CISM Domain 3 - Management of External Services and Relationships
MindMap

Download FREE Audio Files and Printable PDFs of our MindMaps

Your information will remain 100% private. Unsubscribe with 1 click.

Transcript

Introduction

Hey, I’m Nick from Destination Certification, and I’m here to help YOU pass the CISM exam.

In this video, we’re going to break down a full MindMap of some of the most important concepts in Management of External Services and Relationships from Domain 3— not just to help you memorize terms, but to really understand how they interconnect and why they matter.

This is the eleventh of thirteen videos for domain 3. I have included links to the other MindMap videos in the description below. These MindMaps are one part of our complete CISM MasterClass.

Outsourcing

Running an organization without managing external relationships is like running a restaurant without checking your suppliers — sooner or later, you’ll serve spoiled food. Governance means keeping a close eye not just on what happens inside, but also on the partners you rely on.

Managing external services and relationships forms a critical component of modern organizational governance.

Outsourcing Questions

Before engaging with any external service provider, organizations must ask fundamental questions that shape the entire outsourcing relationship. These questions are broad in nature and test everything from due diligence to regulatory compliance. We’ll just be covering some very broad examples here. One of these questions is: has a risk assessment been performed?

Has a risk assessment been performed?

Risk assessment stands as the foundation of any outsourcing decision. Organizations must thoroughly evaluate potential threats, vulnerabilities, and impacts associated with transferring operations to third parties. A good assessment checks everything from data security risks to operational dependencies, business continuity, and even reputation. Skip it, and you’re basically flying blind — just hoping you don’t hit the iceberg you never saw coming.

Are there properly agreed SLA (Service Level Agreement) levels?

Image of outsourced security providers - Destination Certification

Service Level Agreements transform expectations into measurable commitments. Well-crafted SLAs define specific performance metrics, availability targets, response times, and remediation procedures. These agreements must include meaningful penalties for non-compliance and clear escalation paths for issue resolution. Without clear SLAs, working with a vendor is like ordering a pizza with no delivery time — you might get it hot, you might get it cold, or you might not get it at all, and good luck complaining.

That’s why outsourcing requires more than trust — it needs smart recommendations to keep providers in check

Outsourcing Recommendations

Let us consider some recommendations then!

Successful outsourcing requires following established best practices that protect organizational interests while enabling productive vendor relationships. These recommendations provide a roadmap for structuring, managing, and optimizing third-party engagements to achieve desired outcomes while maintaining appropriate oversight and control.

Define appropriate controls to govern relationship

First off, governance controls establish the framework for managing vendor relationships throughout their lifecycle. These controls should encompass performance monitoring, compliance verification, change management procedures, and communication protocols. Regular governance meetings, documented decision processes, and clear accountability structures ensure both parties understand their responsibilities. Effective governance controls prevent relationship drift and maintain alignment between vendor activities and organizational objectives.

Have vendor management teams negotiate contracts

Next, specialized vendor management teams bring expertise in contract negotiation, risk assessment, and relationship management that technical teams may lack. These professionals understand market rates, standard terms, and negotiation tactics that protect organizational interests. Their involvement ensures contracts address security requirements, compliance obligations, and operational needs while avoiding unfavorable terms that could create future liabilities or limit flexibility.

Provide mechanisms to implement changes in a clear manner.

Another thing to keep in mind is that change management procedures prevent confusion and maintain service stability when modifications are necessary.

Risk assessments to include third parties

Furthermore, organizational risk assessments must expand beyond internal boundaries to encompass the entire supply chain. 

Outsourcing risk doesn't entail outsourcing accountability

Third parties introduce unique risks through their own vulnerabilities, business practices, and subcontractor relationships.

Consider the TCO (Total Cost of Ownership)

Finally, it’s important to consider the Total Cost of Ownership, it extends far beyond initial contract prices to encompass implementation costs, ongoing management overhead, transition expenses, and potential risk-related costs. It’s like buying a used car that looks cheap until you factor in gas, insurance, and constant repairs. TCO reveals the real price tag behind vendor deals.

With that frugal idea in mind, let’s take a look at third-party reporting.

Third Party Reporting

Image of third party reporting - Destination Certification

Third-party reporting provides independent validation of vendor controls and practices through standardized frameworks. These reports, particularly Service Organization Control (SOC) reports, offer assurance that vendors maintain appropriate security, availability, and processing integrity controls, reducing the need for individual customer audits. Let’s discuss some of the main ones, starting with SOC1. 

SOC1

SOC1 reports focus specifically on controls relevant to financial reporting, making them essential for vendors handling financial transactions or data that impacts financial statements. These reports follow SSAE 18 standards and provide detailed testing of controls that could affect the accuracy and completeness of financial information. Organizations using service providers for payroll processing, transaction processing, or financial data management should require SOC1 reports to ensure proper financial controls are maintained.

Type I

Type I reports evaluate the design of controls at a specific point in time, providing assurance that controls are suitably designed to meet stated objectives.

Type II

Type II reports test both the design and operating effectiveness of controls over a period, typically six to twelve months, providing stronger assurance than Type I. Now that we have a solid enough understanding of these, let’s move on to SOC 2.

SOC2

SOC2 reports evaluate controls based on Trust Service Criteria covering security, availability, processing integrity, confidentiality, and privacy. Unlike SOC1, SOC2 reports address broader operational and security concerns, making them essential for evaluating vendors handling sensitive data or providing critical infrastructure services. Organizations should review which Trust Service Criteria are included in each report. It has a fairly similar breakdown of type I and type II reports.

Type I

Type I SOC2 reports assess whether security controls are properly designed at a point in time, offering initial validation of a vendor's control environment.

Type II

Type II SOC2 reports provide testing of control effectiveness over time, demonstrating consistent application of security practices and offering stronger assurance for critical vendor relationships. With that in mind, let’s move on to SOC3, the final concept of the video. 

SOC3

SOC3 reports provide general-use summaries of SOC2 findings, designed for public distribution without revealing detailed control descriptions or testing procedures. Think of them this way: SOC 2 is the novel, SOC 3 is the movie trailer — shorter, flashier, and built to impress customers without drowning them in details. Organizations should recognize that SOC3 reports provide limited detail for risk assessment purposes and may need to request SOC2 reports for critical vendors requiring deeper evaluation.

Image of next mindmap - Destination Certification

And that is a high-level review of Management of External Services and Relationships within Domain 3, covering the most critical concepts you need to know for the exam.
Something really cool we are providing with these MindMap videos is a completely FREE downloadable version of all the MindMaps in PDF format. We even include a blank version of each MindMap in case you want to print them out and take notes as you listen along. Link to download the MindMaps is in the description below.

If you found this video helpful you can hit the thumbs up button and if you want to be notified when we release additional videos in this MindMap series, then please subscribe and hit the bell icon to get notifications.
I will provide links to the other MindMap videos in the description below.

Thanks very much for watching! And all the best in your studies

Master CISM from the ground up


Learn more about our CISM MasterClass