ISC2 CC Security Principles Practice Question
Which of the following best describes the difference between due care and due diligence in security governance?
⚠ Common exam trap
The trap is that candidates often think due care and due diligence are interchangeable or that one is proactive and the other reactive; the exam tests the precise definitions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Due care is the minimum standard of care; due diligence is the investigation and assessment
Due care refers to the minimum standard of care that an organization must exercise to protect its assets, often defined by laws, regulations, or industry best practices. Due diligence is the ongoing process of investigation, assessment, and verification to ensure that due care is maintained. In security governance, due care is the baseline, while due diligence is the active effort to identify and mitigate risks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Due care is proactive, due diligence is reactive
Why it's wrong here
Due diligence is the ongoing assessment and verification of controls; due care is acting on those findings to protect assets. The option inverts these, and neither term maps cleanly to proactive versus reactive. The distinction is assessment versus action, not timing.
- ✗
They are synonymous
Why it's wrong here
Treating them as synonymous erases the distinction the question tests: due care is the ongoing duty to protect, while due diligence is the documented, reasonable effort to verify that protection. Governance frameworks separate the two precisely because each demands different evidence and accountability.
- ✗
Due care applies to vendors; due diligence applies to employees
Why it's wrong here
Due care and due diligence are not divided by population; both apply to employees, vendors and processes alike. Due care is the standard of prudence expected, while due diligence is the ongoing activity of verifying that standard. Splitting them by audience misstates the governance principle entirely.
- ✓
Due care is the minimum standard of care; due diligence is the investigation and assessment
Why this is correct
Due care is the minimum standard of care an organisation must exercise, while due diligence is the ongoing investigation and assessment underpinning it. This distinction separates the duty itself from the research activity that informs it.
Go deeper
Related to this question
Learn chapter
Security Governance and Compliance
Key term
Due diligence
Due diligence is the process of systematically reviewing and verifying information, policies, and procedures to identify and manage risks before making a decision or taking an action in an IT or security context.
Key term
Security governance
Security governance is the framework of rules, policies, and processes that an organization uses to align its cybersecurity activities with its business goals and legal obligations.
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.