TechKnowSurge
CompTIA Security+ 5.3 NIST CSF GV.SC-05 ISC2 CISSP 1.11 NIST 800-53 SA-9 CompTIA SecurityX 3.2
VideoSecurityFree

Aggrement Type Example: SaaS

SaaS agreements differ significantly from penetration testing contracts, relying instead on standardized terms of service and service level agreements that define uptime guarantees, security responsibilities, and user obligations. Understanding these documents is essential for ensuring a SaaS provider meets organizational security and operational standards.

Complete this video to capture a CTF flag worth 1 point.

About this video

SaaS agreements operate very differently from the customized contracts typically used in arrangements like penetration testing engagements. With a SaaS provider, the vendor manages all backend infrastructure and bears primary responsibility for security, while customers interact only through the user interface and manage their own data within the platform. Because so much control is handed over to the provider, it becomes essential to hold that provider accountable to defined, documented standards. One of the most important documents to review is the service level agreement, or SLA, which specifies the level of service the provider commits to delivering. A common example is an uptime guarantee, such as 99.5% availability, with defined service credits issued to customers if performance falls below that threshold. While the SLA establishes performance commitments, it does not capture the full scope of the relationship or its legal terms. The terms of service fills that role, functioning as a binding legal agreement that governs how the service can be used. Unlike individually negotiated contracts, terms of service are standardized documents that apply to all customers and are accepted through a checkbox at sign-up. These agreements are written primarily to protect the vendor, which means organizations must read them carefully to ensure their own interests, data rights, and security expectations are adequately addressed and that the terms align with internal policies before committing to any SaaS platform.

What you'll learn

What's covered

SaaS Agreements & Security

Aligned to

CompTIA Security+
5.3 Explain the processes associated with third-party risk assessment and management.
NIST CSF
GV.SC-05 Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties.
ISC2 CISSP
1.11 Apply Supply Chain Risk Management (SCRM) concepts
NIST 800-53
SA-9 External System Services
CompTIA SecurityX
3.2 Explain the security requirements and considerations of cloud deployment models.

Key terms

Software as a Service
SaaS
A cloud service model that delivers software applications over the internet on a subscription basis.
Service Level Agreement
SLA
A formal commitment between a provider and customer that guarantees a defined level of service uptime, including terms for compensation if the standard is not met.
Availability
The assurance that systems and data are accessible and operational when needed by authorized users.
Security Policy
A formal document that defines an organization's security goals, rules, and responsibilities.
Terms of Service
ToS
An agreement between a service provider and a user that outlines the rules, rights, and responsibilities governing use of a product or service.

Topics

Saas Cloud Security Service Level Agreements Terms Of Service Vendor Management Cloud Computing

Transcript

Agreements With a SaaS Company

The type of agreements that we have with a pentester look much different than the type of agreements we have with something like a software company, or a software as a service company, where there's usually some sort of licensing or terms of service. So let's take a look at a SaaS company and what some of them are.

When we're doing everything ourselves, we're responsible for security. But when we're working with a cloud provider, then we're going to rely on them for certain aspects when it comes to security. A SaaS company is an extreme of that, where they are managing all of the backend systems, and all we're doing is working from the user interface and inputting data into the system and then managing our data through that — that essentially is what we're doing. So as software as a service, they're handling all of that and they're responsible for security. We better make sure that they're doing security right, and hold them to certain standards.

Service Level Agreements

One of those standards we want to look at is a service level agreement. What level of service are they guaranteeing that they're going to deliver to us?

Here's a service level agreement, an SLA, for Meo. Meo is a software as a service company and it's one I've used in the past, so I thought I'd look it up. As you can see, there are certain guarantees that they're going to have certain service levels. This particular one right here is saying how much uptime they'll have, and what they say they're going to have is a 99.5% or greater uptime. So that's what we can rely on them for, and if they dip below that then we get a service credit — they'll credit our account back depending on how low they dip below this 99.5%.

Terms of Service and Licensing

But an SLA doesn't give you all of the details, just what service levels they're guaranteeing you. So what you also want to do is make sure that you check out whatever licensing agreement or terms of service that you're agreeing to.

Usually companies like meuro don't have individual contracts with every single customer that's really customized. What they have is they just have a terms of service. They set up the terms of what you are agreeing to if you're using their service, and that's the little check box that you check that you are agreeing to their terms of service, or their licensing, or however they put it. There are several different names for it, but essentially when you sign up for the service you're agreeing to those terms.

Here's that miros site again, and I've gone to the terms of service page. If you look over it, it looks very similar to a contract, and sometimes they read like a contract as well. So you better believe that this terms of service is going to protect the company. What you need to do is read through it and make sure it's going to protect you as a user of the software as well, and make sure that it falls in line with what your company policies and your organization's policies have already set out.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →