⚖️ CISSP Study Note: Due Care
⚖️ CISSP Study Note: Due Care
๐ Definition
Due Care is a legal concept that refers to the responsibility and duty of an organization or individual to act prudently to avoid harm to others. In cybersecurity, it means taking reasonable and expected actions to protect assets, systems, and data—especially those that belong to or impact customers, users, or partners.
๐ง Why It Matters in Cybersecurity
Due Care is a cornerstone of security accountability. It’s the “what would a reasonable person do” test in the context of protecting information. Failing to demonstrate due care can result in legal liability, regulatory penalties, and reputational loss—especially if a breach occurs and preventable negligence is found.
⚖️ Due Care vs. Due Diligence
| Term | Meaning |
|---|---|
| Due Diligence | The investigation or assessment done before taking an action. (Think: planning) |
| Due Care | The actions taken to ensure safety and compliance. (Think: execution) |
Example: Before implementing a new firewall, you research options (due diligence), then configure it securely and maintain it (due care).
๐ ️ What Demonstrates Due Care?
| Activity | Example |
|---|---|
| Enforcing access controls | Using MFA, RBAC, and least privilege models. |
| Employee training | Conducting regular security awareness sessions. |
| Incident response planning | Having documented and tested response procedures. |
| Data encryption | Encrypting data at rest and in transit. |
| Policy enforcement | Ensuring security policies are not just written but actually followed. |
✅ Example (CISSP-Style)
A payment processor is breached. Investigators find the firm never patched a critical known vulnerability for over 9 months.
The firm had no formal patch management process, even though industry standards required it.
✅ This is a failure to exercise due care, and the firm could be held legally liable.
๐ Legal Relevance
-
Due care is often evaluated in civil lawsuits and regulatory investigations.
-
Used to determine negligence: Was harm caused by a failure to act reasonably?
-
Important in contractual obligations (e.g., SLAs, vendor management, compliance programs).
๐ Found In CISSP Domains
| Domain | Focus |
|---|---|
| ๐ Domain 1: Security and Risk Management | Emphasizes legal, regulatory, and ethical responsibilities—including due care and due diligence. |
| ๐ Domain 6: Security Assessment and Testing | Audits and assessments help demonstrate due care is being exercised. |
๐ Memory Hook
“Due care = Do care.”
It’s not enough to plan what’s right—you must also act on it.
Comments
Post a Comment