๐Ÿงช CISSP Study Note: Due Diligence

๐Ÿงช CISSP Study Note: Due Diligence


๐Ÿ” Definition

Due Diligence refers to the actions, research, and evaluation conducted before engaging in a business activity, transaction, or deployment to ensure risks are understood and mitigated. In cybersecurity, it often reflects the efforts a vendor or organization takes to assess security posture and compliance—especially to fulfill or support Due Care.


๐Ÿง  Why It Matters in Cybersecurity

Due Diligence is how organizations demonstrate they’re not acting blindly or negligently. It precedes action and involves thoughtful consideration of security, legal, operational, and reputational risks.
Without it, vendors, partners, and internal stakeholders may make uninformed or harmful decisions—leading to breach, liability, or non-compliance.


๐Ÿ› ️ Due Diligence vs. Due Care

Term When It Happens Focus
Due Diligence Before taking an action Investigation, risk analysis, preparation
Due Care After or during an action Ongoing execution, maintenance, enforcement

Think: Due Diligence is preparing for the trip. Due Care is driving safely once you start.


๐Ÿงพ Examples of Due Diligence Activities

Activity Description
Vendor Risk Assessment Reviewing a vendor’s security policies, breach history, certifications (e.g., SOC 2).
Background Checks Pre-hire screenings for personnel in sensitive roles.
Penetration Testing Assessing security of a system before deployment.
Privacy Impact Assessment (PIA) Evaluating risk to personal data before new tech or processes are adopted.
Compliance Checks Ensuring alignment with laws (e.g., GDPR, HIPAA) before storing or sharing PII.

✅ Example (CISSP-Style)

Before onboarding a third-party payment processor, a company reviews the vendor’s SOC 2 Type II report, confirms encryption practices, and ensures GDPR compliance for EU clients.
✅ These actions show due diligence, helping the company choose a trusted partner and avoid liability.


๐Ÿ“Œ Common Contexts for Due Diligence

  • Mergers and acquisitions (Evaluate cyber risk and liabilities)

  • Third-party vendor onboarding

  • Cloud migration

  • Launching new applications

  • Processing customer data


๐Ÿ“– Found In CISSP Domains

Domain Focus
๐Ÿ“˜ Domain 1: Security and Risk Management Covers legal responsibilities, supply chain security, and the relationship between due diligence and due care.
๐Ÿ“˜ Domain 6: Security Assessment and Testing Emphasizes the importance of testing systems before and after launch.

๐Ÿ”‘ Memory Hook

“Due diligence is the homework. Due care is the follow-through.”
You can’t act responsibly (due care) if you didn’t first do your homework (due diligence).


Comments

Popular posts from this blog

๐Ÿงญ CISSP Study Note: Guidelines

๐Ÿ’ธ CISSP Study Note: Risk Transference

๐Ÿ“ CISSP Study Note: Standards