TechKnowSurge
CompTIA Security+ 5.3 ISC2 CISSP 1.9 NIST CSF GV.SC-05 NIST 800-53 SA-9 NIST CSF GV.SC-07 ISC2 CISSP 1.11
VideoSecurityFree

Service-level agreement (SLA)

A Service Level Agreement (SLA) is a formal contract between a vendor and a customer that defines the expected performance and availability of a service. Understanding when and how to establish SLAs is essential for protecting business operations and managing customer expectations.

Complete this video to capture a CTF flag worth 1 point.

About this video

A Service Level Agreement (SLA) is a binding contract between a service provider and a customer that specifies the expected level of service, most commonly expressed as an availability or uptime percentage. For example, a cloud service provider might guarantee 99.9% uptime — roughly no more than eight hours of downtime per year — and the SLA formalizes that commitment in writing, giving both parties a clear, enforceable reference point. While no universal legal mandate requires SLAs, many enterprise customers and compliance frameworks treat them as standard practice. The AWS S3 SLA illustrates how these agreements work in practice: Amazon guarantees 99.9% availability and issues service credits ranging from 10% to 100% of charges depending on how significantly actual uptime falls below that target. For organizations that depend on third-party vendors, obtaining a signed SLA is a critical risk management step. If a vendor's services go offline and disrupt business operations, a properly executed SLA provides documented legal recourse. On the other side of the relationship, businesses providing services to their own customers face a different set of considerations. Maintaining an internal SLA helps set performance standards for staff without exposing the organization to external liability. However, publishing an SLA externally — whether required by a customer or offered proactively — can serve a valuable purpose by anchoring customer expectations to realistic, measurable benchmarks rather than allowing unchecked assumptions to create unnecessary friction.

What you'll learn

What's covered

Service Level Agreements

Aligned to

CompTIA Security+
5.3 Explain the processes associated with third-party risk assessment and management.
ISC2 CISSP
1.9 Understand and apply risk management concepts
1.11 Apply Supply Chain Risk Management (SCRM) concepts
NIST CSF
GV.SC-05 Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties.
GV.SC-07 The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship.
NIST 800-53
SA-9 External System Services

Key terms

Service Level Agreement
SLA
A formal commitment between a provider and customer that guarantees a defined level of service uptime, including terms for compensation if the standard is not met.
Availability
The assurance that systems and data are accessible and operational when needed by authorized users.
Uptime
The amount of continuous time a network device or service has been running without interruption, often expressed as a percentage of total time available. High uptime percentages (such as 99.9%) indicate a reliable network, while planned and unplanned downtime reduces this figure.
Service Credit
A partial or full refund issued by a service provider to a customer when agreed-upon service levels, such as uptime thresholds, are not met.

Topics

Service Level Agreement Vendor Management Uptime Availability Cloud Services It Governance Service Credits

Transcript

A service level agreement, or SLA, sets the expectations between a vendor and their customers. A service level agreement sets up the expectations of what the service level that will be delivered is.

Let me give you an example. Let's say I have a cloud service and I want that cloud service to be up almost all the time, and maybe I expect it to only be down for a short period of time even throughout the year — maybe it's only 8 hours throughout the year. What I'm going to expect is a service level that it's going to be up 99.9% of the time, and I'm going to look for an SLA, or service level agreement, that says this service will be up 99.9% of the time.

Who should establish an SLA

So who should establish a service level agreement? I'm not aware of any specific laws and regulations — although I wouldn't be surprised if they're out there — that require an SLA. I do know that there are some customers that require service level agreements, and I've had to implement service level agreements because customers demand it. And I know that some frameworks have it built into the framework, so you might be creating one based off of that.

But who do I recommend have a service level agreement? I think there are a couple of different scenarios here. One is if you are working with a vendor, and number two is if you're working with your clients.

If you're working with a vendor and you rely on those services, and if those services went offline it would hinder your business, then make sure you get a service level agreement. Make sure there's an agreement between you and that vendor, that service provider, so that way if they fall short then there's some legal recourse that you have. Make sure you get it in writing.

SLAs for the services you offer

When should you create a service level agreement for the services that you offer? In that scenario I kind of look at it like this: if I'm providing services for customers then I'm going to maybe have an internal SLA that sets the tone and the standard for my employees. I'll have that internally, but I don't necessarily like to release that externally if I can help it. The reason for that is because as soon as I release it externally and give it to my customers, now there's some legal recourse that they have. So I'm just careful with who I release that to, and if they're requiring it then I'll release it at that point in time.

There is also a reason to release it even if other people are not expecting that, and that is just to set the expectations. By having a service level agreement you can set some expectations, because maybe some of your customers have super high expectations that it's not reasonable to meet. Setting out an SLA in that example can help alleviate some of the pain points you might have and make a more realistic expectation for those customers.

An example: the AWS SLA

Here's an example of a service level agreement. This is the service level agreement for Amazon Web Services, or AWS. If I scroll through here we can see that there are a lot of different services, and I'm just going to take one of the S3 services, so I'll take a look at this Amazon S3.

We can see here the expectation for this is that it is up 99.9% of the time or better, and if it goes below that then there is a service credit. If there's anywhere between 98 and 99.9 they'll give me a 10% credit back on my bill. If it's between 95 and 98 then it's 25%. And if it's below 95%, then they'll give 100% of the money that they charge me — they'll give it back for that time period. So this is the agreement that I would have between Amazon Web Services and me.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →