17. A company filed a complaint with its IT service provider after the company discovered the service provider's external audit team had access to some of the company's confidential information. Which of the following is the most likely reason the company filed the complaint?
Answer: D
The most likely reason the company filed the complaint is that a required NDA had not been signed.
The absence of a signed Non-Disclosure Agreement (NDA) is likely the reason for the company's complaint, as it would have legally restricted the IT service provider's external audit team from accessing confidential information.
A) The MOU had basic clauses from a template.
While a Memorandum of Understanding (MOU) with basic clauses may lack specificity, it does not directly address the issue of confidentiality or the access rights of the service provider's audit team. Therefore, this option does not adequately explain the company's concern regarding the handling of its confidential information.
B) A SOW had not been agreed to by the client.
A Statement of Work (SOW) outlines specific project deliverables and objectives but does not inherently cover the confidentiality of sensitive information. The lack of an agreed SOW would not justify the company's complaint about unauthorized access to confidential data.
C) A WO had not been mutually approved.
A Work Order (WO) typically pertains to specific tasks or services to be performed. While its approval is important for project management, it does not directly pertain to the confidentiality obligations necessary to protect sensitive information. Thus, the absence of a mutually approved WO is not a compelling reason for the complaint.
D) A required NDA had not been signed.
The lack of a signed Non-Disclosure Agreement (NDA) is significant because it directly relates to the protection of confidential information. NDAs are designed to legally bind parties to confidentiality, and without one, the company has valid grounds to complain about unauthorized access to its sensitive data.
Conclusion
The company's complaint is most reasonably attributed to the absence of a required NDA, which should have safeguarded its confidential information from unauthorized access. The other options, while relevant to project management, do not address the specific issue of confidentiality, making them inadequate explanations for the complaint. Thus, the failure to secure an NDA is the critical oversight leading to the company's actions.