CISSP GLOSSARY · EXAM STRATEGY
Due diligence
The investigation and ongoing assessment that informs prudent decisions: researching risks, vetting vendors, verifying controls. The homework that precedes due care's action.
Due diligence is the knowing before the doing. It is the research, assessment, and continuous verification a prudent manager performs to understand the organisation’s risks: analysing threats, vetting a supplier before signing, reviewing whether existing controls actually work. Diligence produces the informed basis on which decisions get made; without it, action is guesswork.
Its partner is due care, and the exam almost never tests one without implying the other. The mnemonic that survives exam pressure: due diligence is the investigation, due care is the action. You perform diligence (gather facts, understand risk), then exercise care (implement reasonable safeguards). Vendor management is the textbook illustration: assessing a provider’s security posture is diligence, and building the contractual and monitoring safeguards around them is care. Both are ongoing duties, not checkboxes.
Exam relevance: separate the two by activity. Investigation, assessment, research, and verification are due diligence; implementation, maintenance, and operation of safeguards are due care. Senior management can be held personally liable for failing either duty, which is why Domain 1 questions frame them as obligations owed to the organisation.