StudyToCert

All certifications / SecurityX / Lessons

CompTIA SecurityX CAS-005 · Domain 1: Governance, risk and compliance

Third-party and supply chain risk management: vendor assessments, SBOMs, contracts and right to audit

▶ Watch the overview video

Last reviewed September 25, 2026 · Leer en español

Much of your risk now sits with other companies: cloud providers, SaaS vendors, managed service providers, software suppliers and the open-source components inside your own code. A supply chain compromise can reach thousands of customers at once, so third-party risk management is a core senior responsibility.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 4 more sections, 5 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study SecurityX for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the SecurityX study plan