top of page

Due Care vs Due Diligence for CISSP

The Ultimate CISSP Study Guide, Exam Cheat Sheet & Practical Security Leadership Guide


Domain: CISSP Domain 1 – Security & Risk Management (16%)

Difficulty: ⭐⭐⭐⭐⭐ (High)

CISSP Exam Importance: Very High


Why This Topic Matters

One of the most frequently misunderstood concepts in the CISSP exam is the distinction between Due Care and Due Diligence. Although they are closely related, they represent two different managerial responsibilities.


Understanding the difference is essential because CISSP questions often ask:

  • Which action demonstrates due care?

  • Which activity represents due diligence?

  • Which should occur first?

  • What is management's legal responsibility?

  • Which best reduces organizational liability?

This guide explains both concepts using executive-level examples, real-world scenarios, exam tips, and decision frameworks.


Quick Definition

Due Care

Doing the right thing to protect assets.

Due Care refers to implementing appropriate security controls to reduce identified risks.

It answers:

"What security measures are we putting in place?"

Examples:

  • Installing firewalls

  • Enforcing MFA

  • Encrypting sensitive data

  • Conducting employee awareness training

  • Applying security patches

  • Backing up critical systems


Due Diligence

Making sure the right thing continues to happen.

Due Diligence is the ongoing process of identifying risks, evaluating controls, monitoring effectiveness, and continuously improving security.

It answers:

"How do we know our security controls remain effective?"

Examples:

  • Risk assessments

  • Vulnerability assessments

  • Security audits

  • Penetration testing

  • Compliance reviews

  • Continuous monitoring

  • Vendor assessments


The Simplest Way to Remember

Due Care

DO

You perform security controls.


Due Diligence

CHECK

You verify those controls remain effective.


One-Sentence Difference

Due Care implements security.

Due Diligence verifies, monitors, and improves security.


Real-World Analogy

Imagine owning a hotel.

Due Care

  • Install smoke detectors.

  • Install fire extinguishers.

  • Create evacuation plans.

  • Train staff.


Due Diligence

  • Inspect smoke detectors monthly.

  • Test alarms.

  • Conduct fire drills.

  • Replace expired extinguishers.

  • Review emergency procedures.

Installing protection is Due Care.

Ensuring protection still works is Due Diligence.


Executive Perspective

Executives are expected to:


Exercise Due Care

Implement reasonable safeguards.

Examples:

  • Security policies

  • Access control

  • Incident response

  • Data encryption

  • Employee training


Exercise Due Diligence

Continuously verify safeguards.

Examples:

  • Internal audits

  • Compliance reviews

  • Risk management

  • KPI monitoring

  • Vulnerability management

  • Security metrics


Relationship Between the Two

Risk Identified
        ↓
Risk Assessment
        ↓
Choose Controls
        ↓
Implement Controls
      (Due Care)
        ↓
Monitor Controls
        ↓
Audit Controls
        ↓
Improve Controls
   (Due Diligence)
        ↓
Continuous Improvement

Easy Memory Trick

Care

Care means:

"I protected it."


Diligence

Diligence means:

"I proved I kept protecting it."


CISSP Manager's Mindset

A CISSP professional asks:

Have we implemented reasonable safeguards?

↓

Yes

↓

Are they still working?

↓

How do we know?

↓

Can we prove it?

That final question represents Due Diligence.


Due Care Examples

✔ Install antivirus

✔ Configure MFA

✔ Encrypt databases

✔ Lock server rooms

✔ Create security policies

✔ Classify information

✔ Train employees

✔ Implement backups

✔ Configure IDS/IPS

✔ Deploy SIEM


Due Diligence Examples

✔ Annual audits

✔ Quarterly vulnerability scans

✔ Penetration tests

✔ Policy reviews

✔ Risk assessments

✔ Continuous monitoring

✔ Compliance validation

✔ Vendor assessments

✔ Patch verification

✔ Incident trend analysis


Comparison Table

Due Care

Due Diligence

Action

Verification

Implement

Evaluate

Protect

Monitor

Build controls

Assess controls

Prevent

Improve

Operational

Continuous management

"Do"

"Verify"


Which Comes First?

Due Diligence identifies the need for security controls through activities such as risk assessments and evaluations. Due Care then implements those controls. After implementation, Due Diligence continues by monitoring, auditing, and improving them.

Identify Risk
(Due Diligence)

↓

Implement Controls
(Due Care)

↓

Monitor & Improve
(Due Diligence)

Exam Tip: Due Diligence is both the starting point (understanding risk) and the ongoing process (ensuring controls remain effective).


Legal Perspective

Courts often evaluate whether an organization exercised:

Reasonable Due Care

AND

Reasonable Due Diligence.

Failure to demonstrate either may increase legal liability after a breach.


Regulatory Perspective

Most frameworks require both concepts.

Examples include:

  • ISO 27001

  • NIST CSF

  • PCI DSS

  • HIPAA

  • SOC 2

  • COBIT

Organizations must not only implement controls but also demonstrate that they review, monitor, and improve them.


Due Care in the NIST Cybersecurity Framework

Examples:

  • Protect function

  • Access control

  • Data security

  • Awareness training

  • Protective technologies


Due Diligence in the NIST Cybersecurity Framework

Examples:

  • Identify function

  • Risk assessment

  • Continuous monitoring

  • Detect function

  • Governance reviews

  • Improvement activities


Due Care Throughout the SSDLC

Examples:

  • Secure coding

  • Authentication

  • Encryption

  • Input validation

  • Logging


Due Diligence Throughout the SSDLC

Examples:

  • Code reviews

  • SAST

  • DAST

  • Penetration testing

  • Security audits


Third-Party Risk Management

Due Care

  • Require security controls in contracts.

  • Define security expectations.


Due Diligence

  • Assess vendor security.

  • Review SOC reports.

  • Conduct supplier audits.

  • Monitor compliance.

  • Reassess vendors periodically.


Cloud Security

Due Care

  • Enable MFA

  • Encrypt storage

  • Configure IAM

  • Enable logging


Due Diligence

  • Review cloud configurations

  • Perform CSPM assessments

  • Audit permissions

  • Monitor cloud activity

  • Validate compliance


Incident Response

Due Care

  • Develop an incident response plan.

  • Train responders.

  • Establish communication procedures.


Due Diligence

  • Conduct tabletop exercises.

  • Review incident metrics.

  • Perform post-incident analysis.

  • Update procedures based on lessons learned.


Executive Dashboard Metrics (Due Diligence)

Management should regularly review:

  • Mean Time to Detect (MTTD)

  • Mean Time to Respond (MTTR)

  • Patch compliance

  • Critical vulnerabilities

  • Security awareness completion

  • Audit findings

  • Third-party risk scores

  • Incident trends

  • Risk register updates

  • Control effectiveness


Common CISSP Exam Traps

Trap 1

Installing a firewall demonstrates Due Diligence.

Incorrect.

Installing the firewall is Due Care.

Reviewing firewall rules and effectiveness is Due Diligence.


Trap 2

Due Care and Due Diligence are interchangeable.

Incorrect.

Due Care = Implement.

Due Diligence = Verify and improve.


Trap 3

Security ends after controls are implemented.

Incorrect.

Continuous monitoring is essential.


Trap 4

Annual audits alone demonstrate Due Diligence.

Incorrect.

Due Diligence is an ongoing process, not a once-a-year activity.


Trap 5

Buying security products proves Due Care.

Partially Incorrect.

Buying products is not enough. They must be properly implemented, configured, maintained, and used.


Manager's Decision Framework

A ransomware attack occurs.

Management asks:

Have we implemented reasonable safeguards?

↓

Yes

↓

How do we know they worked?

↓

Were they monitored?

↓

Were vulnerabilities identified earlier?

↓

Were patches applied?

↓

Were audits conducted?

↓

Were lessons learned incorporated?

These questions evaluate Due Diligence.


Decision Tree

Security Risk
      ↓
Risk Assessment
(Due Diligence)

↓

Choose Controls

↓

Implement Controls
(Due Care)

↓

Monitor

↓

Audit

↓

Improve
(Due Diligence)

↓

Repeat

CISSP Memory Sheet

Due Care

  • Implement

  • Protect

  • Prevent

  • Safeguard

  • Act


Due Diligence

  • Assess

  • Monitor

  • Audit

  • Verify

  • Improve

  • Document


Five CISSP Practice Questions

Question 1

An organization installs multi-factor authentication (MFA) for all remote users.

Which concept does this BEST demonstrate?

A. Due Diligence

B. Due Care

C. Risk Acceptance

D. Compliance Monitoring

Answer: B. Due Care

Explanation: Implementing MFA is a security control that protects organizational assets. This is Due Care.


Question 2

Following the deployment of MFA, the security team performs quarterly reviews of authentication logs to verify that MFA is functioning correctly and to identify anomalous login attempts.

Which concept is illustrated?

A. Due Care

B. Separation of Duties

C. Due Diligence

D. Defense in Depth

Answer: C. Due Diligence

Explanation: Monitoring and verifying the effectiveness of implemented controls is Due Diligence.


Question 3

A company performs annual penetration tests and quarterly vulnerability assessments to ensure its security controls remain effective.

What is the PRIMARY objective?

A. Implement new security controls

B. Demonstrate Due Diligence

C. Increase system availability

D. Eliminate all security risks

Answer: B. Due Diligence


Question 4

A cloud provider recommends enabling encryption for data stored in object storage. The organization configures encryption for all sensitive data.

Which concept is BEST represented?

A. Due Care

B. Due Diligence

C. Compliance Auditing

D. Risk Transfer

Answer: A. Due Care


Question 5

Senior management reviews audit reports, compliance findings, incident trends, and risk metrics each quarter to ensure security controls continue to meet organizational objectives.

What does this BEST demonstrate?

A. Due Care

B. Due Diligence

C. Separation of Duties

D. Business Continuity

Answer: B. Due Diligence


Key Takeaways

  • Due Care is the implementation of reasonable security safeguards to protect organizational assets.

  • Due Diligence is the continuous process of assessing, monitoring, auditing, documenting, and improving those safeguards to ensure they remain effective.

  • Both concepts are management responsibilities and are essential for legal defensibility, regulatory compliance, and effective cybersecurity governance.

  • The CISSP exam frequently tests the distinction between implementing a control (Due Care) and verifying its effectiveness over time (Due Diligence).

  • Think like a CISSP leader: implement appropriate controls, continuously validate their effectiveness, document decisions, and drive ongoing improvement to reduce organizational risk.


Related Topics

This article should link to your existing and planned Domain 1 content, including:



Continue Your CISSP Journey with GoCyberNinja

Understanding Due Care and Due Diligence is essential for developing the management mindset required to succeed on the CISSP exam. These concepts appear throughout risk management, governance, compliance, vendor management, incident response, and security operations.


GoCyberNinja CISSP Exam Prep helps you master these principles through realistic, scenario-based learning that reflects how the CISSP exam challenges candidates to think like security leaders.


Strengthen Your CISSP Preparation

  • ✅ 2,800+ Realistic CISSP Practice Questions across all eight domains

  • ✅ 1,200 Full-Length Mock Exam Questions in eight comprehensive exams

  • ✅ 400+ Scenario-Based Questions focused on executive decision-making

  • ✅ 1,040+ Interactive Flashcards for rapid review and retention

  • ✅ Adaptive Smart Review targeting your weakest topics

  • ✅ Performance Analytics to measure readiness and guide improvement

  • ✅ Personalized Study Plans tailored to your progress

  • ✅ Three Free CISSP Readiness Tests to benchmark your preparation before exam day


Practice smarter. Analyze deeper. Think like a CISSP professional.

bottom of page