📖 What is Due Care?

Due Care represents the level of responsibility and caution an organization must exercise to protect information assets. It involves implementing reasonable and appropriate security controls based on identified risks and industry best practices. Demonstrating due care minimizes legal liability in the event of a security incident.

🥋 Sensei Says:

"CISM frequently presents scenarios requiring you to assess whether an organization has exercised due care. Documentation is paramount; a well-documented security program is strong evidence of due care. Understand the legal and regulatory implications of failing to exercise due care."

📚 Certification: Certified Information Security Manager (CISM)

🔑 What are the Key Concepts of Due Care?

  • Due care isn't perfection, but reasonable security measures given the organization's size, industry, and risk profile.
  • Documentation is crucial; policies, procedures, risk assessments, and training records demonstrate a commitment to due care.
  • Regular security assessments (vulnerability scans, penetration tests) and updates to controls are essential for ongoing due care.
  • Due care considers legal and regulatory requirements relevant to the organization's data and operations (e.g., GDPR, HIPAA).
  • Failing to exercise due care can lead to legal repercussions, fines, and reputational damage following a security breach.

🎯 How does Due Care appear on the CISM Exam?

You may be asked to evaluate whether a company’s incident response plan, including regular testing and updates, demonstrates sufficient due care in protecting customer data.

A scenario might describe a company experiencing a breach due to unpatched vulnerabilities. Expect questions about whether the company exercised due care regarding vulnerability management.

Expect questions about the role of due diligence in third-party risk management – assessing if the organization adequately vetted a vendor’s security practices.

❓ Frequently Asked Questions

How does 'due care' relate to 'due diligence'?

Due diligence is the investigation *before* a decision (like hiring a vendor), while due care is the *ongoing* responsibility to maintain security after that decision. Both are important, but distinct.


What if a company implements best-practice security, but still suffers a breach?

Implementing best practices doesn't automatically absolve an organization. The CISM exam will assess if those practices were *reasonable* given the specific risks and if ongoing monitoring and adaptation occurred.


Is cost a factor in determining due care?

Yes, but it's not an excuse to avoid security. The cost of controls must be reasonable *relative* to the potential impact of a breach and the organization’s financial resources. Ignoring risks due to cost is a failure of due care.

Related Terms from Certified Information Security Manager

📝 Related Study Guides

Study Guide 10 min read

CISM Exam Study Guide: Pass the Security Management Exam

The CISM exam consists of 150 multiple-choice questions to be completed in 4 hours, requiring a scaled score of 450/800 to pass. It focuses on four key domains: Governance, Risk Management, Program Development, and Incident Management, prioritizing a managerial perspective over technical implementation to certify security leadership expertise.

Exam Tips 8 min read

Risk Appetite vs Risk Tolerance: ISACA Concepts Explained

Risk appetite is the broad, strategic amount of risk an organization is willing to accept to achieve its goals, typically set by the board. Risk tolerance is the tactical, measurable variation around those goals. While appetite defines the general direction, tolerance sets the specific boundaries for operational deviations.

Deep Dive 8 min read

How to Conduct a Tabletop Exercise: CISM Study Guide

A tabletop exercise is a discussion-based simulation where key stakeholders walk through a hypothetical security incident to validate the Incident Response Plan (IRP). It identifies gaps in communication and processes without impacting production systems, making it a cost-effective, low-risk method for ensuring organizational readiness and meeting CISM governance requirements.

🧠

Test Your Knowledge

Think you understand Due Care? Put it to the test with our practice exam.

Try 10 Free Questions

⭐ 1,000 expert-curated questions available with Premium

Upgrade Premium