One of the concepts that repeatedly tripped me up while studying for the Certified Information Systems Security Professional exam was the difference between due care and due diligence.
At first, the distinction seemed simple. One term involved deciding what an organization should do, while the other involved actually doing it. Then I would read another practice question, both answers would sound reasonable, and suddenly the distinction disappeared.
It reminded me of the famous Spider-Man meme where two nearly identical characters point at each other.
Due care.
Due diligence.
Which one is which again?
The frustrating part was that I could explain both concepts in a conversation and still second-guess myself during a test. Because the terms are closely related—and are sometimes used differently outside certification materials—it is easy to understand why they become tangled together.
The CISSP exam outline includes due care and due diligence within its coverage of legal, regulatory, and compliance issues. ISC2’s student glossary describes due care as a legal concept involving a duty owed and due diligence as the actions taken to demonstrate or provide that care.
That wording finally gave me a better way to separate them.
Why I Kept Getting Them Wrong
Since root-cause analysis is part of how I naturally approach problems, I decided to examine why I could understand the concepts one moment and lose them the next.
The answer was not that the definitions were beyond my comprehension. I was overthinking the questions.
When I take an exam, I sometimes assume every question is trying to trick me. The most obvious answer begins to feel suspicious simply because it appears obvious. I start looking for hidden meanings, unusual exceptions, or one word that might change the entire question.
That habit goes back to school, where multiple-choice questions often included two clearly incorrect answers and two answers that appeared almost identical. I would eliminate the obvious ones, debate the remaining choices, select the answer that seemed most reasonable, and move on.
Then came the real mistake.
After finishing the test, I would review my answers and convince myself to change several of them. More often than I would like to admit, my original answer had been correct.
Due care and due diligence triggered that same pattern. The terms are related closely enough that once I began overanalyzing them, I could make either answer sound correct.
I needed something more reliable than memorizing two similar definitions.
What Is Due Care?
For CISSP study purposes, I think of due care as the responsibility to act with reasonable care.
It represents the standard an organization or individual is expected to meet under the circumstances. In a legal context, due care is generally associated with the level of care that a reasonable person would exercise in a similar situation.
In cybersecurity, due care means recognizing that the organization has a responsibility to protect its systems, information, employees, customers, and other stakeholders through reasonable safeguards.
Examples may include:
- Protecting sensitive information from unauthorized disclosure
- Restricting access to critical systems
- Maintaining a process for reporting security incidents
- Establishing security policies and responsibilities
- Addressing known vulnerabilities within a reasonable period
- Preparing the organization to respond to foreseeable incidents
The exact controls considered reasonable will depend on the organization’s size, industry, resources, legal obligations, information, and risk environment.
A small business and a multinational financial institution may not implement identical programs. However, both may still be expected to take reasonable steps appropriate to the risks they face.
My memory aid is:
Due Care = the Care we are responsible for providing.
The shared C helps me remember that due care is connected to care, responsibility, and the standard the organization is expected to meet.
What Is Due Diligence?
Due diligence is the ongoing work used to understand risk, make informed decisions, and demonstrate that the organization is meeting its responsibilities.
It includes investigation, verification, review, monitoring, testing, documentation, and follow-up.
NIST uses due diligence in its cybersecurity supply-chain guidance to describe an investigative process for researching and verifying available information before making risk-based decisions about suppliers. That is a specific supply-chain use of the term, but the underlying idea is helpful: due diligence requires active investigation rather than assumption.
Cybersecurity examples may include:
- Conducting risk assessments
- Reviewing applicable laws and contractual requirements
- Evaluating vendors before granting them access
- Testing whether security controls work as intended
- Reviewing privileged accounts
- Monitoring security events
- Tracking remediation efforts
- Auditing compliance with established policies
- Reassessing risks when systems or business operations change
- Documenting decisions and accepted risks
My memory aid is:
Due Diligence = Digging into the details.
Due diligence is not merely writing a policy or completing paperwork before a project begins. It is the continuing process of investigating, verifying, monitoring, and documenting whether the organization is managing risk appropriately.
A Simple Example
Imagine that an organization stores sensitive customer information.
Its due-care responsibility is to protect that information using safeguards that are reasonable for the circumstances.
Its due-diligence activities may include:
- Identifying what sensitive information it holds
- Determining which laws, contracts, and policies apply
- Assessing the threats and potential business impact
- Selecting appropriate safeguards
- Testing whether those safeguards work
- Monitoring for failures or suspicious activity
- Correcting weaknesses as they are discovered
- Documenting decisions and reassessing the environment
The organization may then implement encryption, multi-factor authentication, access restrictions, monitoring, employee training, and incident-response procedures.
Those controls help it provide due care. The assessments, testing, monitoring, documentation, and follow-up help demonstrate due diligence.
The two ideas support each other. They should not be treated as entirely separate steps where one permanently ends before the other begins.
Revisiting My Running Analogy
In my original attempt to remember the terms, I compared them to preparing for a run.
That analogy still works, but it needs a small adjustment.
Due care is the responsibility to take reasonable precautions for a safe run. That could mean avoiding a dangerous route, staying hydrated, wearing appropriate shoes, and responding to hazardous weather.
Due diligence is the process of checking the weather, examining the route, considering your physical condition, bringing water, and continuing to pay attention as conditions change.
Stretching, drinking water, and remaining on a safe path are actions, but that does not automatically make them due care rather than due diligence. The better distinction is between the standard of reasonable care and the work used to understand, implement, and verify that standard.
That distinction is less catchy than saying one term is planning and the other is action, but it is more accurate.
My Updated T-Chart
| Due Care | Due Diligence |
|---|---|
| The responsibility to act reasonably | The work performed to meet and demonstrate that responsibility |
| Focuses on the expected standard of care | Focuses on investigation, verification, and follow-through |
| Asks: “What reasonable care do we owe?” | Asks: “How do we know we are providing it?” |
| Connected to responsibility and protection | Connected to assessment, monitoring, testing, and documentation |
| Memory aid: Care = responsibility | Memory aid: Diligence = dig into the details |
The shortest version I now use is:
Due care is the responsibility. Due diligence is the work that proves you are taking that responsibility seriously.
Why These Terms Matter Beyond the CISSP Exam
Due care and due diligence are not merely vocabulary terms created to make certification exams more difficult.
They matter because organizations are expected to manage foreseeable risks reasonably. Security incidents cannot always be prevented, but organizations may still be asked what they knew, what they did, whether their decisions were reasonable, and whether they followed through on identified concerns.
That does not mean an organization is automatically negligent whenever a breach occurs.
Negligence is more complicated than simply failing to stop a bad outcome. In general, negligence involves failing to exercise the level of care that a reasonable person would have exercised under similar circumstances. A negligence claim commonly examines whether a duty existed, whether that duty was breached, whether the breach caused harm, and whether damages resulted. The exact legal test and outcome depend on the jurisdiction and facts involved.
It is also important to distinguish ordinary negligence from intentional misconduct or recklessness. Negligence does not necessarily require someone to knowingly ignore a danger, act for personal gain, or deliberately choose the wrong course. Conduct described as willful, wanton, or reckless may fall into the separate category of gross negligence, depending on the applicable law.
From a cybersecurity perspective, investigations may consider questions such as:
- Did leadership understand the organization’s material risks?
- Were known vulnerabilities evaluated and addressed?
- Were reasonable safeguards implemented?
- Did the organization test and monitor those safeguards?
- Were warnings from employees, auditors, or security professionals ignored?
- Were risk decisions documented and approved?
- Did the organization update its controls as conditions changed?
- Was the incident response plan followed?
Good documentation alone will not compensate for ineffective controls. At the same time, technically strong controls can become difficult to defend if no one can explain why they were selected, whether they were tested, or who was responsible for maintaining them.
Due care and due diligence work together. One concerns the responsibility to act reasonably; the other demonstrates the sustained effort used to fulfill that responsibility.
Final Thoughts
I originally tried to remember the difference by assigning administrative work to due diligence and action to due care.
That shortcut helped temporarily, but it was too rigid. Policies can be part of due care, and actions can be part of due diligence. The distinction is not simply paperwork versus implementation.
The better way for me to remember it is:
Due care is the responsibility to protect. Due diligence is the process of investigating, implementing, checking, and documenting how that responsibility is being met.
Once I stopped treating the terms as competitors and started treating them as partners, the distinction became much clearer.
Due care establishes what reasonable protection requires.
Due diligence helps prove that the organization did more than say the right things—it made a sustained, informed effort to follow through.
Disclaimer
I am not an attorney, and this article is not legal advice. The legal meaning and application of due care, due diligence, negligence, and related standards can vary by jurisdiction and circumstance. Organizations facing specific legal or regulatory questions should consult qualified legal counsel.






