment and management.
5.1 Summarize elements of effective security governance.
5.2 Explain elements of the risk management process.
ISC2 CISSP
1.3 Evaluate and apply security governance principles
1.9 Understand and apply risk management concepts
NIST CSF
GV.SC-05 Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties.
NIST 800-53
SA-9 External System Services
CA-3 Information Exchange

Key terms

Service Level Agreement
SLA
A formal commitment between a provider and customer that guarantees a defined level of service uptime, including terms for compensation if the standard is not met.
Master Service Agreement
MSA
An umbrella contract established between a service provider and a customer that governs the overall business relationship and under which future work or services are conducted.
Statement of Work
SOW
A document tied to a master service agreement that defines the specific tasks, deliverables, timeline, and costs for a particular project or engagement.
Non-disclosure Agreement
NDA
A Non-disclosure Agreement is a legally binding contract that prohibits parties from sharing confidential information obtained during a business relationship, commonly required before sharing sensitive security findings or proprietary data.
Interconnection Security Agreement
ISA
A formal agreement between two organizations that specifies the technical and security requirements for connecting their IT systems, defining each party's responsibilities for protecting shared data in transit.
Operational Level Agreement
OLA
An internal agreement that defines the responsibilities and service expectations between departments within the same organization in support of an SLA.
Memorandum of Understanding
MOU
A Memorandum of Understanding is a non-binding agreement between parties that documents shared intentions, responsibilities, and expectations, commonly used in security contexts for information sharing, incident response coordination, and interagency cooperation.
Memorandum of Agreement
MOA
Memorandum of Agreement is a formal document establishing a cooperative relationship between organizations that defines mutual goals, responsibilities, and security obligations.
Business Partners Agreement
BPA
A Business Partners Agreement is a formal contract between organizations that defines mutual security responsibilities and acceptable use requirements when sharing data or systems.
Vendor Agreement
A formal contract between a business and a third-party provider that defines the terms under which services or goods are delivered.
Penalty Clause
A contractual provision that specifies monetary reimbursement or consequences when a vendor fails to meet agreed-upon performance standards.
Right to Audit
A contractual clause that grants one party the authority to review and audit the systems, processes, or compliance of the other party on an ongoing or scheduled basis.
Source Code Escrow
An arrangement where a copy of software source code is held by a neutral third party and released to a licensee if the developer fails to maintain the software or goes out of business.
Rules of Engagement
Contract terms that define the boundaries, schedule, and procedures governing an activity such as penetration testing.
Third-Party Risk Management
TPRM
Third-Party Risk Management is the process of identifying, assessing, monitoring, and mitigating security risks posed by vendors, partners, and other external parties with access to organizational systems or data.
Vendor Management
The process of selecting, contracting, monitoring, and terminating relationships with external suppliers of hardware, software, or services.

Topics

Interactive Matching

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →