📖 What is Due Care?
Due Care is the ongoing act of implementing the necessary security controls and practices to protect assets and maintain a reasonable standard of care. While due diligence is the research phase, due care is the actual execution and maintenance of the agreed-upon security measures.
"If due diligence is the research, due care is the action. It is about consistently doing the right thing to maintain security over time."
📚 Certification: CCSP (CCSP)
🔑 What are the Key Concepts of Due Care?
- ▸ Due care represents the operational execution of security, focusing on the actual implementation and maintenance of controls to protect organizational assets from foreseeable threats.
- ▸ It adheres to the 'reasonable person' standard, meaning the organization takes the same precautions that any prudent entity would in a similar situation.
- ▸ Unlike a one-time audit, due care is a continuous process involving regular patching, monitoring, and updating of security configurations to maintain a strong posture.
- ▸ In a legal context, a failure to exercise due care can be interpreted as negligence, potentially leading to liability if a preventable security breach occurs.
- ▸ Within the CCSP framework, due care includes the active management of the customer's portion of the Shared Responsibility Model to ensure cloud data remains secure.
🎯 How does Due Care appear on the CCSP Exam?
You may be asked to differentiate between due diligence and due care in a scenario where a company thoroughly vetted a cloud provider's security posture but subsequently failed to configure the firewall correctly.
A scenario might describe a data breach caused by a known vulnerability that was left unpatched despite available updates; you must identify this as a failure of due care rather than due diligence.
Expect questions where you must evaluate whether an organization's security actions meet the 'reasonable standard of care' by implementing industry-standard controls like MFA for administrative cloud access.
❓ Frequently Asked Questions
Can an organization be compliant with regulations but still fail to exercise due care?
Yes. Compliance is often a point-in-time snapshot, whereas due care is a continuous obligation. An organization might pass an annual audit but fail due care by ignoring critical security alerts throughout the year.
How does the Shared Responsibility Model impact the exercise of due care in cloud environments?
Due care is shared. The cloud provider exercises due care over the physical infrastructure and hypervisor, while the customer must exercise due care over their own data, identity management, and guest OS.