TechKnowSurge
NIST CSF GV.PO-01 NIST 800-53 PL-4 ISC2 CC 1.3 CompTIA A+ Core 2 4.6 NIST CSF GV.SC-05 NIST 800-53 PS-6 ISC2 CC 2.1 CompTIA Network+ 3.1
VideoSecurityFree

Administrative Controls - Policies and Agreements

Policies and agreements formalize expectations across every business relationship, from employees and customers to vendors and partners. This content covers the key documents used to define roles, responsibilities, and acceptable behavior in each of those contexts.

Complete this video to capture a CTF flag worth 1 point.

About this video

Policies and agreements serve a critical function in any organization: they convert informal expectations into documented, enforceable standards. Without written policies, there is significant room for misinterpretation around roles, responsibilities, and acceptable behavior. The type of document required depends heavily on the nature of the relationship, which broadly falls into four categories — employees and internal users, customers and external users, vendors and service providers, and business partners. For customer-facing relationships, a privacy policy is foundational and applies to anyone who interacts with a company's website or services, even without making a purchase. As the relationship deepens, terms of service or terms of use define how products and services may be used. Physical products may carry warranties, while ongoing service relationships are governed by a master service agreement, which acts as an umbrella contract that remains in effect over time. When specific projects are undertaken within that relationship, a statement of work captures the scope, deliverables, and cost. These same agreement types apply symmetrically when an organization acts as the customer of its own vendors and service providers. Internal policies focus on how employees and authorized users interact with company systems. An acceptable use policy establishes ground rules for system access and creates legal recourse when those rules are violated. Password policies define requirements for credential creation and management, a key concern in cybersecurity. Data handling policies clarify how sensitive information — whether personal, financial, or proprietary — should be classified, stored, and shared. Bring-your-own-device policies address the security and operational considerations that arise when employees use personal hardware on company networks. Business partnerships introduce a different set of agreements that typically evolve over time. A memorandum of understanding documents a shared direction between two parties without strong legal enforcement, making it useful in early-stage discussions. A memorandum of agreement carries more legal weight and is appropriate when parties are committed to a direction but have not yet finalized a formal contract. Full partnership contracts, developed with legal counsel, represent the most binding and detailed form of these agreements. Moving through these stages allows organizations to establish protections incrementally as a partnership matures.

What you'll learn

What's covered

Policies & Agreements

Aligned to

NIST CSF
GV.PO-01 Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced.
GV.SC-05 Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties.
NIST 800-53
PL-4 Rules of Behavior
PS-6 Access Agreements
ISC2 CC
1.3 Understand governance concepts
2.1 Plan Governance, Risk, and Compliance (GRC)
CompTIA A+ Core 2
4.6 Explain the importance of prohibited content/activity and privacy, licensing, and policy concepts.
CompTIA Network+
3.1 Explain the purpose of organizational processes and procedures.

Key terms

Acceptable Use Policy
AUP
A documented policy that defines the rules and expectations for how employees and internal users may use organizational systems and resources. An AUP establishes the grounds for disciplinary or legal action if violated.
Privacy Policy
A document that discloses how an organization collects, uses, and manages the data of visitors, customers, and other external parties.
Terms of Service
ToS
An agreement between a service provider and a user that outlines the rules, rights, and responsibilities governing use of a product or service.
Master Service Agreement
MSA
An umbrella contract established between a service provider and a customer that governs the overall business relationship and under which future work or services are conducted.
Statement of Work
SOW
A document tied to a master service agreement that defines the specific tasks, deliverables, timeline, and costs for a particular project or engagement.
Memorandum of Understanding
MOU
A Memorandum of Understanding is a non-binding agreement between parties that documents shared intentions, responsibilities, and expectations, commonly used in security contexts for information sharing, incident response coordination, and interagency cooperation.
Memorandum of Agreement
MOA
Memorandum of Agreement is a formal document establishing a cooperative relationship between organizations that defines mutual goals, responsibilities, and security obligations.
Bring Your Own Device
BYOD
Bring Your Own Device is a policy that permits employees to use personal devices to access corporate systems and data, introducing security challenges around data segregation, device management, and policy enforcement.

Topics

Administrative Controls Acceptable Use Policy Data Privacy Policy Master Service Agreement Memorandum Of Understanding Governance Risk Compliance Security Policies

Transcript

When we don't have things written down, it doesn't become formal. That is, there's a lot of room for interpretation. So by writing it down and refining it, we make very clear what's expected and how it's expected. Policies and agreements do exactly that. They get things in writing so we really understand what the roles and responsibilities are and what we are allowed to do.

Who the Agreements Are For

There are a lot of different types of policies and agreements, and a lot of it has to do with the relationship to the business. What do I mean by that? Number one, a business has employees. There's internal people within the company that are using internal business systems, so the way we treat those people and the contracts and the agreements and the policies are all going to be written towards what their use case is.

We also have customers. We need to make sure that the customers understand what the expectation is between us and the customers, so the customers know exactly what's going on. So we've got the customers and the clients, people who we're providing services or products to.

Then we have our vendors. The vendors are who we are in partner with, or who we are purchasing from, who we're getting products and services from. So just like we as a business have customers that come to us, we actually are customers of other businesses, and so those are the vendors. There are certain agreements and certain things that we agree upon when we're doing business with other vendors, and you can imagine that what we have working with other vendors is going to be very similar to what we have for our clients. There's similar types of agreements there.

And then we have partnerships. Partnerships are when two businesses come together and they're saying, hey, let's do something together.

Customers and External Users

So let's tackle the first of these. That would be the customers that are coming to us for services or products, or any kind of external users, so even those who are just visiting our site. There are agreements for people who visit our site and never even purchase from us.

The first of those, and the most important I would say, is the privacy policy. I say most important, I guess, because everybody should have a privacy policy. Every company that's doing business should have some sort of privacy policy. So we have a privacy policy of how we're going to treat people's data, because when they come to our site we're probably going to be collecting some sort of data, like where are they coming from and what site directed them towards us. We're going to be collecting marketing data. So just because they visited our site, we need to have a privacy policy.

And then if they become a customer, we might want to up that and have some sort of terms of service or terms of use. So if they're using our product and services, then we're going to maybe have some sort of terms with that that says this is how you can use that, this is what's expected of you, this is how we will work with you, this is what's expected of us. It just lays that all out. Terms of service and terms of use is a lot of times when we're using something like software. So if I go and use a cloud software as a service, then I would sign some sort of terms of service or some sort of terms of use, or at least agree to it. A lot of times it's just a little check box: I agree to the terms of service. And now I'm bound by that, and I won't be able to have access to those services unless I agree upon the terms of those.

Then we have things like, if I'm buying a product then there's a warranty with that. So maybe there's some sort of warranties. If it's a physical product, that's still the same type of an agreement that I get when I buy that, of how long it will last, how long I can actually use it for and expect to use it before it breaks.

Then there are service providers who maybe I bring in to provide some sort of service. Maybe it's internet services. Maybe it's some sort of cloud service. Maybe they're coming in and helping me out with help desk. Maybe it's a managed service provider like help desk. So there are different services that somebody might be providing me, and we need this overall umbrella of how we're going to do business together. That's the master service agreement. The master service agreement is the umbrella agreement that determines everything else. Usually you just sign the master service agreement once and it's good for years and years and years. Whether we're doing business or not, it's still good. It just sits there, and we only go back and change it and address it when we need to.

And then if they are carrying out some sort of function for us, like maybe they're helping us out with a project, then at that point that's a statement of work. At that point in time we look at the project and what's expected of both people, what is going to be deliverable, and how much is it going to cost. So the statement of work gets specific to the actual work that's going to be done.

Vendors and Service Providers

This all has to deal with customers that we're providing services for, but it also applies for vendors and service providers that we're using, just as we have customers that are reporting it for us. We're asking for services from some sort of vendor, and they're giving us services, and so we're working with those vendors and service providers. They're going to have the same type of contracts depending on what kind of service provider or product provider there is. Generally with IT products it's more like warranties. If it's some sort of software as a service, then it's more like a terms of service. Or if they're like a managed service provider, then it's more like an MSA or S that we are going to agree upon.

Employees and Internal Users

A big focus also for these policies is going to be for employees and internal users of our systems, people who are signing on to our back-end business systems.

First of all, we need to have some sort of acceptable use policy. This is kind of the overall policy of what's expected of them if they're using our services. Maybe we're giving them a username and password, an account to log into our systems. They're going to be in our systems, and if they were to do something illegal or something that is against what the company has, but we don't have something like an acceptable use policy, there's not a lot of legal recourse. What it does is it protects us. We put this AUP out there and it says this is what you're supposed to be doing and how you're supposed to be behaving. And when they break that, then we can fire them, or we can punish them, or we can actually even bring maybe a legal suit against them if it's grievous enough. So there's this acceptable use policy of: okay, you're using our systems, you're not going to abuse those systems. It sets the ground rules for that. An acceptable use policy is extremely important for your employees and your internal users.

Then we also, accompanied with that, might have a password policy. This could be a separate policy from the acceptable use policy, or a component within the AUP, but it just outlines what's expected of user accounts and what's expected of passwords and how they need to form their passwords. Passwords is an extremely important thing when it comes to cyber security, so being able to agree upon a set of rules when it comes to passwords is extremely important.

And then we have data handling policies. What this has to deal with is that it's more and more important that we keep privacy within our company: privacy for our employees, privacy for our customers, privacy for any data that we're handling that's about somebody else. Not only that, but we have internal documents that are sensitive to the company. So having a clear understanding of how we handle data within the company, and what's confidential and what's not confidential, is going to be extremely important. That way everybody's on the same page and we treat that data as it should be treated.

Other Policies

And then we have a lot of other types of policies. By no means are these exhaustive lists; these are just some examples, some highlights of some policies. But one of them is the bring your own device policy. Sometimes companies don't want you to bring your own device, because now you're taking an unknown element of whatever this device is. Let's say it's a laptop, and you're plugging it into the network and into company resources, and they don't know if data is being put onto that laptop, or whatever that device is. They don't know what's happening, if that device has the proper antivirus. So bring your own device is kind of scary for a lot of security professionals. We don't necessarily want that on our network, but there are tools and things that are better now that help us allow this to happen. There's going to be some employees that just want to bring their own device, and there are some advantages to the company, like they don't have to then pay for that device. So in that scenario, maybe we have a bring your own device policy that allows them to bring their own devices and use their own devices, and how are we going to treat that, and it lays out exactly what that looks like. A bring your own device policy is very common for a lot of businesses.

Partnerships

Then we've got that other relationship, working with partners. So we maybe need some sort of partnership agreement. Maybe there's a partnership contract that we sign. But a partnership contract is going to be very detailed, and we have lawyers look at it, and it's going to be very legalistic. So there are steps that we can actually do before we actually get to the contract level. The thing is, a lot of times when you get to the contract level, you've already spent years in negotiation, or at least months, and there's already been a big investment, and that's a long ways away to have this legal document. So leading up to it, we might want to put some protection in place.

A memorandum of agreement, or an MOA, is something that we can put in place before we get to the full contract, something that just says, hey, this is what we're agreeing upon. There is some legal binding to it, that is, that I can take somebody to court, or a business can take somebody to court, if somebody crosses the lines. But really what it does is it just protects the assets and it protects the companies, that this is the direction we're heading. We're leading up to a contract and there's some legal grounding with that.

But sometimes we're not even to that point where we want that legal grounding, where we just want an understanding between two parties of what we're guiding to, what we're going to. And so that's the memorandum of understanding. There's not as much legal backing to this, but at least we've got a document that outlines what this relationship is going to look like. So a lot of times we'll start out with this memorandum of understanding, so that way we've got this good understanding of what we're heading towards and what we have, and then we move to maybe a memorandum of agreement or a partnership where it has a little more legal boundaries with it, of exactly how the partnership is going to work.

There are a lot more policies and things that we create, but these are the major categories that they mostly fall into: those who are internal to the company, those who are clients of us, those who we are clients or customers of, and then partners that the business is partnering with. We want to make sure that there is a good understanding with all of these entities, with all these different groups, with all these users, with all these stakeholders, whoever the case may be. We want to make sure that there's a good understanding of what is expected as we move forward with these agreements and partnerships and moving forward with that relationship.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →