Information Security Agreement for the United States

Information Security Agreement Template for United States

This Information Security Agreement is a legally binding document governed by United States federal and state laws, designed to establish and maintain information security standards between parties sharing sensitive data. It incorporates requirements from various U.S. regulations including GLBA, HIPAA, and state-specific data protection laws, while also considering international standards where applicable. The agreement outlines specific security measures, incident response procedures, and compliance requirements to protect confidential information.

Your data doesn't train Genie's AI

You keep IP ownership of your information

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Download a Standard Template

4.6 / 5
4.8 / 5
Access for free
OR

Alternatively: Run an advanced review of an existing
Information Security Agreement

Let Genie AI's market-leading legal AI identify missing terms, unusual language, compliance issues and more - in just seconds.
Upload your Doc

What is a Information Security Agreement?

This Information Security Agreement addresses the growing need for robust data protection in an increasingly digital business environment. It is essential when organizations share sensitive information, establishing clear security protocols and compliance requirements under U.S. jurisdiction. The agreement covers technical, physical, and administrative safeguards, incident response procedures, and regulatory compliance obligations, particularly relevant given the complex landscape of federal and state data protection laws.

What sections should be included in a Information Security Agreement?

1. Parties: Identifies all parties to the agreement and their legal status

2. Background: Explains the context and purpose of the agreement

3. Definitions: Defines key terms used throughout the agreement

4. Scope of Information Protection: Defines what information is protected and classification levels

5. Security Requirements: Details the technical and organizational measures required

6. Data Handling Procedures: Specifies procedures for storing, processing, and transmitting data

7. Incident Response: Procedures for handling and reporting security incidents

8. Term and Termination: Duration of agreement and termination conditions

What sections are optional to include in a Information Security Agreement?

1. International Data Transfers: Required when data crosses borders - applicable when parties operate in multiple jurisdictions

2. Industry-Specific Requirements: Additional requirements for specific sectors - applicable when dealing with regulated industries like healthcare or finance

3. Subcontractor Requirements: Security requirements for third-party processors - applicable when subcontractors will have access to protected information

What schedules should be included in a Information Security Agreement?

1. Security Controls Matrix: Detailed technical security requirements and controls

2. Data Classification Guide: Detailed information classification levels and handling requirements

3. Incident Response Procedures: Detailed procedures for various types of security incidents

4. Compliance Certificates: Copies of relevant security certifications (ISO 27001, SOC 2, etc.)

5. Contact Matrix: Key contacts for security incidents and escalation procedures

Authors

Alex Denne

Head of Growth (Open Source Law) @ Genie AI | 3 x UCL-Certified in Contract Law & Drafting | 4+ Years Managing 1M+ Legal Documents | Serial Founder & Legal AI Author

Jurisdiction

United States

Publisher

Genie AI

Document Type

Security Agreement

Cost

Free to use
Relevant legal definitions
Clauses
Industries

Gramm-Leach-Bliley Act (GLBA): Federal law that requires financial institutions to protect customers' sensitive financial information and explain their information-sharing practices.

Health Insurance Portability and Accountability Act (HIPAA): Federal law establishing national standards for the protection of individuals' medical records and other personal health information.

Federal Trade Commission Act (FTC Act): Section 5 prohibits unfair or deceptive practices affecting commerce, including those related to data security and privacy practices.

Computer Fraud and Abuse Act (CFAA): Federal law that criminalizes unauthorized access to computers and networks, addressing both external hacking and insider threats.

Electronic Communications Privacy Act (ECPA): Federal law protecting wire, oral, and electronic communications while those communications are being made, in transit, and when stored.

Defend Trade Secrets Act (DTSA): Federal law providing uniform protection for trade secrets, including confidential business information and know-how.

Cybersecurity Information Sharing Act (CISA): Federal law designed to improve cybersecurity through enhanced sharing of information about security threats between the private sector and government.

PCI DSS: Industry standard for organizations that handle branded credit cards, ensuring secure processing, storage, and transmission of cardholder data.

Sarbanes-Oxley Act (SOX): Federal law requiring public companies to establish internal controls and procedures for financial reporting, including IT systems security.

Family Educational Rights and Privacy Act (FERPA): Federal law protecting the privacy of student education records and applying to educational institutions receiving federal funds.

State Data Breach Notification Laws: State-specific requirements for organizations to notify individuals when their personal information has been compromised in a data breach.

California Consumer Privacy Act (CCPA): California state law providing consumers with rights regarding the collection and use of their personal information by businesses.

NY SHIELD Act: New York state law requiring businesses to implement safeguards for private information and expanding breach notification requirements.

General Data Protection Regulation (GDPR): EU regulation that may apply when handling EU residents' data, requiring strict data protection and privacy measures.

NIST Cybersecurity Framework: Voluntary guidance developed by the National Institute of Standards and Technology to help organizations better manage and reduce cybersecurity risk.

ISO 27001: International standard providing requirements for establishing, implementing, maintaining, and continually improving an information security management system.

COBIT: Framework for the governance and management of enterprise IT, providing guidance for security control implementation and risk management.

Teams

Employer, Employee, Start Date, Job Title, Department, Location, Probationary Period, Notice Period, Salary, Overtime, Vacation Pay, Statutory Holidays, Benefits, Bonus, Expenses, Working Hours, Rest Breaks,  Leaves of Absence, Confidentiality, Intellectual Property, Non-Solicitation, Non-Competition, Code of Conduct, Termination,  Severance Pay, Governing Law, Entire Agreemen

Find the exact document you need

Credit Agreement Margin Account

A U.S.-governed agreement establishing terms for margin lending between a broker-dealer and customer for securities trading.

find out more

Model Intercreditor Agreement

A U.S.-law governed agreement establishing rights and priorities between different classes of creditors in secured financing transactions.

find out more

Simple Loan Agreement With Collateral

A U.S. legal agreement establishing terms for a secured loan, including collateral provisions and repayment terms.

find out more

Sale Of LLC Interest Agreement

A U.S. legal agreement documenting the sale and transfer of ownership interests in a Limited Liability Company from one party to another.

find out more

Sale Of Shares Agreement LLC

A U.S. legal agreement documenting the sale and transfer of ownership interests in a Limited Liability Company.

find out more

Collateral Substitute Exchange Agreement

A U.S. legal agreement enabling the exchange of existing loan collateral with substitute collateral while maintaining security interests under UCC provisions.

find out more

Chattel Mortgage Security Agreement

A U.S. legal document creating a security interest in movable property (chattel) to secure a loan, governed by the UCC and state laws.

find out more

Pre Lease Deposit Agreement

A U.S. legal document securing a deposit payment prior to executing a formal lease agreement, subject to state-specific property laws.

find out more

Lending Agreement With Collateral

A U.S.-governed agreement establishing terms for a secured loan, including collateral provisions and security interests under UCC.

find out more

Security Agreement Contract

A U.S.-governed agreement creating a security interest in collateral to secure an obligation, subject to UCC Article 9.

find out more

Pledge Security Agreement

A U.S. law-governed agreement creating a security interest in assets to secure an obligation, subject to UCC Article 9.

find out more

Auto Security Agreement

A U.S. legal document creating a lender's security interest in a motor vehicle under UCC Article 9 and state laws.

find out more

Restaurant Investment Contract

A U.S.-governed agreement establishing terms for restaurant business investment, including ownership rights and profit-sharing arrangements.

find out more

Broker Dealer Referral Agreement

A U.S.-governed agreement establishing terms for referring clients to broker-dealers, compliant with SEC and FINRA regulations.

find out more

Key Holding Contract

A U.S.-compliant agreement governing the professional storage and management of property keys by a security service provider.

find out more

Security Interest Agreement

A U.S. legal document creating an enforceable security interest in collateral under UCC Article 9 to secure an obligation.

find out more

Safe Deposit Box Lease Agreement

A U.S.-governed agreement between a financial institution and customer for the rental and use of a secure storage box within the institution's premises.

find out more

Mortgage Security Agreement

A U.S. legal document creating a security interest in real property to secure a loan, subject to federal and state mortgage regulations.

find out more

Stock Collateral Loan Agreement

A U.S.-governed agreement establishing terms for a loan secured by stocks or securities, subject to federal and state securities regulations.

find out more

Pledged Collateral Account Control Agreement

A U.S. tri-party agreement establishing control over accounts pledged as collateral under UCC Article 9.

find out more

Tri Party Collateral Agreement

A U.S.-governed agreement between three parties establishing terms for custody and management of collateral assets, including rights and obligations of pledgor, secured party, and custodian.

find out more

Safe Deposit Box Rental Agreement

A U.S.-compliant contract establishing terms for renting a secure storage box from a financial institution.

find out more

Purchase Money Security Agreement

A U.S. legal document under UCC Article 9 that creates a security interest in specific purchased goods to secure their financing.

find out more

Master Loan And Security Agreement

A U.S.-governed agreement combining loan terms and security arrangements for secured lending transactions.

find out more

Loan Against Shares Agreement

A U.S.-governed agreement establishing terms for loans secured by shares as collateral, subject to federal and state securities regulations.

find out more

Cyber Security Agreement

A U.S.-governed agreement establishing terms for cybersecurity services, data protection, and incident response procedures.

find out more

Confidentiality Ip And Data Protection Agreement

A U.S.-governed agreement combining confidentiality, IP protection, and data privacy compliance obligations.

find out more

Preferred Stock Subscription Agreement

A U.S.-governed agreement documenting the purchase of preferred stock by investors, including terms, conditions, and rights of the investment.

find out more

Debenture Purchase Agreement

A U.S.-governed agreement for the issuance and purchase of corporate debentures, subject to federal and state securities laws.

find out more

Purchase Security Agreement

A U.S. legal document creating a security interest in property to secure payment or performance of an obligation, governed by UCC Article 9.

find out more

Note And Warrant Purchase Agreement

A U.S.-governed agreement establishing terms for investors to purchase convertible notes and warrants from a company.

find out more

Note And Security Agreement

A U.S. legal document combining a promissory note with a security agreement, establishing loan terms and collateral rights under UCC provisions.

find out more

Global Collateral Account Control Agreement

A U.S.-governed agreement establishing control over global collateral accounts and security interests under UCC regulations.

find out more

Factoring And Security Agreement

A U.S.-governed agreement establishing terms for the sale of accounts receivable to a factor and granting associated security interests.

find out more

Debenture Trustee Agreement

A U.S.-governed agreement appointing a trustee to act on behalf of debenture holders and setting out the terms of the relationship between issuer and trustee.

find out more

Data Protection Agreement

A legally binding agreement governing personal data processing and protection under U.S. federal and state privacy laws.

find out more

Consumer Security Agreement

A U.S. legal document that establishes a lender's security interest in a consumer borrower's property as collateral for a loan or credit.

find out more

Commercial Pledge Agreement

A U.S.-governed agreement establishing a security interest in assets as collateral for securing obligations.

find out more

Collateral Control Agreement

A U.S.-governed agreement establishing third-party control over collateral securing a loan or obligation, subject to UCC Article 9.

find out more

Preferred Equity Agreement

A U.S.-governed agreement establishing terms and conditions for preferred stock issuance, including investor rights and privileges.

find out more
See more related templates

Genie’s Security Promise

Genie is the safest place to draft. Here’s how we prioritise your privacy and security.

Your documents are private:

We do not train on your data; Genie’s AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it

2 Docs LeftAccess Now