Domain 2: Governance and Management of IT7 min · 3 questions

Service Level Agreements and Performance Monitoring

An SLA nobody measures is a paragraph, not a control. The exam tests what makes a service level meaningful and how an auditor knows it is actually met.

What this makes you able to do

Evaluate whether service level agreements are measurable, monitored against independent data, and enforced.

By the end you can

  • State the properties that make a service level meaningful and testable.
  • Explain why the source of the performance data matters.
  • Recognise when an SLA exists but provides no assurance.

Transcript

Service level agreements and performance monitoring. This lesson is about what makes a service level a real control, and how an auditor knows it is actually being met.

Here is the situation. The cloud contract has a thorough S-L-A: ninety nine point nine per cent availability, defined response times, credits for breaches. It reads well. Then you ask for the last twelve months of measured performance against it, and there is none. Nobody has ever checked. The S-L-A is real. As a control, it is doing nothing.

An S-L-A becomes a control, rather than a statement of good intentions, when it has two properties. Its targets are specific and measurable, so performance can be tested objectively. And breaching them carries a consequence, so the target has force. Without measurability and consequence, the S-L-A is intent, not control.

So hold those two apart. Measurable targets: specific, quantified levels you can test. Ninety nine point nine per cent availability, a four-hour response time. Good service is not a target; a number is. And consequences: something that follows when a target is missed, service credits, escalation, termination rights. A target with no consequence has no force. Signatures and legal review do neither of those jobs.

Verifying that an S-L-A was met is an evidence question, and the reliability hierarchy from Domain 1 applies directly. The provider’s own monthly summary is self-reported by the very party whose performance is being judged. That is the weakest kind of evidence.

The most reliable evidence is independent measurement: your own uptime monitoring, or a neutral third-party monitor. It does not depend on the party being measured having reported honestly. When a question asks for the most reliable source of S-L-A performance evidence, prefer independent data over self-reported figures, exactly as you would prefer a configuration you extracted yourself over a screenshot the provider sent.

And one more thing the exam likes to slip in: the absence of complaints is not measurement. Users under-report, and silence is not evidence that a service level was met. No news is not the same as good news.

So rank the sources. Your own independent monitoring is the strongest, because it does not rely on the provider at all.

Below it, the provider’s self-reported summary, which comes from the party in question.

Weaker still, the provider’s verbal assurance, a representation. And at the bottom, the absence of complaints, which is not evidence at all. Prefer the top of that list.

The core failure, though, is the one in our scenario: an S-L-A that is never measured against. Without monitoring, you cannot know whether targets are met, cannot substantiate a breach, and cannot enforce a consequence. You cannot even conclude the provider is in breach, because no one is measuring. The lack of monitoring is the finding.

So carry this away. The auditor’s test is not, is there an S-L-A. It is, is it monitored, and against independent data. A well-written agreement nobody measures assures nothing at all.

Knowledge check
0 / 3
  1. 1.Which of the following makes a service level agreement MOST useful as a control?

  2. 2.An IS auditor is verifying whether a provider met its 99.9% availability SLA. What is the MOST reliable source of evidence?

  3. 3.An organisation has a detailed SLA with its cloud provider but has never measured actual performance against it. What is the MAIN issue?

Independent training produced by Marco Cavani. Not affiliated with, endorsed by, or sponsored by ISACA. CISA is a registered trademark of ISACA. Practice questions are written for this course and are not reproduced from ISACA materials.

Stay ahead of cyber threats

Get the latest cybersecurity reports, threat intelligence, and IT governance insights delivered straight to your inbox. No spam. Unsubscribe any time.

No spam. Unsubscribe at any time.