SaveMyCert
Log in
5 of 5 free questions left today·for unlimited practice
Security Principles

ISC2 Code of Ethics, Due Care, and Due Diligence for the CC Exam

10 min readCC · Security PrinciplesUpdated

The ISC2 Code of Ethics is a mandatory set of professional standards that every ISC2 certification holder, including CC candidates, agrees to follow: a preamble plus four canons that must be applied in a fixed order of priority, starting with protecting society and ending with advancing the profession. Alongside the Code, the CC exam expects you to separate two related legal concepts: due care is taking the reasonable, prudent actions a sensible professional would take, while due diligence is the ongoing investigation and research that tells you which actions are reasonable in the first place. In this lesson you will learn why security professionals need a formal code of conduct, how due care and due diligence differ and depend on each other, the exact wording and priority order of the four ISC2 canons, how to resolve situations where canons conflict, and what happens to your certification if you violate the Code.

What you’ll learn
  • Explain why security professionals need a formal code of professional conduct
  • Define due care as the reasonable actions of a prudent person
  • Define due diligence as the ongoing investigation that informs due care
  • State the four canons of the ISC2 Code of Ethics in their required order of priority
  • Apply canon precedence to resolve a scenario where two canons conflict
  • Describe the consequences of violating the ISC2 Code of Ethics

Why security professionals need a code of conduct

Security professionals hold a position of unusual trust. To do the job at all, you are handed access that ordinary employees never get: administrator credentials, unfiltered views of network traffic, personal data about employees and customers, knowledge of unpatched vulnerabilities, and details of how the organization's defenses work. Every one of those privileges could be abused, and most abuse would be invisible to the people it harms.

That is the core problem a professional code of conduct solves. Employers, customers, and the public cannot personally verify that each security practitioner is trustworthy, so the profession publishes a shared standard of behavior and holds every certified member to it. The code turns trust from a personal gamble into an institutional guarantee: if someone holds the certification, they have formally committed to a known set of ethical rules and can lose the credential for breaking them.

A code of conduct also protects you as a practitioner. When a manager pressures you to hide a breach, snoop on a colleague, or overstate a product's security, the code gives you an external, non-negotiable standard to point to. The answer is not merely that you personally feel uncomfortable; it is that the action would violate the ethical obligations of your profession.

For ISC2 members that standard is the ISC2 Code of Ethics. Agreeing to it is a condition of certification, which means it applies to you from the moment you earn the CC credential, not only once you reach a senior role.

Due care: acting as a prudent person would

Due care is the practice of taking the reasonable precautions that a sensible, careful person would take in the same situation. It is often summarized by the prudent person rule: ask what a prudent professional with the same responsibilities would do, and then do that. Due care is about action. It is the doing of the right thing at the right time.

In a security context, due care looks like concrete, visible steps: applying security patches on a sensible schedule, enabling multifactor authentication for privileged accounts, backing up critical data, training staff on phishing, encrypting sensitive records, and responding promptly when an incident is detected. None of these actions require heroics. They are simply what a reasonable organization is expected to do to protect the assets in its charge.

Due care matters legally as well as ethically. If an organization suffers a breach and can show it exercised due care, meaning it took the precautions a prudent organization would have taken, it is in a far stronger position with regulators, courts, and customers. The opposite of due care is negligence: failing to take precautions that any reasonable professional would recognize as necessary. An organization that never patched a known critical vulnerability, or a professional who ignored an obvious warning sign, has failed the prudent person test.

For the exam, anchor due care to two triggers: the word care maps to action, and the phrase prudent person signals due care. When a question describes someone actually implementing safeguards or correcting a known problem, that is due care.

Due diligence: the investigation that informs due care

Due diligence is the ongoing work of investigation, research, and evaluation that tells you what reasonable care actually requires. Before you can take the right precautions, you have to find out what the risks are, what the standards say, and whether your current measures are working. That fact-finding activity is due diligence. It is about knowledge. Due care is then the action you take based on that knowledge.

Examples of due diligence include performing risk assessments, researching threats that target your industry, reviewing audit results and logs, evaluating a vendor's security posture before signing a contract, verifying that policies are actually being followed, and monitoring whether the patches you deployed really closed the gap. Notice that due diligence is continuous, not a one-time checkbox: threats change, so the research that informs your precautions must keep running.

The two concepts form a cycle. Due diligence identifies what needs to be done; due care does it; further due diligence confirms the action worked and looks for the next gap. One without the other fails. Precautions taken without investigation may be aimed at the wrong risks, and research that never leads to action protects nobody.

AspectDue careDue diligence
EssenceDoing the right thingFinding out what the right thing is
NatureAction, practice, correctionInvestigation, research, verification
Memory hookPrudent person ruleOngoing homework behind the action
ExamplesPatching, encrypting, training staffRisk assessments, vendor reviews, monitoring
Failure looks likeNegligence: known risk, no actionIgnorance: acting without investigating

The CC exam loves this pairing. If the scenario describes researching, assessing, evaluating, or verifying, choose due diligence. If it describes implementing, fixing, or taking precautions, choose due care.

The ISC2 Code of Ethics: preamble and purpose

The ISC2 Code of Ethics is short by design. It consists of a preamble and four mandatory canons. There is no long rulebook of specific dos and don'ts; instead, the Code states broad principles that members are expected to apply with judgment to whatever situation they face.

The preamble establishes two ideas. First, the safety and welfare of society and the common good, the duty to our principals, and the duty to each other require that ISC2 members adhere, and be seen to adhere, to the highest ethical standards of behavior. The phrase be seen to adhere matters: it is not enough to be privately ethical; the profession's credibility depends on visibly ethical conduct. Second, the preamble states that strict adherence to the Code is a condition of certification. Ethics is not optional extra credit; it is part of what the credential certifies.

Who must follow the Code? Every ISC2 member and every holder of an ISC2 certification, including Certified in Cybersecurity. You commit to the Code when you certify, and the commitment covers your professional conduct from that point on, regardless of your job title or seniority.

Two terms in the Code deserve definition before you read the canons. Principals are the people you serve and answer to in a professional capacity, such as your employer or your clients. The profession means the community of security practitioners as a whole, whose collective reputation every member either strengthens or damages.

The four canons in their required order of priority

The heart of the Code is four canons. Learn them word for word, and learn them in order, because the order is itself part of the Code:

  1. Protect society, the common good, necessary public trust and confidence, and the infrastructure.
  2. Act honorably, honestly, justly, responsibly, and legally.
  3. Provide diligent and competent service to principals.
  4. Advance and protect the profession.

Read the sequence as a set of widening then narrowing circles of duty. Your first obligation is to society at large: the public, the shared trust that makes digital life possible, and the critical infrastructure everyone depends on. Your second obligation is to personal integrity: honorable, honest, just, responsible, and legal behavior in everything you do. Only third comes your duty to your principals, the employers and clients who pay you: they deserve diligent and competent service, but never at the expense of society or your integrity. Fourth and last is your duty to the profession itself: advancing the field, mentoring others, and refusing to associate the credential with wrongdoing.

Notice the vocabulary inside canon three: diligent and competent service. Diligence here echoes due diligence, meaning careful, sustained, well-informed effort on behalf of your principals, and competence means maintaining the skills the work requires. Also notice that canon two makes legality an ethical floor: an unlawful act is automatically a Code violation, but the canon demands more than mere legality, because it also requires honor, honesty, justice, and responsibility.

Memory aids help, but do not let a mnemonic scramble the sequence. A simple anchor is the priority chain: society first, integrity second, principals third, profession fourth.

When canons conflict: apply them in order

The canons are listed in priority order for a reason: real situations can put them in tension, and the Code resolves the tension mechanically. When two canons point in different directions, the higher-listed canon wins. You do not weigh them case by case or pick the one that feels most compelling; you follow the order.

Work through a scenario. You are a security analyst at a software company. During testing you discover that your company's flagship product contains a critical flaw that exposes customer data, and some of those customers operate hospital systems. Your manager, worried about a major deal closing this quarter, instructs you to stay quiet and delay any fix or disclosure until next year. What does the Code require?

Map the pressures to canons. Staying quiet arguably serves your principal's short-term commercial interest, which sounds like canon three, service to principals. But leaving hospital systems exposed endangers the public and undermines public trust and confidence, which is canon one, and knowingly concealing a serious risk is neither honest nor responsible, which violates canon two. Canon one outranks canon three, and canon two outranks canon three as well. The Code therefore requires you to push for responsible remediation and appropriate disclosure through proper channels, even though your principal prefers silence. Serving a principal never licenses harming society or acting dishonestly.

Note what canon ordering does not mean. It does not tell you to leak the flaw to the press as a first step; acting responsibly, per canon two, means escalating internally, documenting your concerns, and following lawful disclosure processes. The ordering tells you whose interests prevail, not that dramatic action is always the answer.

Enforcement: violations can cost you the certification

The ISC2 Code of Ethics has teeth. Because strict adherence is a condition of certification, ISC2 can discipline members who violate it, and the sanctions run up to revocation of the certification itself. For a working professional, losing the credential can mean losing the job that requires it, so the Code is a genuinely enforceable standard rather than an aspirational poster.

Enforcement works through a complaint process. Complaints alleging a violation are submitted to ISC2, supported by evidence, and reviewed by an ethics committee that examines the facts and recommends action to the ISC2 board. Standing to complain tracks the canons: for example, members of the public may raise complaints relevant to the duty to society, and principals such as employers or clients may raise complaints about the duty of diligent and competent service. Members are also expected not to abuse the process itself; filing a baseless complaint to harass a colleague is unethical conduct in its own right.

You do not need to memorize procedural detail for the CC exam. What you must know is the principle: the Code is mandatory for all ISC2 members and certification holders, violations can be reported and investigated, and a proven violation can end with censure or loss of the certification. Combine that with the canon order and you have the two enforcement facts the exam actually tests.

Ethical conduct also has a daily, preventive dimension: declining conflicts of interest, protecting confidential information even after you change jobs, being truthful about your qualifications, and giving honest assessments even when they are unwelcome. Practicing these habits is how you keep the Code from ever becoming a disciplinary matter.

How to answer ethics questions on the CC exam

Ethics questions on the CC exam are scenario questions in disguise. They rarely ask you to recite the Code; instead they describe a situation and ask what you should do, or which principle applies. A reliable method has three steps.

First, classify the concept being tested. If the scenario is about research, assessment, evaluation, or verification, the answer involves due diligence. If it is about taking reasonable precautions or fixing a known problem, the answer involves due care, and the phrase prudent person is a giveaway. If the scenario involves professional behavior, conflicting loyalties, or misconduct, it is testing the Code of Ethics.

Second, when the Code applies, identify which canons are in play and rank them. Ask: is society, public trust, or infrastructure at risk? That is canon one and it beats everything. Is honesty, legality, or responsibility at stake? Canon two beats duties to employers and clients. Is this about serving an employer or client well? Canon three. Is it about the reputation or advancement of the security field? Canon four, the lowest priority.

Third, prefer answers that are responsible in method as well as correct in priority: escalate through proper channels, document concerns, follow lawful disclosure processes, and decline unethical instructions without committing a rash act yourself. Distractor answers often pair the right priority with a reckless method, or the wrong priority with a professional-sounding method. The credited answer gets both right: society and integrity outrank the paycheck, pursued through responsible action.

Tip. The CC exam tests this sub-domain with scenario questions: expect a described situation followed by which concept applies or what should you do. Trigger words to watch: prudent person and reasonable precautions signal due care, while assess, research, investigate, and verify signal due diligence. Canon questions hinge on the required priority order, often by putting duty to an employer against duty to the public and crediting the answer that protects society first through responsible channels. Also expect a direct recall item on the canons' order or on the fact that violating the Code can cost you the certification.

Key takeaways
  • Due care is action: taking the reasonable precautions a prudent person would take.
  • Due diligence is investigation: the ongoing research and verification that informs due care.
  • The four ISC2 canons in priority order: protect society; act honorably; serve principals; advance the profession.
  • When canons conflict, the higher-listed canon always wins; duty to society outranks duty to an employer.
  • Canon two makes legality a floor: unlawful conduct is automatically a Code violation.
  • Adherence to the Code is a condition of certification; violations can be investigated and can cost you the credential.
  • Prudent person in a question signals due care; assessing or verifying signals due diligence.
  • Serving a principal never justifies harming the public or acting dishonestly.

Frequently asked questions

What are the four canons of the ISC2 Code of Ethics in order?

In their required order of priority: first, protect society, the common good, necessary public trust and confidence, and the infrastructure; second, act honorably, honestly, justly, responsibly, and legally; third, provide diligent and competent service to principals; fourth, advance and protect the profession. The order matters because when canons conflict, the higher-listed canon takes precedence.

What is the difference between due care and due diligence?

Due care is the action side: taking the reasonable precautions a prudent person would take, such as patching systems, encrypting data, and training staff. Due diligence is the knowledge side: the ongoing investigation, research, and verification that determines which precautions are needed and whether they are working, such as risk assessments, vendor reviews, and monitoring. Due diligence informs due care; due care acts on due diligence.

What is the prudent person rule in cybersecurity?

The prudent person rule is the standard used to judge due care: it asks what a sensible, careful professional with the same responsibilities would do in the same situation. If an organization or individual took the precautions a prudent person would have taken, they exercised due care; if they ignored precautions any reasonable professional would recognize as necessary, they were negligent.

What happens if you violate the ISC2 Code of Ethics?

Strict adherence to the Code is a condition of holding any ISC2 certification, including Certified in Cybersecurity. Alleged violations can be reported to ISC2, reviewed by an ethics committee, and sanctioned, with penalties up to revocation of the certification. Losing the credential can in turn cost you roles that require it, so the Code is an enforceable professional standard, not just guidance.

Which ISC2 canon takes priority when duties conflict?

The first canon, protecting society, the common good, necessary public trust and confidence, and the infrastructure, always takes priority. The canons are applied in their listed order, so duty to society outranks personal integrity obligations, which outrank service to principals such as employers and clients, which outranks advancing and protecting the profession.

Does the ISC2 Code of Ethics apply to CC certification holders?

Yes. The Code applies to all ISC2 members and to every holder of an ISC2 certification, including the entry-level Certified in Cybersecurity credential. You agree to the Code when you certify, and it governs your professional conduct from that point on, regardless of your job title or experience level.

Test yourself on this topic
Practice questions with full explanations.
Practice now

Sign up free to mark lessons complete, bookmark topics and track your exam readiness.