nerdexam
PECB

LEAD-AUDITOR · Question #119

An auditor of organisation A performs an audit of supplier B. Which two of the following actions is likely to represent a breach of confidentiality by the auditor after having identified findings in B

The correct answer is A. Shares the findings with other relevant managers in A D. Shares the findings with B's other customers. According to the PECB Candidate Handbook1, one of the principles of auditing is confidentiality, which means that auditors should respect the confidentiality of information obtained during the audit and not disclose it to unauthorized parties. The handbook also states that audito

Audit Ethics and Conduct

Question

An auditor of organisation A performs an audit of supplier B. Which two of the following actions is likely to represent a breach of confidentiality by the auditor after having identified findings in B's information security management system?

Options

  • AShares the findings with other relevant managers in A
  • BShares the findings with B's Information Security Manager
  • CShares the findings with A's supplier evaluation team
  • DShares the findings with B's other customers
  • EShares the findings with B's certification body
  • FShares the findings with other relevant managers in B

How the community answered

(69 responses)
  • A
    80% (55)
  • B
    12% (8)
  • C
    1% (1)
  • E
    4% (3)
  • F
    3% (2)

Explanation

According to the PECB Candidate Handbook1, one of the principles of auditing is confidentiality, which means that auditors should respect the confidentiality of information obtained during the audit and not disclose it to unauthorized parties. The handbook also states that auditors should only report audit results to those who have a legitimate need to know, such as the client, the auditee, and the certification body. Therefore, sharing the findings with other relevant managers in A or B's other customers would be a breach of confidentiality, as they are not directly involved in the audit process or the information security management system of B. Sharing the findings with B's Information Security Manager or other relevant managers in B would be appropriate, as they are part of the auditee organization and responsible for the implementation and improvement of the ISMS. Sharing the findings with A's supplier evaluation team or B's certification body would also be acceptable, as they have a legitimate need to know the audit results for the purpose of supplier selection or certification, respectively.

Topics

#auditor confidentiality#audit ethics#supplier audit#findings disclosure

Community Discussion

No community discussion yet for this question.

Full LEAD-AUDITOR Practice