StudyToCert

All certifications / CISSP / Lessons

ISC2 CISSP 2024 outline · Domain 8: Software development security

Security impact of acquired software: COTS, open source, third party, managed services (SaaS, PaaS, IaaS)

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

Most software an organization runs is not built in-house. It is bought, downloaded, contracted or consumed as a service. Each source brings different security risks and different levels of visibility and control, and the CISSP expects you to assess those risks before acquisition and manage them afterward. The constant across every source is accountability: you can outsource the work, but not responsibility for protecting your data.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study CISSP for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the CISSP study plan