📖 What is Due Diligence?
Due Diligence is the act of investigating and researching a situation to ensure that all necessary precautions are taken before entering into an agreement. It involves the verification, auditing, and continuous monitoring of security controls.
"Distinguish this from Due Care; Due Diligence is the 'research and verification' phase, while Due Care is the 'execution and implementation' phase."
📚 Certification: Certified in Cybersecurity (CC)
🔑 What are the Key Concepts of Due Diligence?
- ▸ Conducting background checks and security audits on third-party vendors before signing contracts to ensure they meet the organization's minimum security standards.
- ▸ Performing continuous monitoring and periodic reviews of security logs and audit reports to verify that controls remain effective over time.
- ▸ Analyzing potential threats and vulnerabilities associated with a new project or partnership to make informed, risk-based decisions before proceeding.
- ▸ Gathering evidence, such as SOC 2 reports or industry certifications, to prove that a security control is present and operating correctly.
- ▸ Ensuring compliance with legal and regulatory requirements by documenting the research and verification steps taken to mitigate known risks.
🎯 How does Due Diligence appear on the CC Exam?
You may be asked to identify the correct term when a company reviews a vendor's security policies and audit reports before signing a service level agreement to ensure risk is managed.
A scenario might describe a manager conducting a risk assessment and reviewing existing security documentation to decide if a new software tool is safe to deploy in the environment.
Expect questions that require you to distinguish between the act of researching a security requirement (Due Diligence) and the act of actually implementing that control (Due Care).
❓ Frequently Asked Questions
How can I easily tell the difference between Due Diligence and Due Care on the exam?
Think of Due Diligence as the 'homework' or research phase, which involves verifying and auditing. Due Care is the 'action' phase, involving the actual implementation and enforcement of those security controls.
Is Due Diligence a one-time event during the procurement process?
No. While critical during initial vendor selection, it must be an ongoing process. Periodic audits and continuous monitoring are required to ensure that the vendor's security posture does not degrade over time.
What are the legal implications of failing to perform Due Diligence?
Failure to perform Due Diligence can be viewed as negligence. If a breach occurs and the organization cannot prove they researched the risk, they may face severe legal penalties and liabilities.