CertMike Explains Due Care vs. Due Diligence

แชร์
ฝัง
  • เผยแพร่เมื่อ 14 ก.ค. 2022
  • Due care and due diligence are common phrases that people associate with doing the right thing. However the distinction between the two often confuses people. Understanding the difference between due care and due diligence is an important topic as you prepare for the CISSP, CISM, and other cybersecurity certification exams.
    In this video, certification and cybersecurity expert Mike Chapple breaks down the basics of due care vs. due diligence to help you prepare for your exam.
    Learn more about Mike's full certification preparation programs at www.certmike.com/
    #cybersecurity #CertMike #DueCare #DueDiligence #RightThings #PriorPlanning #CybersecurityPreparation #ProtectionEfforts
  • วิทยาศาสตร์และเทคโนโลยี

ความคิดเห็น • 16

  • @olumideoginni1978
    @olumideoginni1978 ปีที่แล้ว +6

    have always struggled to know the difference between due care and due diligence, this video nailed it for me, thanks Mike

  • @MariaFladung
    @MariaFladung 4 หลายเดือนก่อน

    I have searched so long for a good explanation! That's it! Thanks

  • @matankarbian5644
    @matankarbian5644 6 หลายเดือนก่อน

    Thank you Mike Chapple for making everything simple !

  • @songofyesterday
    @songofyesterday 8 หลายเดือนก่อน

    This is a much better explanation than some of the other TH-camrs

  • @sakhiwodlalisa4844
    @sakhiwodlalisa4844 ปีที่แล้ว

    Explained like a pro with passion. Thank you. This will assist me with my PWC assignment.

  • @kkgill1806
    @kkgill1806 ปีที่แล้ว

    It's a perfectly clear definition and explanation of due care and due diligence with different real-life examples. It's really brilliant. Thanks.

  • @DeepakKumar-kr9ki
    @DeepakKumar-kr9ki ปีที่แล้ว

    Always helpful to listen these videos!

  • @marcmenard9121
    @marcmenard9121 ปีที่แล้ว

    Damn. I'd bet that any company in the world who was absolutley totally irresponsible at following it's own company guidelines & rules as well as proper procedures would be totally afraid out of their wits of you. That was a wonderful presentaion and explanation. Thanks for sharing.

  • @timabdiukov
    @timabdiukov ปีที่แล้ว +1

    I want to add my 5c: I noticed there's a mild mistake in the video - it seems as if due dilligence is just before due care in the timeline, which is not always the case. If we hypothetically had an exposed live electric wire, putting a fence around it would be due care. And periodically monitoring that the fence isn't breached/hasn't become conductive/hasn't become eroded would be due dilligence. You may notice that in this example, due care is before due dilligence
    I personally think of due dilligence as "business as usual when things go well", and due care as "doing everything reasonable in the event of things going bad fast"

  • @vq8gef32
    @vq8gef32 ปีที่แล้ว

    Finally got it. Thanks

  • @chinhquang7390
    @chinhquang7390 ปีที่แล้ว +1

    hi Mike, after this video, I think that setting up a firewall, a WAF means doing due diligence exercises, and maintaining/operating the firewalls, inspecting their logs means doing due care tasks.
    Please correct me if I'm wrong.
    Thank you!

    • @kqabro
      @kqabro 4 หลายเดือนก่อน

      In simple words Due Care = DC= Do correct, and Due Diligence= DD= Do detect.
      and as per CISSP CBK 6th edition page 22" reviewing security log output for suspicious activity and conducting penetration tests to
      determine if firewall rules are sufficiently restrictive is due dilgence" hence reviewing logs comes under due diligence.

  • @atanumaji1739
    @atanumaji1739 5 หลายเดือนก่อน

    so, running a VA scan is due diligence? n fixing vulnerability part is due care?

    • @kqabro
      @kqabro 4 หลายเดือนก่อน

      in simple words Due Care = DC= Do correct, and Due Diligence= DD= Do detect.
      so by this your approach is right to consider above concept.

  • @kqabro
    @kqabro 4 หลายเดือนก่อน +1

    I am sorry here Mike.
    you had made this concept bit difficult and in fact more confusing.
    The explanation provided in CISSP CBK 6th edition page 22 is " Due Care : reasonable care to protect the interests of your organization, and Due Diligence : ongoing execution and monitoring of due care"
    and this is simply opposite what you explain here or described in your book i.e. CISSP OSG 9th Edition.
    This has caused a lot confusion and every time we respond wrong of there is any question related with this concept.
    I must say we must stick with CBK, as this would be right approach to answer correctly in the exam, whatever the actual answer is, since the same concept is endorsed at ISC2 website of flash cards.