CISSP GLOSSARY · EXAM STRATEGY
Due care
Doing what a reasonable, prudent person would do to protect the organisation's interests. The ongoing act of implementing and maintaining reasonable safeguards. The do part.
Due care is the standard of conduct the law and CISSP both hold a manager to: acting as a reasonable, prudent person would to protect the organisation’s assets and interests. In practice it is the doing, putting real safeguards in place and keeping them running: enforcing the security policy, applying patches, training staff, monitoring controls. Failing to exercise due care is negligence, and negligence is where liability attaches.
It is almost always tested against its twin, due diligence. The reliable mnemonic: due diligence is investigation, due care is action. Diligence is doing your homework, gathering the facts and understanding the risks; care is then doing something prudent about them. Diligence usually precedes care, because you investigate before you act, and both are continuous obligations rather than one-off events.
Exam relevance: match the verb. If the scenario describes implementing, maintaining, or operating a safeguard, the answer is due care. If it describes researching, assessing, or verifying before deciding, the answer is due diligence. Watch for the negligence framing too: an organisation that skipped reasonable safeguards failed its duty of due care.