Determines minimum level of services required - uptime, response time, etc.
. Longer term relationships usually between manufacturers and resellers
. Used by the gov't to define security controls
. Less formal agreement, not a signed contract or legally binding
. Next step up from MOU
. Helps ID fraud or illegal activity - you can see if anything weird happens when someone leaves
. No one keeps control of one role too long
. Split the knowledge (such as 2 people knowing half the combo of a lock); dual control
. Nothing visible on top of desk when you leave
. Something found in the background check that denies someone employment
. Prevents the use and dissemination of confidential information - it's a legal contract
. Train on IT security for the role at the time of hiring
. Documents exactly what is appropriate and what is not on the network - can cover all hardware
. Discuss with employee their reason for leaving
.