A company experienced a data breach after failing to patch a known vulnerability for six months. During litigation, they would most likely be found to have failed which of the following?
Due care refers to taking reasonable steps that a prudent person would take in a given situation to prevent harm or meet obligations. In this scenario, the company failed to apply a patch for a known vulnerability for an extended period (six months), which represents a failure to exercise due care. This demonstrates a lack of reasonable action to protect systems and data, which a prudent organization would typically address in a more timely manner.
Due diligence, in contrast, refers to the investigation and research process undertaken before making decisions or taking actions, such as assessing risks before implementing systems. The scenario specifically shows a failure to act on known information rather than a failure to investigate.
The other options are incorrect because: code of ethics violations typically involve professional conduct issues, not security maintenance practices; and the business impact analysis is a process for determining critical business functions and is not directly related to patch management failures.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the difference between due care and due diligence?
Open an interactive chat with Bash
Why is failing to patch a known vulnerability a due care problem and not a code of ethics issue?
Open an interactive chat with Bash
How does the concept of due care relate to cybersecurity best practices?
Open an interactive chat with Bash
ISC2 CISSP
Security and Risk Management
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .