ExamGecko
Question list
Search
Search

Related questions











Question 296 - CISA discussion

Report
Export

Which of the following BEST protects an organization's proprietary code during a joint-development activity involving a third party?

A.
Statement of work (SOW)
Answers
A.
Statement of work (SOW)
B.
Nondisclosure agreement (NDA)
Answers
B.
Nondisclosure agreement (NDA)
C.
Service level agreement (SLA)
Answers
C.
Service level agreement (SLA)
D.
Privacy agreement
Answers
D.
Privacy agreement
Suggested answer: B

Explanation:

A nondisclosure agreement (NDA) is the best way to protect an organization's proprietary code during a joint-development activity involving a third party. An NDA is a legal contract that binds the parties involved in a joint-development activity to keep confidential any information, data or materials that are shared or exchanged during the activity. An NDA specifies what constitutes confidential information, how it can be used, disclosed or protected, how long it remains confidential, what are the exceptions and remedies for breach of confidentiality, and other terms and conditions. An NDA can help to protect an organization's proprietary code from being copied, modified, distributed or exploited by unauthorized parties without its consent or knowledge. The other options are not as effective as option B, as they do not address confidentiality issues specifically. A statement of work (SOW) is a document that defines the scope, objectives, deliverables, tasks, roles, responsibilities, timelines and costs of a joint-development activity, but it does not cover confidentiality issues explicitly. A service level agreement (SLA) is a document that defines the quality, performance and availability standards and metrics for a service provided by one party to another party in a joint-development activity, but it does not cover confidentiality issues explicitly. A privacy agreement is a document that defines how personal information collected from customers or users is collected, used, disclosed and protected by one party or both parties in a joint-development activity, but it does not cover confidentiality issues related to proprietary code.Reference:CISA Review Manual (Digital Version) , Chapter 3: Information Systems Acquisition, Development & Implementation, Section 3.2: Project Management Practices.

asked 18/09/2024
Tillmon, Quinton
37 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first