๐งช CISSP Study Note: Due Diligence
๐งช CISSP Study Note: Due Diligence
๐ Definition
Due Diligence refers to the actions, research, and evaluation conducted before engaging in a business activity, transaction, or deployment to ensure risks are understood and mitigated. In cybersecurity, it often reflects the efforts a vendor or organization takes to assess security posture and compliance—especially to fulfill or support Due Care.
๐ง Why It Matters in Cybersecurity
Due Diligence is how organizations demonstrate they’re not acting blindly or negligently. It precedes action and involves thoughtful consideration of security, legal, operational, and reputational risks.
Without it, vendors, partners, and internal stakeholders may make uninformed or harmful decisions—leading to breach, liability, or non-compliance.
๐ ️ Due Diligence vs. Due Care
| Term | When It Happens | Focus |
|---|---|---|
| Due Diligence | Before taking an action | Investigation, risk analysis, preparation |
| Due Care | After or during an action | Ongoing execution, maintenance, enforcement |
Think: Due Diligence is preparing for the trip. Due Care is driving safely once you start.
๐งพ Examples of Due Diligence Activities
| Activity | Description |
|---|---|
| Vendor Risk Assessment | Reviewing a vendor’s security policies, breach history, certifications (e.g., SOC 2). |
| Background Checks | Pre-hire screenings for personnel in sensitive roles. |
| Penetration Testing | Assessing security of a system before deployment. |
| Privacy Impact Assessment (PIA) | Evaluating risk to personal data before new tech or processes are adopted. |
| Compliance Checks | Ensuring alignment with laws (e.g., GDPR, HIPAA) before storing or sharing PII. |
✅ Example (CISSP-Style)
Before onboarding a third-party payment processor, a company reviews the vendor’s SOC 2 Type II report, confirms encryption practices, and ensures GDPR compliance for EU clients.
✅ These actions show due diligence, helping the company choose a trusted partner and avoid liability.
๐ Common Contexts for Due Diligence
-
Mergers and acquisitions (Evaluate cyber risk and liabilities)
-
Third-party vendor onboarding
-
Cloud migration
-
Launching new applications
-
Processing customer data
๐ Found In CISSP Domains
| Domain | Focus |
|---|---|
| ๐ Domain 1: Security and Risk Management | Covers legal responsibilities, supply chain security, and the relationship between due diligence and due care. |
| ๐ Domain 6: Security Assessment and Testing | Emphasizes the importance of testing systems before and after launch. |
๐ Memory Hook
“Due diligence is the homework. Due care is the follow-through.”
You can’t act responsibly (due care) if you didn’t first do your homework (due diligence).
Comments
Post a Comment