CompTIA Security+ (SY0-701)Security Program Management and OversightMedium
A software vendor wants to share proprietary source code with a client's security team so they can perform a source code review, but the vendor is concerned about the client disclosing the code to competitors. Which document should be signed before the review begins?
- AMemorandum of Agreement (MOA)
- BService Level Agreement (SLA)
- CBusiness Associate Agreement (BAA)
- DNon-Disclosure Agreement (NDA)
Show answer & explanationAnswer & explanation
Correct answer: D. Non-Disclosure Agreement (NDA)
A Non-Disclosure Agreement (NDA) is a legal contract that obligates a party to protect confidential information, such as proprietary source code, from unauthorized disclosure. This is the appropriate document to protect the vendor's intellectual property during the review.
Why the other options are wrong
- A. An MOA outlines a formal agreement between parties on responsibilities, but is not specifically for confidentiality.
- B. An SLA defines performance metrics and service expectations, not confidentiality obligations.
- C. A BAA is used under HIPAA between covered entities and business associates handling PHI, not source code.
Non-Disclosure Agreement (NDA)
A legally binding contract that requires one or more parties to keep specified information confidential and not disclose it to unauthorized parties.
- Commonly used before sharing proprietary code, trade secrets, or sensitive data
- Can be unilateral (one party discloses) or mutual (both parties disclose)
- Breach of an NDA can result in legal and financial consequences
Memory trick: NDA = 'No Disclosure Allowed' for secrets