📖 What is Due Diligence?

Due Diligence is the act of investigating and researching a situation to ensure that all necessary precautions are taken before entering into an agreement. It involves the verification, auditing, and continuous monitoring of security controls.

🥋 Sensei Says:

"Distinguish this from Due Care; Due Diligence is the 'research and verification' phase, while Due Care is the 'execution and implementation' phase."

📚 Certification: Certified in Cybersecurity (CC)

🔑 What are the Key Concepts of Due Diligence?

  • Conducting background checks and security audits on third-party vendors before signing contracts to ensure they meet the organization's minimum security standards.
  • Performing continuous monitoring and periodic reviews of security logs and audit reports to verify that controls remain effective over time.
  • Analyzing potential threats and vulnerabilities associated with a new project or partnership to make informed, risk-based decisions before proceeding.
  • Gathering evidence, such as SOC 2 reports or industry certifications, to prove that a security control is present and operating correctly.
  • Ensuring compliance with legal and regulatory requirements by documenting the research and verification steps taken to mitigate known risks.

🎯 How does Due Diligence appear on the CC Exam?

You may be asked to identify the correct term when a company reviews a vendor's security policies and audit reports before signing a service level agreement to ensure risk is managed.

A scenario might describe a manager conducting a risk assessment and reviewing existing security documentation to decide if a new software tool is safe to deploy in the environment.

Expect questions that require you to distinguish between the act of researching a security requirement (Due Diligence) and the act of actually implementing that control (Due Care).

❓ Frequently Asked Questions

How can I easily tell the difference between Due Diligence and Due Care on the exam?

Think of Due Diligence as the 'homework' or research phase, which involves verifying and auditing. Due Care is the 'action' phase, involving the actual implementation and enforcement of those security controls.


Is Due Diligence a one-time event during the procurement process?

No. While critical during initial vendor selection, it must be an ongoing process. Periodic audits and continuous monitoring are required to ensure that the vendor's security posture does not degrade over time.


What are the legal implications of failing to perform Due Diligence?

Failure to perform Due Diligence can be viewed as negligence. If a breach occurs and the organization cannot prove they researched the risk, they may face severe legal penalties and liabilities.

Related Terms from Certified in Cybersecurity

📝 Related Study Guides

Study Guide 8 min read

ISC2 CC Certification Guide: Your Free Entry into Cyber

The ISC2 Certified in Cybersecurity (CC) is a free, entry-level certification designed for beginners. It covers five core domains—Security Principles, BCP/DR, Access Control, Network Security, and Security Operations—via a 100-question exam. It's the ideal starting point for career changers to build a foundation without financial barriers.

Exam Tips 8 min read

ISC2 CC Exam Domains: What You Need to Know to Pass

The ISC2 CC exam consists of five domains: Security Principles, Business Continuity (BC), Disaster Recovery (DR), and Incident Response (IR), Access Controls, Network Security, and Security Operations. To pass, you must master the CIA Triad and security governance, while prioritizing high-weight domains through targeted practice and domain-specific analytics.

Deep Dive 10 min read

Mastering the CIA Triad for ISC2 CC: A Deep Dive

The CIA triad is the foundational model of information security, consisting of Confidentiality (preventing unauthorized access), Integrity (ensuring data accuracy and consistency), and Availability (guaranteeing reliable access to resources). Balancing these three pillars allows security professionals to manage risk effectively and protect organizational assets against diverse cyber threats.

🧠

Test Your Knowledge

Think you understand Due Diligence? Put it to the test with our practice exam.

Try 10 Free Questions

⭐ 1,000 expert-curated questions available with Premium

Upgrade Premium