47. A company filed a complaint with its IT service provider after the company discovered the service provider's external audit team had access to some of the company's confidential information. Which of the following is the most likely reason the company filed the complaint?
Answer: D
The company filed the complaint because a required NDA had not been signed.
The company's complaint likely centers around the lack of a signed Non-Disclosure Agreement (NDA), which would have legally protected its confidential information from unauthorized access by the service provider's external audit team.
A) The MOU had basic clauses from a template.
While an MOU (Memorandum of Understanding) might contain basic clauses, it does not specifically address confidentiality in the same manner as an NDA. Therefore, this option does not adequately explain the company’s concern regarding unauthorized access to confidential information.
B) A SOW had not been agreed to by the client.
A Statement of Work (SOW) outlines specific tasks and deliverables but does not inherently cover confidentiality issues. The absence of an agreed-upon SOW does not directly relate to the unauthorized access to the company’s confidential information, making this option less relevant to the complaint.
C) A WO had not been mutually approved.
A Work Order (WO) may define the scope of work to be performed but does not specifically address access to confidential information. Thus, the lack of mutual approval of a WO is not a sufficient reason for the company's complaint regarding the breach of confidentiality.
D) A required NDA had not been signed.
The absence of a signed Non-Disclosure Agreement is a critical factor that would allow the service provider’s external audit team to access confidential information without legal repercussions. This is the most logical reason for the company's complaint, as an NDA is specifically designed to protect sensitive information from unauthorized disclosure.
Conclusion
The complaint filed by the company is most logically tied to the absence of a signed NDA, which is essential for safeguarding confidential information. In contrast, the other options do not directly address the issue of confidentiality or unauthorized access, thereby failing to explain the company’s actions effectively.