StudyToCert

All certifications / CC / Lessons

ISC2 Certified in Cybersecurity 2026 outline · Domain 2: Security governance

Third-party and vendor risk

▶ Watch the overview video

Last reviewed September 25, 2026 · Leer en español

Almost no organization runs everything itself. Cloud providers host data, payroll companies process salaries, contractors maintain buildings and software comes from dozens of suppliers. Each of these third parties can introduce risk, and many serious breaches began at a supplier rather than at the victim. Third-party risk management is the process of identifying, assessing and controlling those risks throughout the relationship.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 5 more sections, 5 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study CC for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the CC study plan