Due Diligence vs Due Care: What Is the Difference?
Due diligence is finding out. Due care is acting on what you found. A CISSP insight on the prudent person rule and the evidence that proves both.
TOPIC
How to think like a manager on exam day: reading a scenario for what it is really asking, spotting the distractors, and holding the fine distinctions that decide close questions. Scoping against tailoring, due care against due diligence.
Due diligence is finding out. Due care is acting on what you found. A CISSP insight on the prudent person rule and the evidence that proves both.
The foundational certificate pinning decision: choosing between certificate fingerprints, public key hashes and chain elements. A CISSP exam insight.
Scoping makes binary yes or no calls on whether a control applies. Tailoring customises how it is implemented. A CISSP insight with a manager mindset.
Hardcoding which certificate or public key a client will accept for a service, so a fraudulent certificate from a compromised CA is rejected even though it validates normally.
Doing what a reasonable, prudent person would do to protect the organisation's interests. The ongoing act of implementing and maintaining reasonable safeguards. The do part.
The investigation and ongoing assessment that informs prudent decisions: researching risks, vetting vendors, verifying controls. The homework that precedes due care's action.
The binary decision about whether a baseline control applies to your environment at all. A control for a technology you do not run is scoped out. Applicability, not customisation.
Customising how the controls that apply to your environment are implemented: adjusting parameters, adding compensating controls, or refining assumptions to fit organisational reality.