What CPA Information Systems and Controls actually tests
ISC is a Discipline section (choose 1 of 3: BAR, ISC, or TCP):
| Area | What it covers |
|---|---|
| IT Governance & Strategy | COBIT framework, IT risk governance |
| Information Systems Architecture | ERP, cloud computing (IaaS/PaaS/SaaS), databases, SDLC |
| Cybersecurity | CIA triad, NIST framework, cryptography, access controls |
| System and Organisation Controls (SOC) | SOC 1, SOC 2 (Trust Services Criteria), Type I vs. Type II |
| Internal Controls in IT Environment | General IT controls, application controls, CAATs |
| Business Continuity | RTO, RPO, disaster recovery planning |
| Data Analytics for Assurance | Benford's Law, exception reporting |
| Emerging Technologies | Blockchain, RPA, AI/ML in business processes |
Why the SOC 1 vs. SOC 2 distinction is worth locking down early
ISC repeatedly tests which SOC report type is appropriate for a given scenario — SOC 1 for controls relevant to a user entity's financial reporting, SOC 2 for controls relevant to security, availability, and related Trust Services Criteria. Confusing the two, or confusing Type I with Type II within either, is one of the most common ISC mistakes.
Sample question: SOC Report Types
Which SOC report type includes the auditor's opinion on the OPERATING EFFECTIVENESS of controls over a period of time, not just their design at a point in time?
A Type II report tests whether controls actually operated effectively over a defined period (e.g., 6-12 months). A Type I report (whether SOC 1 or SOC 2) only opines on whether controls were suitably designed as of a single point in time — a meaningfully lower bar of assurance.
The ISC blueprint, area by area
Pinnacle runs on a syllabus graph — named areas with explicit prerequisites, each one mapped against the AICPA's Uniform CPA Examination Blueprints effective January 2026. It is the same map the free diagnostic reasons over, not a marketing summary of it. These are the four confirmed ISC areas, and what each one covers:
Regulations, Standards & Frameworks
The rulebooks ISC tests by name: HIPAA's Security and Privacy Rules with covered entities and permitted disclosures, the GDPR's scope and six principles, PCI DSS, the NIST Cybersecurity and Privacy Frameworks with their cores, tiers and profiles, NIST SP 800-53, the CIS Controls, and COBIT 2019's governance principles and the components of a governance system.
Information Systems & Data Management
IT infrastructure from operating systems to end-user devices, cloud service and deployment models with provider responsibilities, ERP and accounting information systems, blockchain risks in financial reporting, and reconciling key business processes to their flowcharts and narratives. Availability covers disaster recovery, business continuity, backup types and recovery; change management runs from control policies through testing environments to conversion approaches; and data management spans warehouses, lakes and marts, database schemas and normalization, SQL, the data life cycle, and business process models such as data flow diagrams and BPMN.
Security, Confidentiality & Privacy
Threat agents from insiders to nation-states, and the attack catalogue — DDoS, malware, social engineering, buffer overflows, cross-site scripting, SQL injection, replay attacks — with the preventive, detective and corrective controls that mitigate them, including segmentation and VPNs for remote access. Confidentiality and privacy cover encryption, data obfuscation and tokenization, data loss prevention, and the implications of a breach; incident response covers plans, roles, timelines, insurance as mitigation, and testing the response against the plan.
SOC Engagements
Planning and performing SOC work: the Trust Services Criteria and their alignment with the COSO framework, management assertions across Type 1 and Type 2 engagements, and the purpose and users of SOC 1, SOC 2, SOC 3 and SOC for Cybersecurity reports. The machinery matters here — independence across service and subservice organizations, inclusive versus carve-out methods, complementary user entity and subservice organization controls, materiality, system descriptions and their boundaries, written representations, subsequent events, and the form, content and opinion types of SOC 1 and SOC 2 examination reports.
Every practice question in the bank is tagged to one of these blueprint areas — which is how the diagnostic can name the specific concept underneath a wrong answer, not just the area it sat in.
Area names follow the AICPA's published Uniform CPA Examination Blueprints (effective January 2026), referenced for accuracy. Pinnacle is an independent adaptive learning platform. CPA is a professional designation administered by US state boards of accountancy. Pinnacle is not affiliated with, endorsed by, or connected to the AICPA, NASBA, or any US state board of accountancy.