Confidentiality

Keep audit information confidential

Define recipients, access and handling rules for all engagement information.

The commitment covers everything

All information I access, receive, share, discuss or produce during an engagement stays between me and the client’s authorized recipients. This includes discussions, documents, system details, vulnerabilities, findings and work products. I never discuss one client with another or reuse engagement information in marketing, case studies or publications.

I am the Company Owner and conduct all consulting alone, from interviews and assessment to reporting and follow-up.

Agree the rules before sharing evidence

Establish confidentiality terms, an NDA, scope and handling arrangements before access begins. Define the authorized recipients, permitted environments and communication channels. Agree what may be copied, how working material is retained and how it is returned or removed. Identify who can authorize access and resolve questions. Update the handling arrangements when the scope changes or additional systems are reviewed. Keep the authorized recipient list current throughout the engagement.

Use the access the review needs

Build the evidence plan around the agreed questions. Viewing material in the agreed environment can reduce copying. Handle credentials, personal information and operational details within the established information boundary. Record how access is provided and withdrawn. Define any activity that changes a system before it is undertaken.

Control discussions and delivery

Confirm participants, channels and note handling for meetings. Agree the audience and delivery route for each work product, including drafts. Close the engagement with the agreed access withdrawal and retention or removal actions. Confidentiality continues after delivery and follow-up.

NIST CSF and SSDF provide organizational reference points. The confidentiality commitment and recommendations here describe how I conduct my own engagements.

References

Blog

Continue reading.

Define the scope before an audit

Agree the business question, systems, evidence and expected outputs before the review starts.