Security spending goes unquestioned until something breaks. After the incident, one question decides how the organisation is judged: could a reasonable organisation have done more? Due diligence is finding out. Due care is acting on what you found. The CISSP exam tests the pair constantly because the distinction is what separates an unfortunate incident from a negligent one.

Key Insight

Due diligence is the knowing part and due care is the doing part. Monitor everything and act on nothing, and you have failed due care. Act decisively on no information, and you have failed due diligence. Neither one on its own is a defence, and the exam builds scenarios out of organisations that have exactly one of the two.

Think Like a Manager

Manager thinking means running the diligence so decisions are informed, and recording the care so decisions are provable. The risk register, the board minutes and the funding trail are the artefacts that turn a defensible decision into a demonstrable one. A control that was funded but never minuted is, from the outside, indistinguishable from one that was never considered.

Accountability is the part that does not move. Outsource the assessment, the monitoring or the whole security function, and senior leadership still answers for the outcome. The same discipline of getting the sequence right runs through scoping and tailoring, where the applicability question has to be settled before the implementation question is worth asking.

Due Diligence vs Due Care: Quick Comparison

AspectDue diligenceDue care
PurposeFind outAct on what was found
TimingContinuousAt the point of decision
Typical activityAudits, control tests, vendor assessmentPatching, enforcement, funding, formal risk acceptance
Evidence producedReports, audit logs, register entriesMinutes, funding trail, change records
Failure looks likeActing uninformedNegligence

Both columns produce evidence, and that is not incidental. In a dispute the organisation is asked to show its work, and the two categories of artefact answer two different questions: what did you know, and what did you do about it.

The Prudent Person Rule

Due care is judged by the prudent person rule: would a reasonable, prudent person in the same role, with the same information, have acted the same way? That standard is deliberately about the decision rather than the outcome, which produces the point candidates most often miss. Being breached is not negligence. An organisation that investigated properly, decided reasonably, funded the decision and documented all three has met the standard even if the breach still happened.

The reverse is also true. An organisation that never looked, or looked and did nothing, has failed the standard regardless of whether anything went wrong yet. Risk that was consciously examined and then formally accepted in writing is a due care decision, because acceptance is one of the four deliberate responses. The same risk left unexamined is not a decision at all.

How the CISSP Exam Tests Due Diligence vs Due Care

The exam describes an activity and asks you to classify it. The reliable test is what the activity produces. If it produces knowledge, it is due diligence. If it changes the state of the organisation, it is due care. Vendor questions are a favourite: assessing a supplier before signing is diligence, and the clause you then negotiate into the contract is care. Supply chain risk management scenarios usually contain both, one sentence apart.

Distinctions this fine are where near misses happen. Our CISSP practice tests put due diligence and due care in the same scenario, the way the exam does, so classifying them stops being a coin flip.