TechKnowSurge
CompTIA Security+ 5.3 NIST CSF GV.SC-05 NIST 800-53 SA-4 ISC2 CC 1.3 NIST 800-53 PL-4 NIST 800-53 PS-6 CompTIA Security+ 5.1 CompTIA A+ Core 2 4.6
InteractiveSecurityFree

Name That Policy or Agreement

Who is the document between, and what does it do? Type its name.

⚑ Complete this interactive to capture a CTF flag worth 5 points.

About this interactive

When things are not written down, there is a lot of room for interpretation. Policies and agreements make clear what is expected, who is responsible, and what each side is allowed to do. Which one you need depends on the relationship. Customers and other external users. Everyone who visits your site has data collected about them, so every business should have a privacy policy. Customers using your product or service agree to terms of service (or terms of use), often with a checkbox. Physical products come with a warranty. A client you provide services to signs a master service agreement (MSA), the umbrella agreement, usually signed once and good for years; each project under it gets a statement of work (SOW) setting out the deliverables and the cost. Vendors and service providers. Your company is a customer too, so the same documents apply from the other side: warranties for IT products, terms of service for software as a service, and an MSA and SOWs with a managed service provider. Employees and internal users. The acceptable use policy (AUP) sets the ground rules for using company systems and gives the company recourse when someone abuses them. A password policy can sit inside the AUP or stand alone. A data handling policy says what is confidential and how data is treated. A bring-your-own-device (BYOD) policy says whether, and how, personal devices may be used. Partners. A partnership contract is detailed, reviewed by lawyers, and can take months or years to reach. A memorandum of understanding (MOU) records a shared understanding and carries little legal weight; a memorandum of agreement (MOA) is more formal, spells out what each side has agreed to, and can carry legal weight. They lead up to the contract.

What you'll learn

Aligned to

CompTIA Security+
5.3 Explain the processes associated with third-party risk assessment and management.
5.1 Summarize elements of effective security governance.
NIST CSF
GV.SC-05 Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties.
NIST 800-53
SA-4 Acquisition Process
PL-4 Rules of Behavior
PS-6 Access Agreements
ISC2 CC
1.3 Understand governance concepts
CompTIA A+ Core 2
4.6 Explain the importance of prohibited content/activity and privacy, licensing, and policy concepts.

Key terms

Acceptable Use Policy
AUP
A documented policy that defines the rules and expectations for how employees and internal users may use organizational systems and resources. An AUP establishes the grounds for disciplinary or legal action if violated.
Privacy Policy
A document that discloses how an organization collects, uses, and manages the data of visitors, customers, and other external parties.
Master Service Agreement
MSA
An umbrella contract established between a service provider and a customer that governs the overall business relationship and under which future work or services are conducted.
Statement of Work
SOW
A document tied to a master service agreement that defines the specific tasks, deliverables, timeline, and costs for a particular project or engagement.
Terms of Service
ToS
An agreement between a service provider and a user that outlines the rules, rights, and responsibilities governing use of a product or service.
Bring Your Own Device
BYOD
Bring Your Own Device is a policy that permits employees to use personal devices to access corporate systems and data, introducing security challenges around data segregation, device management, and policy enforcement.
Memorandum of Understanding
MOU
A Memorandum of Understanding is a non-binding agreement between parties that documents shared intentions, responsibilities, and expectations, commonly used in security contexts for information sharing, incident response coordination, and interagency cooperation.
Memorandum of Agreement
MOA
Memorandum of Agreement is a formal document establishing a cooperative relationship between organizations that defines mutual goals, responsibilities, and security obligations.
Password Policy
A set of organizational rules governing the creation, complexity, expiration, and management of user passwords to reduce security risk.

Topics

Acceptable Use Policy Privacy Policy Master Service Agreement Statement Of Work Memorandum Of Understanding Interactive Fill In

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →