CPA Information Systems and Controls: IT risk meets assurance

Information Systems and Controls (ISC) is one of the 3 Discipline sections — IT governance, cybersecurity, and the SOC reporting framework, for candidates heading toward IT audit or advisory work. Here's the full breakdown, plus a worked SOC report example.

Practice fresh ISC questions daily

No credit card required · FSRS scheduling · AI tutor included
Get started →

What CPA Information Systems and Controls actually tests

ISC is a Discipline section (choose 1 of 3: BAR, ISC, or TCP):

AreaWhat it covers
IT Governance & StrategyCOBIT framework, IT risk governance
Information Systems ArchitectureERP, cloud computing (IaaS/PaaS/SaaS), databases, SDLC
CybersecurityCIA triad, NIST framework, cryptography, access controls
System and Organisation Controls (SOC)SOC 1, SOC 2 (Trust Services Criteria), Type I vs. Type II
Internal Controls in IT EnvironmentGeneral IT controls, application controls, CAATs
Business ContinuityRTO, RPO, disaster recovery planning
Data Analytics for AssuranceBenford's Law, exception reporting
Emerging TechnologiesBlockchain, RPA, AI/ML in business processes

Why the SOC 1 vs. SOC 2 distinction is worth locking down early

ISC repeatedly tests which SOC report type is appropriate for a given scenario — SOC 1 for controls relevant to a user entity's financial reporting, SOC 2 for controls relevant to security, availability, and related Trust Services Criteria. Confusing the two, or confusing Type I with Type II within either, is one of the most common ISC mistakes.

Sample question: SOC Report Types

Information Systems and Controls · Easy-medium difficulty

Which SOC report type includes the auditor's opinion on the OPERATING EFFECTIVENESS of controls over a period of time, not just their design at a point in time?

A. SOC 1 Type I
B. SOC 2 Type I
C. SOC 2 Type II
D. SOC 3
The correct answer is C — SOC 2 Type II.
A Type II report tests whether controls actually operated effectively over a defined period (e.g., 6-12 months). A Type I report (whether SOC 1 or SOC 2) only opines on whether controls were suitably designed as of a single point in time — a meaningfully lower bar of assurance.

Master ISC with adaptive practice

Fresh SOC and cybersecurity questions daily · Full explanations · No card needed
Get started →

More CPA sections