<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Due Care vs Due Diligence in Exam Preparation</title>
    <link>https://community.isc2.org/t5/Exam-Preparation/Due-Care-vs-Due-Diligence/m-p/11479#M2553</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When you are unclear on something, it is best to check multiple resources.&amp;nbsp; Most often a different perspective will help make things clearer...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Harris, Shon. CISSP Boxed Set, Second Edition (All-in-One) (Kindle Locations 20967-20971).&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;P&gt;&lt;STRONG&gt;Due care&lt;/STRONG&gt; means that a company practiced common sense and prudent management and acted responsibly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Due diligence&lt;/STRONG&gt; means that the company properly investigated all of its possible weaknesses and vulnerabilities.&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;USlegal.com&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;&lt;A href="https://definitions.uslegal.com/d/due-care/" target="_self"&gt;Due Care&lt;/A&gt; &lt;/STRONG&gt;refers to the effort made by an ordinarily prudent or reasonable party to avoid harm to another, taking the circumstances into account.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;&lt;A href="https://definitions.uslegal.com/d/due-diligence/" target="_self"&gt;Due Diligence&lt;/A&gt;&lt;/STRONG&gt; is a process of acquiring objective and reliable information, generally on a person or a company, prior to a specific event or decision. It is usually a systematic research effort,&lt;/SPAN&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;...in this case, the "clarity" is that the Sybex glossary appears to have the definitions reversed.&amp;nbsp;Sybex does&amp;nbsp;have an &lt;A href="https://www.wiley.com/WileyCDA/WileyTitle/productCd-1119475937,miniSiteCd-SYBEX.html" target="_self"&gt;errata section&lt;/A&gt; on their web site, but this is not mentioned.&amp;nbsp; You might consider submitting it using their &lt;A href="https://www.wiley.com/go/help/sybexerrataform" target="_self"&gt;errata form&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Avoiding error is another&amp;nbsp;good example of why one ought to use multiple resources when studying.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/585570881"&gt;@Nedryck&lt;/a&gt;&amp;nbsp;wrote:&lt;/P&gt;&lt;P&gt;The Sybex online glossary (and book) state:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Due Care:&lt;/STRONG&gt; The steps taken to ensure that assets and employees of an organization have been secured and protected and that upper management has properly evaluated and assumed all unmitigated or transferred risks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Due diligence:&lt;/STRONG&gt; The extent to which a reasonable person will endeavor under specific circumstances to avoid harming other people or property&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;</description>
    <pubDate>Thu, 14 Jun 2018 17:14:53 GMT</pubDate>
    <dc:creator>denbesten</dc:creator>
    <dc:date>2018-06-14T17:14:53Z</dc:date>
    <item>
      <title>Due Care vs Due Diligence</title>
      <link>https://community.isc2.org/t5/Exam-Preparation/Due-Care-vs-Due-Diligence/m-p/11457#M2547</link>
      <description>&lt;P&gt;So I have come across a testing issue that has been bothering me and found a little conflict:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Sybex online glossary (and book) state:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Due Care:&lt;/STRONG&gt; The steps taken to ensure that assets and employees of an organization have been secured and protected and that upper management has properly evaluated and assumed all unmitigated or transferred risks. due diligence The extent to which a reasonable person will endeavor under specific circumstances to avoid harming other people or property.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Due diligence:&lt;/STRONG&gt; The extent to which a reasonable person will endeavor under specific circumstances to avoid harming other people or property&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The (ISC)2 practice test Iphone app test question shows the following test question:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IMG_0085.jpeg" style="width: 225px;"&gt;&lt;img src="https://community.isc2.org/t5/image/serverpage/image-id/2465i11CF991705898CC7/image-size/medium?v=v2&amp;amp;px=400" role="button" title="IMG_0085.jpeg" alt="IMG_0085.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So my question at this point what is correct answer? This is very discouraging through my studying.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jun 2018 11:52:21 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exam-Preparation/Due-Care-vs-Due-Diligence/m-p/11457#M2547</guid>
      <dc:creator>Nedryck</dc:creator>
      <dc:date>2018-06-14T11:52:21Z</dc:date>
    </item>
    <item>
      <title>Re: Due Care vs Due Diligence</title>
      <link>https://community.isc2.org/t5/Exam-Preparation/Due-Care-vs-Due-Diligence/m-p/11463#M2548</link>
      <description>&lt;P&gt;I think the confusion might be clarified with several key words, such as 'standard', 'specific', 'broad'.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Due care is a broad, standard, more general sense of 'care', more applicable the general, broad interests of the organization,&amp;nbsp; whereas due diligence is a 'specific' action such as following policy, procedure, etc. Don't get hung over 'reasonable person', since that is expected for both.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Your study question contains 'standard' and 'broad', thus C is correct.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just my interpretation, hope it helps.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jun 2018 13:52:30 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exam-Preparation/Due-Care-vs-Due-Diligence/m-p/11463#M2548</guid>
      <dc:creator>Chuxing</dc:creator>
      <dc:date>2018-06-14T13:52:30Z</dc:date>
    </item>
    <item>
      <title>Re: Due Care vs Due Diligence</title>
      <link>https://community.isc2.org/t5/Exam-Preparation/Due-Care-vs-Due-Diligence/m-p/11464#M2549</link>
      <description>&lt;P&gt;Honestly not really...&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Due care seems to be a more defined definition than Due Diligence based on the definitions. Due Care seems to stem from the broad sense of Due Diligence. Just my thoughts...&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jun 2018 14:07:46 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exam-Preparation/Due-Care-vs-Due-Diligence/m-p/11464#M2549</guid>
      <dc:creator>Nedryck</dc:creator>
      <dc:date>2018-06-14T14:07:46Z</dc:date>
    </item>
    <item>
      <title>Re: Due Care vs Due Diligence</title>
      <link>https://community.isc2.org/t5/Exam-Preparation/Due-Care-vs-Due-Diligence/m-p/11465#M2550</link>
      <description>&lt;P&gt;In the Q the word "care" is used.&amp;nbsp; Which option does it occur in? C - don't make it harder then it is.&amp;nbsp; This is the way (ISC)2 will test you.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jun 2018 14:29:30 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exam-Preparation/Due-Care-vs-Due-Diligence/m-p/11465#M2550</guid>
      <dc:creator>Flyslinger2</dc:creator>
      <dc:date>2018-06-14T14:29:30Z</dc:date>
    </item>
    <item>
      <title>Re: Due Care vs Due Diligence</title>
      <link>https://community.isc2.org/t5/Exam-Preparation/Due-Care-vs-Due-Diligence/m-p/11467#M2551</link>
      <description>&lt;P&gt;Christopher,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I concur with both Chuxing and Mark.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;First test-taking skills, generally.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/297159657"&gt;@Flyslinger2&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;In the Q the word "care" is used.&amp;nbsp; Which option does it occur in? C - don't make it harder then it is.&amp;nbsp; This is the way (ISC)2 will test you.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;This needs to be amplified.&amp;nbsp; The question used the term care and that should cue for you that the answer is looking for the same feedback.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Second, Due Care and Due Diligence.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/323397747"&gt;@Chuxing&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;I think the confusion might be clarified with several key words, such as 'standard', 'specific', 'broad'.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Due care is a broad, standard, more general sense of 'care', more applicable the general, broad interests of the organization,&amp;nbsp; whereas due diligence is a 'specific' action such as following policy, procedure, etc.&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;STRONG&gt;Due Care&lt;/STRONG&gt; is a general approach to provide the best services possible.&amp;nbsp; It is broad in its scope in that the person will act as a responsible security professional addressing risks to assets and employees.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Due&amp;nbsp;&lt;/STRONG&gt;&lt;STRONG&gt;Diligence&lt;/STRONG&gt; is a specific set of actions to inform yourself in the context of a specific and narrowly defined condition or activity, and avoid worsening any loss or further causing harm.&amp;nbsp; It is one component of &lt;EM&gt;Due Care&lt;/EM&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This question and answer series has to do with your understanding of how each of these terms applies to the scope of behavior.&amp;nbsp; They can be vaguely described using practically the same language, except that one is overall professional conduct (&lt;EM&gt;Due Care&lt;/EM&gt;) and the other is conduct applied to a specific problem (&lt;EM&gt;Due Diligence&lt;/EM&gt;).&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know it seems trite to nitpick at these definitions.&amp;nbsp; If you take on a consulting position or one where you are in senior management where something goes wrong, you may want to be able to apply these terms correctly and in their proper place when (or hopefully before) the corporate lawyers are sitting across the table from you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sincerely,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Eric B.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jun 2018 15:04:07 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exam-Preparation/Due-Care-vs-Due-Diligence/m-p/11467#M2551</guid>
      <dc:creator>Baechle</dc:creator>
      <dc:date>2018-06-14T15:04:07Z</dc:date>
    </item>
    <item>
      <title>Re: Due Care vs Due Diligence</title>
      <link>https://community.isc2.org/t5/Exam-Preparation/Due-Care-vs-Due-Diligence/m-p/11471#M2552</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/585570881"&gt;@Nedryck&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;BR /&gt;&lt;P&gt;The Sybex online glossary (and book) state:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;At first I thought you meant me, and then realized that mine was from Syngress.&amp;nbsp; Anyway, due care and due diligence come to us from law.&amp;nbsp; The legal literature actually shows them as roughly equivalent, so that's no help in distinguishing them for questions.&amp;nbsp; (And, I would say, if you actually came across &lt;STRONG&gt;that&lt;/STRONG&gt; question in an exam, you could challenge it.&amp;nbsp; That's a &lt;STRONG&gt;bad&lt;/STRONG&gt; question.)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you have to distinguish between them, then due care is the reasonable care you take, and due diligence is mostly the documentation or actions or research that prove you took it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jun 2018 15:28:09 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exam-Preparation/Due-Care-vs-Due-Diligence/m-p/11471#M2552</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2018-06-14T15:28:09Z</dc:date>
    </item>
    <item>
      <title>Re: Due Care vs Due Diligence</title>
      <link>https://community.isc2.org/t5/Exam-Preparation/Due-Care-vs-Due-Diligence/m-p/11479#M2553</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When you are unclear on something, it is best to check multiple resources.&amp;nbsp; Most often a different perspective will help make things clearer...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Harris, Shon. CISSP Boxed Set, Second Edition (All-in-One) (Kindle Locations 20967-20971).&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;P&gt;&lt;STRONG&gt;Due care&lt;/STRONG&gt; means that a company practiced common sense and prudent management and acted responsibly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Due diligence&lt;/STRONG&gt; means that the company properly investigated all of its possible weaknesses and vulnerabilities.&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;USlegal.com&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;&lt;A href="https://definitions.uslegal.com/d/due-care/" target="_self"&gt;Due Care&lt;/A&gt; &lt;/STRONG&gt;refers to the effort made by an ordinarily prudent or reasonable party to avoid harm to another, taking the circumstances into account.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;&lt;A href="https://definitions.uslegal.com/d/due-diligence/" target="_self"&gt;Due Diligence&lt;/A&gt;&lt;/STRONG&gt; is a process of acquiring objective and reliable information, generally on a person or a company, prior to a specific event or decision. It is usually a systematic research effort,&lt;/SPAN&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;...in this case, the "clarity" is that the Sybex glossary appears to have the definitions reversed.&amp;nbsp;Sybex does&amp;nbsp;have an &lt;A href="https://www.wiley.com/WileyCDA/WileyTitle/productCd-1119475937,miniSiteCd-SYBEX.html" target="_self"&gt;errata section&lt;/A&gt; on their web site, but this is not mentioned.&amp;nbsp; You might consider submitting it using their &lt;A href="https://www.wiley.com/go/help/sybexerrataform" target="_self"&gt;errata form&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Avoiding error is another&amp;nbsp;good example of why one ought to use multiple resources when studying.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/585570881"&gt;@Nedryck&lt;/a&gt;&amp;nbsp;wrote:&lt;/P&gt;&lt;P&gt;The Sybex online glossary (and book) state:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Due Care:&lt;/STRONG&gt; The steps taken to ensure that assets and employees of an organization have been secured and protected and that upper management has properly evaluated and assumed all unmitigated or transferred risks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Due diligence:&lt;/STRONG&gt; The extent to which a reasonable person will endeavor under specific circumstances to avoid harming other people or property&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Thu, 14 Jun 2018 17:14:53 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exam-Preparation/Due-Care-vs-Due-Diligence/m-p/11479#M2553</guid>
      <dc:creator>denbesten</dc:creator>
      <dc:date>2018-06-14T17:14:53Z</dc:date>
    </item>
    <item>
      <title>Re: Due Care vs Due Diligence</title>
      <link>https://community.isc2.org/t5/Exam-Preparation/Due-Care-vs-Due-Diligence/m-p/38323#M2601</link>
      <description>&amp;gt; Nedryck (Newcomer I) moved a topic in Exam Preparation on 06-14-2018 07:52 AM in&lt;BR /&gt;&lt;BR /&gt;&amp;gt; So I have come across a testing issue that has been bothering me and found a&lt;BR /&gt;&amp;gt; little conflict: Â&amp;nbsp; The Sybex online glossary (and book) state:Â&amp;nbsp; Â&amp;nbsp; Due Care:&lt;BR /&gt;&amp;gt; The steps taken to ensure that assets and employees of an organization have been&lt;BR /&gt;&amp;gt; secured and protected and that upper management has properly evaluated and&lt;BR /&gt;&amp;gt; assumed all unmitigated or transferred risks. due diligence The extent to which&lt;BR /&gt;&amp;gt; a reasonable person will endeavor under specific circumstances to avoid harming&lt;BR /&gt;&amp;gt; other people or property. Â&amp;nbsp; Due diligence: The extent to which a reasonable&lt;BR /&gt;&amp;gt; person will endeavor under specific circumstances to avoid harming other people&lt;BR /&gt;&amp;gt; or property&lt;BR /&gt;&lt;BR /&gt;OK, this is a very sticky issue, and one which it is extremely difficult to resolve.&lt;BR /&gt;Due care and due diligence are legal terms, and even the lawyers can't seem to&lt;BR /&gt;agree on the difference. Some legal dictionaries say there is a difference, some say&lt;BR /&gt;there isn't. For those that *do* say there is a difference, it is generally that due&lt;BR /&gt;care is being reasonably prudent, and due diligence is how you prove you *were*&lt;BR /&gt;prudent. So, in that case, Sybex is wrong and has it backwards, and the ISC2 app&lt;BR /&gt;test has it right. (From long experience, I would say that it is always safest to&lt;BR /&gt;assume that Sybex has it wrong.)&lt;BR /&gt;&lt;BR /&gt;======================&lt;BR /&gt;rslade@gmail.com rmslade@outlook.com rslade@computercrime.org&lt;BR /&gt;"If you do buy a computer, don't turn it on." - Richards' 2nd Law&lt;BR /&gt;"Robert Slade's Guide to Computer Viruses" 0-387-94663-2&lt;BR /&gt;"Viruses Revealed" 0-07-213090-3&lt;BR /&gt;"Software Forensics" 0-07-142804-6&lt;BR /&gt;"Dictionary of Information Security" Syngress 1-59749-115-2&lt;BR /&gt;============= for back issues:&lt;BR /&gt;[Base URL] site &lt;A href="http://victoria.tc.ca/techrev/" target="_blank"&gt;http://victoria.tc.ca/techrev/&lt;/A&gt;&lt;BR /&gt;CISSP refs: [Base URL]mnbksccd.htm&lt;BR /&gt;PC Security: [Base URL]mnvrrvsc.htm&lt;BR /&gt;Security Dict.: [Base URL]secgloss.htm&lt;BR /&gt;Security Educ.: [Base URL]comseced.htm&lt;BR /&gt;Book reviews: [Base URL]mnbk.htm&lt;BR /&gt;[Base URL]review.htm&lt;BR /&gt;Partial/recent: &lt;A href="http://groups.yahoo.com/group/techbooks/" target="_blank"&gt;http://groups.yahoo.com/group/techbooks/&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://en.wikipedia.org/wiki/Robert_Slade" target="_blank"&gt;http://en.wikipedia.org/wiki/Robert_Slade&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://is.gd/RotlWB" target="_blank"&gt;https://is.gd/RotlWB&lt;/A&gt; &lt;A href="http://twitter.com/rslade" target="_blank"&gt;http://twitter.com/rslade&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://blogs.securiteam.com/index.php/archives/author/p1/" target="_blank"&gt;http://blogs.securiteam.com/index.php/archives/author/p1/&lt;/A&gt;</description>
      <pubDate>Thu, 20 Aug 2020 18:14:48 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exam-Preparation/Due-Care-vs-Due-Diligence/m-p/38323#M2601</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2020-08-20T18:14:48Z</dc:date>
    </item>
    <item>
      <title>Re: Due Care vs Due Diligence</title>
      <link>https://community.isc2.org/t5/Exam-Preparation/Due-Care-vs-Due-Diligence/m-p/49276#M3753</link>
      <description>Although always confusing, esp for the culture varies of daily life, in the cyber security world. due care is for common, and due diligence focus on the duties on specified components ( 3rd parties) and taking actions.</description>
      <pubDate>Mon, 24 Jan 2022 19:46:49 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exam-Preparation/Due-Care-vs-Due-Diligence/m-p/49276#M3753</guid>
      <dc:creator>aidan</dc:creator>
      <dc:date>2022-01-24T19:46:49Z</dc:date>
    </item>
    <item>
      <title>Re: Due Care vs Due Diligence</title>
      <link>https://community.isc2.org/t5/Exam-Preparation/Due-Care-vs-Due-Diligence/m-p/55783#M3887</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Due care and due diligence are often confused, they are related, but there is a difference between them. Due care is informal, while due diligence follows a process. Think of due diligence as a step beyond due care. For example, expecting your staff to keep their systems patched means that you expect them to exercise due care, while verifying that your staff has patched their systems is an example of due diligence.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;[citing from a book written by Eric Conrad, Seth Misenar, Joshua Feldman]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;Simple trick to follow when in doubt.&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Due Care = DC = Do Correct&lt;/P&gt;&lt;P&gt;Due Diligence = DD = Do Detect&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;eg:&amp;nbsp;&lt;/P&gt;&lt;P&gt;A &lt;U&gt;routine review&lt;/U&gt; of the most current SOC 2 report is a critical part of a cloud customer's&amp;nbsp;&lt;STRONG&gt;due diligence&lt;/STRONG&gt;&amp;nbsp;for their cloud service vendor.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There are several approaches to risk mitigation in cloud environments. The start of security is with the selection of a CSP, and a set of documented requirements and comparison of CSP offerings against those requirements is a key&amp;nbsp;&lt;STRONG&gt;due diligence&lt;/STRONG&gt;&amp;nbsp;activity.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Designing a supply chain risk management (SCRM) program to &lt;U&gt;assess&lt;/U&gt; CSP or vendor risks is a &lt;STRONG&gt;due diligence&lt;/STRONG&gt; practice, and actually performing the assessment is an example of&amp;nbsp;&lt;SPAN&gt;due care&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;in a nutshell, by practicing due care, the organization shows it has taken the necessary steps to protect itself and its workers. By practicing due diligence, the organization ensures that these security policies are properly maintained, communicated, and implemented.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this would clear confusion...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Dec 2022 06:55:11 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exam-Preparation/Due-Care-vs-Due-Diligence/m-p/55783#M3887</guid>
      <dc:creator>iluom</dc:creator>
      <dc:date>2022-12-09T06:55:11Z</dc:date>
    </item>
    <item>
      <title>Re: Due Care vs Due Diligence</title>
      <link>https://community.isc2.org/t5/Exam-Preparation/Due-Care-vs-Due-Diligence/m-p/55792#M3888</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/637665353"&gt;@iluom&lt;/a&gt;&amp;nbsp;Mouli, good try at putting some order to the question, however, &amp;nbsp;instill read some linguistic ambiguity to your and all previous replies in this thread.&lt;/P&gt;&lt;P&gt;I am convinced that&amp;nbsp;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1324864413"&gt;@rslade&lt;/a&gt;&amp;nbsp;Grandpa Rob had it right: The question itself is a &amp;nbsp;BAD QUESTION because it tries to differentiate two legal terms in the context of non-lawyers. Subsequent posts in the thread demonstrate that there is no consistent difference between the terms in either legal or general public references.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Dec 2022 13:30:51 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exam-Preparation/Due-Care-vs-Due-Diligence/m-p/55792#M3888</guid>
      <dc:creator>CraginS</dc:creator>
      <dc:date>2022-12-09T13:30:51Z</dc:date>
    </item>
    <item>
      <title>Re: Due Care vs Due Diligence</title>
      <link>https://community.isc2.org/t5/Exam-Preparation/Due-Care-vs-Due-Diligence/m-p/57836#M3931</link>
      <description>This is the clearest definition I have seen on this thread regarding due care and due diligence so far. Due care is what you do, it is action where as due diligence is the paperwork you erect about your actions which includes the policies, written procedures or plan that prove you exercise due care.&lt;BR /&gt;Example: making regular backups and restores to test and ensure these backups are good and sound is due care while a a written backup and restore policy, the steps aka procedures you use you to perform these backups and restores represente due diligence and you can bring these documents with you in the board room when you speak with the organization's lawyer &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;</description>
      <pubDate>Thu, 16 Mar 2023 09:33:04 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exam-Preparation/Due-Care-vs-Due-Diligence/m-p/57836#M3931</guid>
      <dc:creator>Babnerbaptiste</dc:creator>
      <dc:date>2023-03-16T09:33:04Z</dc:date>
    </item>
    <item>
      <title>Re: Due Care vs Due Diligence</title>
      <link>https://community.isc2.org/t5/Exam-Preparation/Due-Care-vs-Due-Diligence/m-p/57837#M3932</link>
      <description />
      <pubDate>Thu, 16 Mar 2023 09:37:04 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exam-Preparation/Due-Care-vs-Due-Diligence/m-p/57837#M3932</guid>
      <dc:creator>Babnerbaptiste</dc:creator>
      <dc:date>2023-03-16T09:37:04Z</dc:date>
    </item>
  </channel>
</rss>

