scaredoftests wrote: » all depends on who you are doing the website for. I would think lack of due diligence.
[FONT=&]Conrad:[/FONT][FONT=&]Whereas due care intends to set a minimum necessary standard of care to be employed by an organization , due diligence requires that an organization continually scrutinize their own practices to ensure that they are always meeting or exceeding the requirements for protection of assets and stakeholders. Due diligence is the management of due care, and it follows a formal process.[/FONT]
TechGuru80 wrote: » I have always thought of it this way...due care (a point in time) setting a standard/policy/etc., due diligence is continually updating or testing what was set. Given the example, if you did not initially follow best practices in the development and release...you did not practice due care....if you did not continuously test your website and resolve any new vulnerabilities, then you are not practicing due diligence.https://resources.infosecinstitute.com/category/certifications-training/cissp/domains/security-and-risk-management/due-care-vs-due-diligence/#grefhttps://www.cybrary.it/forums/topic/due-care-vs-due-diligence/