Due care 与 Due diligence

本文探讨了信息安全领域中违反尽职(Due Care)概念的情况,指出数据所有者未建立数据保护基础是主要违规行为。此外,文章还分析了其他可能违反尽职与勤勉概念的行为。

摘要生成于 C知道 ,由 DeepSeek-R1 满血版支持, 前往体验 >

Which of the following would VIOLATE the Due Care concept?

o     Security policy being outdated

o     Data owners not laying out the foundation of data protection

o     Network administrator not taking mandatory two-week vacation as planned

o     Latest security patches for servers only being installed once a week

Violating Due Diligence may mean not working diligently enough.

Comment: C choice says there is a mandatory two-week vacation, but he just ignored to do it. Therefore, it is a Diligence issue. Care is made by mandating two-week vacation.

B. Due care is when the necessary steps to help protect the company and its resources from possible risks have been taken. If the information owner does not lay out the foundation od data protection and ensure that the directives are being enforced, this would violate the due care concept. Due diligence is practiced by activities that make sure that the protection mechanisms are continually maintained and operational. The security policy being outdated would be an example of violating the due diligence concept. Any reason could force a network administrator to delay planned vacation. Not taking any vacation would probably violate the company's security policy, thus violating of the due diligence concept. Security patches only being installed periodically could only mean a violation of the due diligence concept if the security policy specified that patches should be installed as soon as available.

The correct answer is ' Data owners not laying out the foundation of data protection ' , if the information owner does not lay out the foundation of data protection and ensure that the directives are being enforced, this would violate the due care concept.

The other answers are incorrect because :

Security policy being outdated is incorrect as it would violate due diligence concept.

Network administrator not taking mandatory two-week vacation as planned is also incorrect as this will also violate due diligence concept.

Latest security patches for servers only being installed once a week is also incorrect as this will violate the due diligence concept.

Reference: Shon Harris AIO v3 , Chapter-3: Security Management Practices , Page:7 , 46.

Last Modifed - 06/08/2007 - S G Krishnan

Comment:

Due diligence is the act of investigating and understanding the risks the company faces. A company practices due care by developing and implementing security policies, procedures, and standards. Due care shows that a company has taken responsibility for the activities that take place within the corporation and has taken the necessary steps to help protect the company, its resources, and employees from possible threats. So, due diligence is understanding the current threats and risks and due care is implementing countermeasures to provide protection from those threats. If a company does not practice due care and due diligence pertaining to the security of its assets, it can be legally charged with negligence and held accountable for any ramifications of that negligence.

评论 2
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值