Courseiva
mediumMultiple ChoiceObjective-mapped

CISSP Practice Question: Is implementing a security program and wants to…

An organization is implementing a security program and wants to ensure it meets legal and regulatory requirements. The security manager is reviewing the concept of due care. Which best describes due care in the context of information security?

⚠ Common exam trap

A common mix-up: candidates confuse 'due care' with 'compliance' (option C), but due care is a broader legal duty of prudence that often exceeds regulatory minimums, and the CISSP exam emphasizes that compliance alone does not guarantee security or legal protection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The level of prudence expected from a reasonable organization in the same industry

Due care is the legal concept that an organization must act with the level of prudence that a reasonable organization in the same industry would exercise to protect sensitive information. It is not merely compliance with laws (option C), but a broader standard of care that includes implementing reasonable security measures, even where specific regulations do not mandate them. In information security, due care is demonstrated through policies, procedures, and controls that a prudent organization would adopt to avoid negligence liability.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The process of responding to security incidents after they occur

    Why it's wrong here

    This option incorrectly defines due care as a reactive measure. Due care primarily involves the proactive implementation of reasonable security controls and practices to prevent incidents from occurring in the first place. While incident response is a critical component of a comprehensive security program, it addresses the aftermath of a security breach rather than the preventative actions expected from a prudent organization.

  • The selection of security controls based on cost-benefit analysis

    Why it's wrong here

    While cost-benefit analysis is an essential tool for making informed decisions about security control investments, it describes a methodology for resource allocation, not the definition of due care itself. Due care represents the overarching standard of conduct—the obligation to act prudently—whereas cost-benefit analysis is a technique used to help meet that standard by optimizing the selection and implementation of appropriate security measures.

  • Compliance with all applicable laws and regulations

    Why it's wrong here

    Compliance with laws and regulations, while a necessary component of responsible organizational behavior, does not fully encompass the concept of due care. Due care demands a higher standard, requiring an organization to implement security measures that are reasonable and prudent given the circumstances, even if specific actions are not explicitly mandated by law. It often extends to adopting industry best practices and evolving security standards beyond mere legal minimums.

  • The level of prudence expected from a reasonable organization in the same industry

    Why this is correct

    This option accurately defines due care as the standard of reasonable prudence expected from an organization within a specific industry. It signifies the obligation to take appropriate and customary steps to protect information assets and mitigate risks, aligning with what a similarly situated, responsible entity would do under comparable circumstances. This standard is dynamic, evolving with technological advancements and emerging threats, requiring continuous assessment and adaptation of security practices.

About these practice questions

One of 747 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.