Match the agreement and the request to the relationship

short · 35 min · Objective 5.3

Task

Work eleven described situations to the right document: the four request documents of vendor selection and the seven agreement types of a vendor relationship. Then write the security clauses each agreement needs. The acronyms are recall marks; the clauses are what makes an agreement a control.

Steps

  1. Write /tmp/relationships.md describing eleven situations, one for each of RFI, EOI, RFP, RFQ, SLA, SLO, MOU, MOA, MSA, SOW and NDA, without naming the document.
  2. For each, record the correct document and the single feature that decided it. For the MOU, that feature is that it is not intended to bind; for the SLO, that it is one measurable target inside an SLA.
  3. For each agreement (not the request documents), list the security clauses it should carry: incident notification within a stated period, right to audit, approved sub-processors, data location, encryption, return and destruction at termination, and liability. For the request documents, write what security requirement must appear in them, remembering that a supplier prices only what you asked for.
  4. Mark which clauses must be negotiated BEFORE signature because there is no leverage afterwards.
  5. Write /tmp/agreements.csv as scenario,document,deciding_feature,key_clauses.
  6. For the SLA specifically, write in /tmp/relationships.md the three ways a service level can be met on paper while the customer had a bad month, and why you measure the SLOs yourself.

Verify

python3 - <<'PY'
import csv
rows=list(csv.DictReader(open('/tmp/agreements.csv')))
assert len(rows)>=11, 'fewer than eleven situations'
kinds={r['document'].strip().upper() for r in rows}
need={'RFI','EOI','RFP','RFQ','SLA','SLO','MOU','MOA','MSA','SOW','NDA'}
missing=need-kinds
assert not missing, 'not covered: '+', '.join(sorted(missing))
mou=[r for r in rows if r['document'].strip().upper()=='MOU'][0]
assert 'bind' in mou['deciding_feature'].lower() or 'intent' in mou['deciding_feature'].lower(), \
    'the MOU was not distinguished by being non-binding'
for r in rows:
    assert r['key_clauses'].strip(), 'nothing listed for '+r['document']
print('all eleven documents, each with a deciding feature and its security content')
PY
grep -ciE "excluded|planned maintenance|service credit|measure" /tmp/relationships.md

The MOU assertion checks the distinction the exam most often tests: it is the only document on the list whose defining property is that it does not bind. The final grep must be non-zero: you identified how an SLA can be met while the customer suffers, which is the difference between a measured service level and a promised one.

Notes

The 'before signature' marking is the practically important half. A right-to- audit clause is cheap to ask for during negotiation and impossible to obtain afterwards, and the same is true of incident notification timeframes, which matter because your own regulatory clock starts when the breach happens, not when the vendor decides to tell you.

This is an independent study companion for CompTIA Security+ SY0-801 and is not produced by or endorsed by CompTIA.