The standard of demonstrable diligence an organisation can show to auditors, boards or regulators. In mobile security, it means there is a traceable record of testing, policy enforcement, remediation and privacy oversight that supports the approval decision.
Expanded Definition
Reasonable care is a governance standard, not a single technical control. It describes whether an organisation can prove it acted prudently, consistently and proportionately for the risk at hand. In mobile security, that proof usually includes documented testing, policy enforcement, remediation tracking and privacy oversight, rather than informal assurances or one-time reviews. The concept is closely related to due diligence, but it is broader in practice because auditors, boards and regulators often assess the completeness of evidence, not just the existence of a policy. Under the NIST Cybersecurity Framework 2.0, this kind of evidence aligns with governance, protection and continuous improvement expectations. Definitions vary across vendors and legal contexts, so organisations should treat reasonable care as a documented standard of defensible decision-making rather than a claim of perfect security. The most common misapplication is equating reasonable care with having a policy on paper, which occurs when teams cannot show that the policy was tested, enforced and revisited after risk changes.
Examples and Use Cases
Implementing reasonable care rigorously often introduces documentation overhead, requiring organisations to weigh faster delivery against the cost of proving that security decisions were made responsibly.
- A mobile application team retains test results, remediation tickets and sign-off records to show that security findings were addressed before release.
- An enterprise enforces device encryption and screen-lock policies, then preserves audit logs demonstrating that exceptions were reviewed and approved.
- A privacy review process records data minimisation decisions, retention limits and third-party disclosures so the organisation can explain why the design was acceptable.
- A security team maps controls to a framework such as NIST Cybersecurity Framework 2.0 and uses that mapping to show ongoing oversight across business owners and technical operators.
- Following a vulnerability disclosure, the organisation documents triage timing, patching actions and communications to demonstrate that it responded with reasonable diligence.
Why It Matters for Security Teams
Security teams rely on reasonable care because many post-incident questions are about process quality, not just technical outcomes. If a breach, privacy complaint or unsafe release occurs, investigators will often ask whether controls were chosen thoughtfully, applied consistently and monitored over time. That makes reasonable care central to governance, risk acceptance and board reporting. It also matters for mobile and identity-adjacent systems where authentication, device trust and data handling decisions can affect user harm and regulatory exposure. Teams that cannot produce evidence of testing, approvals and remediation are left arguing intent instead of demonstrating practice. The standard is especially important where security decisions are distributed across product, legal, privacy and operations, because accountability breaks down quickly when ownership is unclear. Organisaties typically encounter the significance of reasonable care only after an adverse event, at which point the absence of traceable evidence becomes operationally unavoidable to address.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022, GDPR and DORA define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.OV-01 | Reasonable care is evidenced through governance oversight, risk tracking and repeatable security decisions. |
| NIST SP 800-53 Rev 5 | CA-2 | Assessment controls support the evidence base used to demonstrate reasonable care. |
| ISO/IEC 27001:2022 | 5.1 | Leadership commitment and policy enforcement underpin demonstrable diligence in this term. |
| GDPR | Art. 5(2) | Accountability requires organisations to show compliance, a core element of reasonable care. |
| DORA | Art. 9 | Operational resilience expectations require evidence of controlled and tested security measures. |
Document oversight, approvals and review cycles so risk decisions are defensible to boards and auditors.