A company filed a complaint with its IT service provider after the company discovered the service provider's external audit team had access to some of the company's confidential information. Which of the following is the most likely reason the company filed the complaint?
A required NDA had not been signed.
The company's complaint likely stems from the lack of a Non-Disclosure Agreement (NDA), which is crucial for protecting confidential information from unauthorized access or disclosure. Without an NDA in place, the service provider's external audit team may have accessed sensitive information without proper legal safeguards, leading to the company's concerns.
While a Memorandum of Understanding (MOU) with basic clauses might indicate a lack of thoroughness in the agreement, it does not directly address the issue of confidentiality. An MOU typically outlines the intentions and general agreements between parties but does not specifically govern the handling of confidential information like an NDA would.
The Statement of Work (SOW) outlines specific deliverables and services to be provided but does not inherently protect confidential information. The absence of an agreed SOW might lead to confusion about services rendered, but it does not directly relate to the unauthorized access of confidential data by the audit team.
A Work Order (WO) describes specific tasks or jobs to be completed, but like an SOW, it does not serve to safeguard confidential information. Lack of mutual approval on a WO may affect project execution but does not have a direct bearing on the confidentiality of sensitive data shared with the service provider.
The filing of a complaint by the company is most likely due to the absence of a signed NDA, which is essential for ensuring that confidential information is protected from unauthorized access. While other agreements like MOUs, SOWs, and WOs are important for defining project scope and expectations, they do not specifically address the confidentiality concerns raised by the company's situation with the IT service provider.
Related Questions
View allWhen used with an access control vestibule, which of the following wou...
A network security analyst monitors the network's IDS, which has flagg...
Which of the following risk management strategies describes applying a...
Which of the following activities identifies but does not exploit vuln...
Which of the following is a use of CVSS?
Related Quizzes
View allCompTIA A Plus Certification Exam
CompTIA A Plus Exam Questions
CompTIA A Plus 1001 Exams Practice
CompTIA A Plus Practice Exam
CompTIA CySA+ Cybersecurity Analyst Certification all in One Exam Guide
CompTIA Network Plus Certification Exam Quiz
CompTIA Security Plus Exam Answers
Free CompTIA Security Plus Practice Test
CompTIA Security Plus Simulation Questions
CompTIA Security Plus 501 Practice Questions
- ✓ 500+ Practice Questions
- ✓ Detailed Explanations
- ✓ Progress Analytics
- ✓ Exam Simulations