📖 What is Due Care?
Due Care is the legal concept of taking the reasonable steps that a prudent person would take under similar circumstances to avoid harm to others. In cybersecurity, it refers to the actual implementation of security controls.
"Think of Due Care as the 'doing' phase—it is the action of implementing the protections you have planned for the organization."
📚 Certification: Certified in Cybersecurity (CC)
🔑 What are the Key Concepts of Due Care?
- ▸ Focuses on the active implementation of security controls, such as deploying firewalls or patching software, to protect organizational assets from known threats.
- ▸ Relies on the 'prudent person' standard, meaning the organization must act as any reasonable entity would under similar circumstances to prevent harm.
- ▸ Serves as a critical legal defense by demonstrating that the organization took practical, reasonable steps to safeguard data and maintain a secure environment.
- ▸ Represents the execution phase of security, transforming the knowledge gained during due diligence into tangible protections and operational security practices.
- ▸ Requires ongoing maintenance and monitoring of controls to ensure they remain effective as the threat landscape and organizational needs evolve over time.
🎯 How does Due Care appear on the CC Exam?
You may be asked to identify a failure in due care in a scenario where a company failed to apply a critical security patch for a known vulnerability, leading to a data breach.
A scenario might describe a manager performing a risk assessment (due diligence) and then configuring the suggested access controls; you will need to identify the configuration step as due care.
Expect questions that ask you to determine if a specific action, such as implementing multi-factor authentication for all administrative accounts, fulfills the 'reasonable person' standard for protecting sensitive customer data.
❓ Frequently Asked Questions
How do I distinguish Due Care from Due Diligence on the CC exam?
Think of Due Diligence as the 'thinking' or 'research' phase, such as conducting a risk assessment. Due Care is the 'doing' phase, where you actually implement the security controls identified during that research process.
Is Due Care a one-time checklist that can be completed?
No, due care is a continuous obligation. Because threats evolve, a control that was reasonable last year may be insufficient today, requiring the organization to update its actions to remain prudent.