CIS Critical Security Control 15: Service Provider Management (v8)
Your organization’s security depends on more than just your internal systems. This course explores how CIS Critical Security Control 15 helps organizations manage third-party relationships and reduce risks introduced by external service providers.

Course Content
CIS Critical Security Control 15: Service Provider Management (v8) focuses on identifying, assessing, and managing cybersecurity risks associated with vendors, contractors, and other external partners. This course examines how organizations can establish stronger oversight of third-party services while ensuring providers meet security expectations.
You’ll explore key practices such as vendor assessments, security requirements, contractual considerations, service provider monitoring, and risk management processes. Through practical scenarios, the course highlights how third-party weaknesses can impact an organization’s environment and how proactive management reduces exposure. By the end of the course, you’ll understand how to apply CIS Control 15 to improve vendor security and strengthen supply chain resilience.














