Concerns about unethical behavior, such as stealing confidential information, should be reported through established ethical reporting mechanisms to ensure impartiality and compliance with governance policies. The CGEIT Review Manual 8th Edition advises using ethics hotlines or similar channels to handle allegations of misconduct.
Extract from CGEIT Review Manual 8th Edition (Domain 1: Governance of Enterprise IT):"Allegations of unethical behavior, including the misuse of confidential information, should be reported through the enterprise’s ethics hotline or designated reporting channel. This ensures that concerns are handled impartially, in accordance with governance policies, and with appropriate escalation to senior management or the board." (Approximate reference: Domain 1, Section on Ethical Governance)
Reporting the concern to the ethics hotline (option B) is the best course of action, as it follows governance protocols, protects the IT director from retaliation, and ensures an independent investigation.
Why not the other options?
A. File a report with the local law enforcement agency: Involving law enforcement is premature without evidence and bypasses internal governance processes.
C. Discuss the concern with the chair directly: Confronting the chair risks escalation and lacks impartiality, potentially compromising the investigation.
D. Conduct an investigation to substantiate the chair’s activities: The IT director should not conduct an investigation personally, as this could compromise objectivity and governance protocols.
[References:, ISACA CGEIT Review Manual 8th Edition, Domain 1: Governance of Enterprise IT, Section on Ethics and Compliance., ISACA CGEIT Study Guide, Chapter on Governance and Ethical Behavior., , , ]
Submit