Due Care and Due Diligence

Due care and due diligence are two related governance concepts: due care is doing what a reasonable person would do to protect the organization, while due diligence is the ongoing effort to gather information and verify that those protections work.

Due diligence tends to come first. It is the research and continuous monitoring, such as assessing vendors, reviewing risk, and checking that policies stay current. Due care is the action taken on that knowledge, such as implementing controls and funding the security program. Running a vendor risk assessment before signing a contract is due diligence; requiring that vendor to encrypt your data is due care.

On the exam these two are frequently confused, and both connect to the prudent person rule and to legal liability. Showing due care and due diligence can reduce a company’s culpable negligence if a breach reaches court. One watch-out: due care is not a one-time project, and neglecting due diligence lets controls quietly drift out of date.

Why do due care and due diligence matter for the CISSP exam?

They sit in Domain 1, Security and Risk Management, which carries the largest exam weight at 16% and covers governance, ethics, and legal concepts. Study them alongside related terms in Domain 1 Security and Risk Management.