Establishing secure connection…Loading editor…Preparing document…

Information Security Agreement

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

INFORMATION SECURITY AGREEMENT

This Information Security Agreement (the Agreement) is entered into as of Effective Date: by and between Disclosing Party: , an entity type Corporation LLC Individual, with principal place of business at ; and Receiving Party: , an entity type Corporation LLC Individual, with principal place of business at .

RECITALS

WHEREAS, Disclosing Party possesses certain Confidential Information, trade secrets, personal data and other sensitive information that must be protected from unauthorized access, use, disclosure and destruction; and

WHEREAS, Receiving Party will receive, process, store, or otherwise have access to such information in connection with the Parties' business relationship and requires defined security measures, incident response procedures, and contractual assurances; and

WHEREAS, the Parties desire to allocate responsibilities and establish minimum information security standards and remedies for failure to comply.

NOW, THEREFORE, in consideration of the mutual promises set forth herein, the Parties agree as follows:

1. DEFINITIONS

1.1 "Confidential Information" means all non-public information disclosed by Disclosing Party to Receiving Party, whether in oral, written, electronic or other form, including but not limited to personal data, financial information, technical data, trade secrets, system architecture, authentication credentials, and security procedures.

1.2 "Personal Data" means any information relating to an identified or identifiable natural person. The categories of Personal Data that may be processed under this Agreement are:

2. SCOPE OF PROCESSING

2.1 Receiving Party shall process Confidential Information only as necessary to perform its obligations under the Parties' underlying commercial agreement and solely on documented instructions from Disclosing Party.

2.2 The authorized purposes for processing and the services to be performed are:

3. SECURITY CONTROLS

3.1 Receiving Party shall implement and maintain administrative, physical and technical safeguards appropriate to the nature of the Confidential Information. Minimum controls include, at a level no less protective than described below:

- Access control procedures limiting access to authorized personnel; role-based access control and least-privilege enforcement; multi-factor authentication for remote access and privileged accounts.

- Encryption of Confidential Information in transit and at rest using industry-standard algorithms. Required encryption standard:

- Patch management, vulnerability scanning and timely application of security updates.

3.2 Receiving Party shall maintain logical and physical segregation of Disclosing Party data where feasible and shall not commingle Disclosing Party data with data belonging to other customers.

4. INCIDENT RESPONSE AND NOTIFICATION

4.1 Receiving Party shall maintain an incident response program and shall notify Disclosing Party without undue delay and no later than after becoming aware of a security incident affecting Confidential Information.

4.2 Notification shall include a description of the incident, types of data affected, steps taken to contain and mitigate the incident, and proposed remedial actions. Additional incident details and timeline:

5. AUDIT, ASSESSMENT AND RECORDS

5.1 Upon reasonable notice, Receiving Party shall permit Disclosing Party or an independent auditor engaged by Disclosing Party to conduct audits, inspections and assessments to verify compliance with this Agreement. Audits may include review of policies, procedures, technical controls, and records. Confidentiality of audit findings shall be maintained.

5.2 Receiving Party shall maintain records of processing activities and security incidents reasonably sufficient to demonstrate compliance for a period of .

6. SUBCONTRACTORS AND THIRD-PARTY PROCESSORS

6.1 Receiving Party shall not engage subprocessors to process Confidential Information without prior written authorization. Where subprocessors are authorized, Receiving Party shall impose written obligations no less protective than those in this Agreement and shall remain responsible for the acts and omissions of such subprocessors.

6.2 Approved subprocessors (if any):

7. CONFIDENTIALITY AND USE LIMITATIONS

7.1 Receiving Party shall maintain Confidential Information in strict confidence and shall not disclose such information except to authorized personnel, subprocessors or as compelled by law, subject to advance notice to Disclosing Party where legally permitted.

7.2 Receiving Party shall use Confidential Information only to perform its obligations under this Agreement and shall implement commercially reasonable measures to prevent unauthorized access, disclosure, alteration or destruction.

8. RETURN OR DESTRUCTION

8.1 Upon termination or expiry of the Parties' underlying relationship, Receiving Party shall, at Disclosing Party's election, return all Confidential Information or securely destroy it and certify in writing the completion of such destruction within .

9. LIABILITY, INDEMNIFICATION AND INSURANCE

9.1 Receiving Party shall indemnify, defend and hold harmless Disclosing Party from any claims, damages, losses or expenses arising out of Receiving Party's breach of this Agreement, unauthorized disclosure of Confidential Information, or failure to implement required security measures.

9.2 Notwithstanding any other provision, neither Party shall be liable for incidental, consequential or punitive damages except for liability resulting from gross negligence, willful misconduct, or breaches involving Personal Data that give rise to statutory liability.

9.3 Receiving Party shall maintain cyber liability insurance with a minimum limit of and provide certificates of insurance upon request.

10. TERM AND TERMINATION

10.1 This Agreement shall commence on the Effective Date and continue for a period of , unless earlier terminated in accordance with this Agreement.

10.2 Either Party may terminate this Agreement for material breach that remains uncured for thirty (30) days following written notice specifying the breach.

11. SURVIVAL

Sections addressing Confidentiality, Return or Destruction, Liability, Indemnification, Audit Rights and Survival shall survive termination or expiration of this Agreement for the longer of the period specified in those sections or the statute of limitations applicable to the claims.

12. NOTICES

12.1 All notices required under this Agreement shall be in writing and delivered to the contact details below. Notices are effective upon receipt.

13. AMENDMENT, WAIVER AND COUNTERPARTS

13.1 This Agreement may be amended only by a written instrument executed by authorized representatives of both Parties. No waiver of any provision shall be effective unless in writing and signed by the waiving Party.

13.2 This Agreement may be executed in counterparts and by electronic signature, each of which shall be deemed an original, and all of which together shall constitute one and the same instrument.

14. GOVERNING LAW, ENTIRE AGREEMENT, SEVERABILITY

14.1 Governing Law. This Agreement shall be governed by and construed in accordance with the laws of the jurisdiction of , without regard to conflict of law principles.

14.2 Entire Agreement. This Agreement constitutes the entire agreement between the Parties with respect to the subject matter herein and supersedes all prior oral or written agreements.

14.3 Severability. If any provision of this Agreement is held invalid or unenforceable, the remaining provisions shall remain in full force and effect and the Parties shall negotiate in good faith a substitute provision to effect the original intent.

15. CERTIFICATIONS

Each Party represents and warrants that it has the full right, power and authority to enter into this Agreement and to perform its obligations hereunder, and that the execution and delivery of this Agreement has been authorized by all necessary corporate or other organizational action.

Disclosing Party Printed Name:

By:

Date:

Receiving Party Printed Name:

By:

Date:

Enter text✕

What an Information Security Agreement Covers

An Information Security Agreement (ISA) is a formal contract that sets expectations, responsibilities, and technical controls for handling, protecting, and sharing confidential information between parties. It defines permitted use, data classification, access controls, encryption standards, incident reporting, audit rights, remediation obligations, and post-termination duties. ISAs often reference regulatory frameworks such as HIPAA or PCI-DSS and assign clear accountability for compliance, monitoring, and corrective actions to reduce data breach risk and support enforceability in commercial relationships.

Why an ISA Matters for Risk and Compliance

An ISA documents security commitments, clarifies responsibilities for data handling, and reduces legal and regulatory uncertainty. It supports auditor requests, defines breach response steps, and makes contractual remedies explicit so both parties understand obligations and risk allocation.

Why an ISA Matters for Risk and Compliance

Who Typically Prepares and Signs an ISA

Typical users include legal teams, procurement, IT security, and third-party vendors managing confidential data under contract.

  • IT security teams — specify technical controls, encryption, and access management responsibilities.
  • Procurement and vendor managers — include contractual remedies and audit rights for third parties.
  • Healthcare and financial organizations — impose specific regulatory clauses such as HIPAA or GLBA controls.

Use ISAs when engaging vendors handling sensitive data, outsourcing services, or exchanging regulated personal information.

Who Signs and Who Manages the Agreement

Authorized Signer

An individual with contractual authority to bind the organization, typically a director, officer, or delegated procurement designee. Verify signature authority before execution and match the name to corporate records to avoid disputes over validity or mistaken acceptance of obligations.

Security Officer

The security or privacy officer is responsible for implementing controls described in the ISA, coordinating audits, and managing incident response. Provide contact details and escalation steps so counterparties can report suspected breaches or compliance failures promptly and consistently.

Essential Data Elements to Include

Party Name: Full legal name and entity type
Effective Date: Enter MM/DD/YYYY; governs obligations start
Data Types: Classify data (PII, PHI, PCI, confidential)
Security Controls: Encryption, access controls, logging required
Point of Contact: Name, title, email, and phone
Breach Notice: Notification timeline and delivery method

Common Legal and Financial Risks

1099 Late Penalty: Up to $330 per form
1099 Intentional: At least $660 per form
I-9 Violation: $281–$2,789 per violation
Backup Withholding: 24% withholding rate
Contract Breach Risk: Damages, injunctive relief possible
Regulatory Fines: HIPAA fines and penalties

Frequent Preparation Pitfalls to Avoid

  • Incomplete fields or vague data classifications lead to ambiguity, making enforcement and audits slower and increasing legal risk during disputes.
  • Failing to designate authorized signers or verify authority can void contractual commitments if a counterparty challenges the signer's authority in court.
  • Overly broad liability caps or missing insurance requirements may leave parties exposed to unanticipated losses after a security incident or data breach.
  • Neglecting incident response timelines or audit rights can hinder regulatory reporting and increase fines or contractual penalties.

Real-world Examples of ISA Use

These examples show how different organizations use an Information Security Agreement to manage vendor risk and regulatory obligations.

Optica Ventures

Optica Ventures required a standard ISA for third-party analytics vendors to protect investor data and proprietary models.

  • Tight access and encryption rules.
  • The agreement specified encryption at rest and in transit, annual penetration testing, and audit rights; Optica reduced policy exceptions and accelerated vendor onboarding while preserving legal remedies for noncompliance through defined breach procedures.

Fertility Centers of Illinois

Fertility Centers of Illinois integrated an ISA into patient data exchanges with labs and referral partners to meet HIPAA obligations.

  • Defined PHI handling and business associate obligations.
  • The ISA included a BAAs clause, logging requirements, and incident notification timelines; it clarified liability limits and reduced time to investigate suspected breaches, improving compliance documentation for audits and payer reviews.

Step-by-Step: Prepare and Execute an ISA

Follow these steps to prepare, execute, and manage an Information Security Agreement with internal and external stakeholders.

  • 01
    Prepare Draft: Identify parties, data categories, and required controls.
  • 02
    Assign Roles: Designate signatories and the security point of contact.
  • 03
    Review Terms: Confirm encryption, incident response, and audit provisions.
  • 04
    Execute & Store: Obtain signatures, retain originals, and record version history.

Typical ISA Lifecycle

The typical lifecycle for an ISA includes drafting, approval, signing, implementation, monitoring, and periodic review.

  • Draft: Use template clause bank aligned to regulatory requirements.
  • Approve: Legal and security complete review and negotiate terms.
  • Sign: Execute by authorized signers; consider notarization if required.
  • Monitor: Track controls, audit logs, and remediation activities.

Core Clauses to Include in Every ISA

A professional Information Security Agreement should clearly define scope, security controls, incident protocols, liability, audit rights, and data return or destruction obligations.

Scope

Describe covered systems, data classifications, environments, and third-party subprocessors, including retention durations and permitted processing purposes to avoid ambiguity in audits.

Security Controls

List required technical measures such as AES-256 at rest, TLS 1.2/1.3 in transit, access control, MFA, logging, and regular vulnerability scanning and patch management programs.

Incident Response

Define notification timeframes, roles, forensic obligations, and communication protocols to customers and regulators; require cooperation during investigations and specify costs allocation for remediation.

Audit Rights

Grant rights to perform security audits, penetration tests, and compliance assessments, define frequency, acceptable notice, and remediation benchmarks, and require delivery of redacted audit reports where necessary.

Liability

Specify indemnity, caps on direct damages, exclusions for consequential losses, insurance minimums, and carve-outs for willful misconduct; require proof of coverage upon request.

Data Return

State procedures for secure data return or verified destruction at termination, format requirements for returned data, and certification of deletion including copies in backups and third-party repositories.

eSignature Pricing and Feature Snapshot

The table compares starting prices and core capabilities of common eSignature providers relevant to executing an Information Security Agreement.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial 7-day free trial Varies by plan Varies by plan Varies by plan Varies by plan
Bulk Send Yes Yes Yes Yes No
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes Yes Yes No No

Frequently Asked Questions

Answers to common questions about creating, signing, and enforcing an Information Security Agreement, including digital execution and compliance considerations.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users