学CISSP时的了解如下:
Due Care说的是,你应该去做的事件,像方案
Due Diligence说的是你要包管Due Care要做的那些事件始终在放弃最新的形态,有点像审计,要包管Due Care在履行。
Due Diligence: continual effort of making sure that the correct polices, procedures and standards are in place and being followed
Due diligence involves investigating the risks, and due care involves carrying out the necessary steps to mitigate these risks.