What CPA Information Systems and Controls actually tests
ISC is a Discipline section (choose 1 of 3: BAR, ISC, or TCP):
| Area | What it covers |
|---|---|
| IT Governance & Strategy | COBIT framework, IT risk governance |
| Information Systems Architecture | ERP, cloud computing (IaaS/PaaS/SaaS), databases, SDLC |
| Cybersecurity | CIA triad, NIST framework, cryptography, access controls |
| System and Organisation Controls (SOC) | SOC 1, SOC 2 (Trust Services Criteria), Type I vs. Type II |
| Internal Controls in IT Environment | General IT controls, application controls, CAATs |
| Business Continuity | RTO, RPO, disaster recovery planning |
| Data Analytics for Assurance | Benford's Law, exception reporting |
| Emerging Technologies | Blockchain, RPA, AI/ML in business processes |
Why the SOC 1 vs. SOC 2 distinction is worth locking down early
ISC repeatedly tests which SOC report type is appropriate for a given scenario — SOC 1 for controls relevant to a user entity's financial reporting, SOC 2 for controls relevant to security, availability, and related Trust Services Criteria. Confusing the two, or confusing Type I with Type II within either, is one of the most common ISC mistakes.
Sample question: SOC Report Types
Which SOC report type includes the auditor's opinion on the OPERATING EFFECTIVENESS of controls over a period of time, not just their design at a point in time?
A Type II report tests whether controls actually operated effectively over a defined period (e.g., 6-12 months). A Type I report (whether SOC 1 or SOC 2) only opines on whether controls were suitably designed as of a single point in time — a meaningfully lower bar of assurance.