CISSP GLOSSARY · EXAM STRATEGY

Due diligence

The investigation and ongoing assessment that informs prudent decisions: researching risks, vetting vendors, verifying controls. The homework that precedes due care's action.

Due diligence is the knowing before the doing. It is the research, assessment, and continuous verification a prudent manager performs to understand the organisation’s risks: analysing threats, vetting a supplier before signing, reviewing whether existing controls actually work. Diligence produces the informed basis on which decisions get made; without it, action is guesswork.

Its partner is due care, and the exam almost never tests one without implying the other. The mnemonic that survives exam pressure: due diligence is the investigation, due care is the action. You perform diligence (gather facts, understand risk), then exercise care (implement reasonable safeguards). Vendor management is the textbook illustration: assessing a provider’s security posture is diligence, and building the contractual and monitoring safeguards around them is care. Both are ongoing duties, not checkboxes.

Exam relevance: separate the two by activity. Investigation, assessment, research, and verification are due diligence; implementation, maintenance, and operation of safeguards are due care. Senior management can be held personally liable for failing either duty, which is why Domain 1 questions frame them as obligations owed to the organisation.