CompTIA Security+ (SY0-701)Security Program Management and OversightMedium
A new IT director tells staff that patches must be applied within 30 days of release, exceeding the organization's documented minimum requirement of 90 days, because the director believes this reflects prudent security practice. Which concept does the director's action illustrate?
- ADue care
- BRisk tolerance
- CDue diligence
- DCompensating control
Show answer & explanationAnswer & explanation
Correct answer: A. Due care
Due care refers to the ongoing, reasonable steps an organization takes to protect its assets and maintain a standard of care beyond the bare minimum, such as patching faster than the policy requires. Due diligence, by contrast, refers to the research and investigation performed before making a decision, such as vetting a vendor.
Why the other options are wrong
- B. Risk tolerance is the acceptable deviation from risk appetite, not an operational practice.
- C. Due diligence is investigative and typically occurs before a decision, such as vendor evaluation.
- D. A compensating control addresses a specific control gap, not a general practice of exceeding minimums.
Due Care
The ongoing, reasonable actions an organization takes to protect assets and maintain an acceptable security posture, often exceeding minimum policy requirements.
- Due care is continual/operational; due diligence is investigative/pre-decision
- Failure to exercise due care can result in legal liability for negligence
- Example: patching faster than required, enforcing strong access controls
Memory trick: Diligence = research before, Care = action during