StudyToCert

All certifications / CISM / Lessons

ISACA Certified Information Security Manager (CISM) 2026 exam content outline · Domain 3: Information security program

Managing external services: vendors, cloud providers and fourth parties

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

Most organizations depend on outside providers for software, cloud infrastructure, payroll, customer support and many other services. Each provider that handles your data or connects to your systems extends your attack surface, and several major breaches have started at a supplier. Outsourcing transfers work, not accountability: regulators, customers and courts still hold you responsible for your data and services. Third-party risk management (TPRM) is how the information security program manages that exposure.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study CISM for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the CISM study plan