Due diligence refers to the process of researching and understanding the laws, regulations, and best practices that govern information security within a specific industry. Organizations are required to conduct due diligence to ensure compliance with legal and regulatory requirements, which helps mitigate risks and avoid penalties. * Compliance reporting involves generating reports to demonstrate adherence to legal or regulatory standards. * GDPR is a specific regulation governing data privacy in the EU, not a general practice of researching laws. * Attestation is a formal declaration that an organization is compliant with a set of standards but is not the act of researching the laws.