[CCCure CISSP] Qs2 Risk Mgmt: cccure QuizEngn doubts

classic Classic list List threaded Threaded
1 message Options
Reply | Threaded
Open this post in threaded view

[CCCure CISSP] Qs2 Risk Mgmt: cccure QuizEngn doubts

Amlan Deb
Hello everyone,
I have some doubts regarding some cccure Quiz questions and concepts mentioned below. Would really appreciate it if
you could take out some time and help me with them. Request you to please provide a quick reply as I need to appear
for the exam in the month of July.

I would have loved to send a single mail with an attachment containing all the questions, but since that is not 
allowed by the website I'm sending the questions out on separate mails.

These bulk mails would only appear for another week's time. Hope you would understand and bear with me till then



1.     Question: 727 | Difficulty: 5/5 | Relevancy: 3/3

Which of the following would NOT violate the Due Diligence concept?

o      Security policy being outdated

o      Data owners not laying out the foundation of data protection

o      Network administrator not taking mandatory two-week vacation as planned

o     Latest security patches for servers being installed as per the Patch Management process

Congratulations, you got the correct answer! Details can be reviewed below.

The correct answer is: Latest security patches for servers being installed as per the Patch Management process

To be effective a patch management program must be in place (due diligence) and detailed procedures would specify how and when the patches are applied properly (Due Care).  Remember, the question asked for NOT a  violation of Due Diligence, in this case, applying patches demonstrates due care and the patch management process in place demonstrates due diligence. 

Due diligence is the act of investigating and understanding the risks the company faces. A company practices by developing and implementing security policies, procedures, and standards.  Detecting risks would be based on standards such as ISO 2700,  Best Practices, and other published standards such as NIST standards for example.

Due Diligence is understanding the current threats and risks.  Due diligence is practiced by activities that make sure that the protection mechanisms are continually maintained and operational where risks are constantly being evaluated and reviewed.  The security policy being outdated would be an example of violating the due diligence concept.

Due Care is implementing countermeasures to provide protection from those threats.  Due care is when the necessary steps to help protect the company and its resources from possible risks that have been identifed.  If the information owner does not lay out the foundation of data protection (doing something about it) and ensure that the directives are being enforced (actually being done and kept at an acceptable level), this would violate the due care concept. 

If a company does not practice due care and due diligence pertaining to the security of its assets, it can be legally charged with negligence and held accountable for any ramifications of that negligence. Liability is usually established based on Due Diligence and Due Care or the lack of either.

A good way to remember this is using the first letter of both words within Due Diligence (DD) and Due Care (DC).

Due Diligence = Due Detect 
Steps you take to identify risks based on best practices and standards.

Due Care = Due Correct.
Action you take to bring the risk level down to an acceptable level and maintaining that level over time.

The Following answer were wrong:

Security policy being outdated:
While having and enforcing a security policy is the right thing to do (due care), if it is outdated, you are not doing it the right way (due diligence).  This questions violates due diligence and not due care.

Data owners not laying out the foundation for data protection:
Data owners are not recognizing the "right thing" to do.   They don't have a security policy. 

Network administrator not taking mandatory two week vacation:
The two week vacation is the "right thing" to do, but not taking the vacation violates due diligence (not doing the right thing the right way)

Reference(s) used for this question

Shon Harris, CISSP All In One, Version 5, Chapter 3, pg 110

Last Modifed - 06/08/2007 - S G Krishnan
Thanks to Christian Charris for providing feedback to improve this question.

Contributor: Christian Vezina

Study area: Information Security Governance and Risk Management

Covered topics (2): <A title="Due care and due diligence - The due care concept concerns the necessary steps that should normally be taken to help protect the company and its resources from possible risks. Due diligence is practiced by activities that make sure that the protection mec" href="javascript:void(0)">Due care and due diligence, <A title="Risk management - The process of identifying, assessing, and reducing the risk to an acceptable level and implementing the right mechanisms to maintain that level of risk." href="javascript:void(0)">Risk management


My doubt:  Aren’t the options given in the Qs. more of ‘Due Care’ than ‘Due Diligence’?


You can find the list archive at:

CISSPstudy mailing list
[hidden email]

To UNSUBSCRIBE, SUBSCRIBE, or MANAGE your accout visit the link below: