CPA Information Systems and Controls: IT risk meets assurance

Information Systems and Controls (ISC) is one of the 3 Discipline sections — IT governance, cybersecurity, and the SOC reporting framework, for candidates heading toward IT audit or advisory work. Here's the full breakdown, plus a worked SOC report example.

Find the gap you didn't know you had

10 questions · about 4 minutes · no account. It names the concept underneath your wrong answers, not just the topic.
Take the free CPA diagnostic →

Practice fresh ISC questions daily

FSRS scheduling · AI tutor included
Get started →

What CPA Information Systems and Controls actually tests

ISC is a Discipline section (choose 1 of 3: BAR, ISC, or TCP):

AreaWhat it covers
IT Governance & StrategyCOBIT framework, IT risk governance
Information Systems ArchitectureERP, cloud computing (IaaS/PaaS/SaaS), databases, SDLC
CybersecurityCIA triad, NIST framework, cryptography, access controls
System and Organisation Controls (SOC)SOC 1, SOC 2 (Trust Services Criteria), Type I vs. Type II
Internal Controls in IT EnvironmentGeneral IT controls, application controls, CAATs
Business ContinuityRTO, RPO, disaster recovery planning
Data Analytics for AssuranceBenford's Law, exception reporting
Emerging TechnologiesBlockchain, RPA, AI/ML in business processes

Why the SOC 1 vs. SOC 2 distinction is worth locking down early

ISC repeatedly tests which SOC report type is appropriate for a given scenario — SOC 1 for controls relevant to a user entity's financial reporting, SOC 2 for controls relevant to security, availability, and related Trust Services Criteria. Confusing the two, or confusing Type I with Type II within either, is one of the most common ISC mistakes.

Sample question: SOC Report Types

Information Systems and Controls · Easy-medium difficulty

Which SOC report type includes the auditor's opinion on the OPERATING EFFECTIVENESS of controls over a period of time, not just their design at a point in time?

A. SOC 1 Type I
B. SOC 2 Type I
C. SOC 2 Type II
D. SOC 3
The correct answer is C — SOC 2 Type II.
A Type II report tests whether controls actually operated effectively over a defined period (e.g., 6-12 months). A Type I report (whether SOC 1 or SOC 2) only opines on whether controls were suitably designed as of a single point in time — a meaningfully lower bar of assurance.

The ISC blueprint, area by area

Pinnacle runs on a syllabus graph — named areas with explicit prerequisites, each one mapped against the AICPA's Uniform CPA Examination Blueprints effective January 2026. It is the same map the free diagnostic reasons over, not a marketing summary of it. These are the four confirmed ISC areas, and what each one covers:

Regulations, Standards & Frameworks

The rulebooks ISC tests by name: HIPAA's Security and Privacy Rules with covered entities and permitted disclosures, the GDPR's scope and six principles, PCI DSS, the NIST Cybersecurity and Privacy Frameworks with their cores, tiers and profiles, NIST SP 800-53, the CIS Controls, and COBIT 2019's governance principles and the components of a governance system.

Information Systems & Data Management

IT infrastructure from operating systems to end-user devices, cloud service and deployment models with provider responsibilities, ERP and accounting information systems, blockchain risks in financial reporting, and reconciling key business processes to their flowcharts and narratives. Availability covers disaster recovery, business continuity, backup types and recovery; change management runs from control policies through testing environments to conversion approaches; and data management spans warehouses, lakes and marts, database schemas and normalization, SQL, the data life cycle, and business process models such as data flow diagrams and BPMN.

Security, Confidentiality & Privacy

Threat agents from insiders to nation-states, and the attack catalogue — DDoS, malware, social engineering, buffer overflows, cross-site scripting, SQL injection, replay attacks — with the preventive, detective and corrective controls that mitigate them, including segmentation and VPNs for remote access. Confidentiality and privacy cover encryption, data obfuscation and tokenization, data loss prevention, and the implications of a breach; incident response covers plans, roles, timelines, insurance as mitigation, and testing the response against the plan.

SOC Engagements

Planning and performing SOC work: the Trust Services Criteria and their alignment with the COSO framework, management assertions across Type 1 and Type 2 engagements, and the purpose and users of SOC 1, SOC 2, SOC 3 and SOC for Cybersecurity reports. The machinery matters here — independence across service and subservice organizations, inclusive versus carve-out methods, complementary user entity and subservice organization controls, materiality, system descriptions and their boundaries, written representations, subsequent events, and the form, content and opinion types of SOC 1 and SOC 2 examination reports.

Every practice question in the bank is tagged to one of these blueprint areas — which is how the diagnostic can name the specific concept underneath a wrong answer, not just the area it sat in.

Area names follow the AICPA's published Uniform CPA Examination Blueprints (effective January 2026), referenced for accuracy. Pinnacle is an independent adaptive learning platform. CPA is a professional designation administered by US state boards of accountancy. Pinnacle is not affiliated with, endorsed by, or connected to the AICPA, NASBA, or any US state board of accountancy.

Master ISC with adaptive practice

Fresh SOC and cybersecurity questions daily · Full explanations
Get started →

More CPA sections