Most software an organization runs is not built in-house. It is bought, downloaded, contracted or consumed as a service. Each source brings different security risks and different levels of visibility and control, and the CISSP expects you to assess those risks before acquisition and manage them afterward. The constant across every source is accountability: you can outsource the work, but not responsibility for protecting your data.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.