OBJ 1.1: The Statement of Work (also called a Scope of Work) is a formal document stating what activities will and will not be performed during a penetration test. The SOW is a document that defines the expectations for a specific business arrangement, including the assessment's size and scope, a list of the assessment's objectives, and a list of deliverables for the assessment. A master service agreement, or MSA, is a contract reached between parties, in which the parties agree to most of the terms that will govern future transactions or future agreements. The MSA is used when a pentester will be on retainer for a multi-year contract, and an individual SOW will be issued for each assessment to define the individual scopes for each one. A non-disclosure agreement (NDA) is a legal contract between at least two parties that outlines confidential material, knowledge, or information that the parties wish to share for certain purposes but wish to restrict access. A service level agreement (SLA) is a contract that outlines the detailed terms under which a service is provided, including reasons the contract may be terminated. OBJ. 1.1