CISSP Domain8 Section 3 and 4
8.3 Assess the effectiveness of software security8.3.1 Auditing and logging of changes8.3.2 Risk analysis and mitigation8.4 Assess security impact of acquired software8.4.1 Commercial-off-the-shelf (COTS)8.4.2 Open Source8.4.3 Third-Party8.4.4 Managed Services (e.g.., enterprise applications)8.4.5 Cloud Services (e.g.., SaaS, IaaS, PaaS)