TechKnowSurge
K0872 K0873 CompTIA Security+ 5.3 ISC2 CISSP 1.6
VideoSecurityFree

Operational Level Agreement (OLA)

A Service Level Agreement (SLA) defines the performance standards a provider must meet, while an Operational Level Agreement (OLA) details the internal processes used to achieve those standards. Understanding the distinction between these two documents is essential for evaluating and managing third-party service relationships.

Complete this video to capture a CTF flag worth 1 point.

About this video

A Service Level Agreement (SLA) is a formal document that establishes the performance standards a service provider is expected to meet. Common metrics include uptime thresholds and availability windows, and SLAs are a standard component of virtually any provider relationship. Organizations relying on external services for critical business functions should review and confirm SLA terms before entering any agreement, as these commitments define the baseline quality of service being contracted. An Operational Level Agreement (OLA) addresses a gap that SLAs leave open: while an SLA states what level of service will be provided, it does not specify how the provider will achieve it. The OLA documents the internal operations, responsibilities, dependencies, and incident management procedures that support SLA compliance. It is a more detailed and complex document, often covering multiple teams or parties, and may go by different names depending on the organization. In practice, SLAs are far more common than OLAs and are a routine part of vendor and provider contracts. OLAs become relevant when an organization has a specific interest in the processes and accountability structures behind service delivery, rather than just the end metrics. Real-world examples, such as the published SLAs from Amazon Web Services and the OLA framework used by UC Berkeley, illustrate how these documents differ in scope and depth, with OLAs offering a significantly more granular view of how service commitments are operationally supported.

What you'll learn

What's covered

SLA vs OLA

Aligned to

CompTIA Security+
5.3 Explain the processes associated with third-party risk assessment and management
ISC2 CISSP
1.6 Develop, document, and implement security policy, standards, procedures, and guidelines

Key terms

Service Level Agreement
SLA
A formal commitment between a provider and customer that guarantees a defined level of service uptime, including terms for compensation if the standard is not met.
Operational Level Agreement
OLA
An internal agreement that defines the responsibilities and service expectations between departments within the same organization in support of an SLA.

Topics

Operational Level Agreement Service Level Agreement It Service Management Vendor Management It Governance

Transcript

A service level agreement, or SLA, is something that you should have with all your providers. That is, you should expect them to operate at a certain level, especially if your internal systems and your business rely on those services.

However, there are some gaps in what the SLA covers. That is, it maintains a certain standard, things like uptime, but it doesn't say how they're going to perform their functions when it comes to maintaining those SLAs. In that case we may want an operational level agreement. One thing to note is that an OLA could go by many different names, so it's not necessarily called an operational level agreement.

SLA Versus OLA

Both an SLA and OLA really has to deal with service providers providing a service, and the SLA specifies what level of a service is going to be provided. So in essence it's going to be things like uptime, versus an OLA is how are we going to achieve that, what are the operations that we are going to perform to give you that SLA.

What we're seeing here is we're seeing the long list of Amazon services, Amazon Web Services, that they can deliver, and all the SLAs for their services. Now an SLA can be more complex than what you're seeing here, but essentially it's a little more simplistic and just what is the service levels that are being delivered.

In contrast, an operational level agreement can be a little more complex. It gives the operational level of what's going to happen. So here we see an operational level agreement for UC Berkeley. So as we scroll through here, it starts out with a general overview, goes over the services and dependencies and what those look like. It outlines who are the responsible parties, so who's signing this contract or coming into this contract, what are the rules and responsibilities for each of those parties. It gets into the what if there's an incident, what incident management looks like. So it gets much more detailed in that operational level.

How Common Are They?

One question you may have is what is the use of these two documents and how common are they. Well, the SLA is very standard. This is, if you're a service provider, your customers are probably going to ask for it. If you are getting services from a service provider, you're going to want to see the SLA and verify what service levels you're agreeing to.

The operational agreement is not as common, not nearly as common as the SLA. So where we see this come into play is if you care about how the service is being delivered, not just what the service levels are.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →