All ATMF Exam Prep courses

CPA Exam Prep — ISC: Information Systems and Controls

Complete preparation for the ISC Discipline section, built on the 2027 AICPA blueprint.

advanced
16h 50m12 lessons

Enrollment

Free

Enroll free

Already a student? Student login

  • Lifetime access
  • Progress tracking
  • Certificate from ATMF Exam Prep

About this course

Twelve lessons across the three official ISC Areas: information systems and data management; security, confidentiality and privacy; and SOC engagements — with knowledge checks after every lesson and a graded assessment at the end of each module.

What you'll learn

  • Explain IT infrastructure, enterprise and accounting information systems, availability and change management.
  • Apply data management concepts, including data life cycle, relational databases and data integration.
  • Identify security, confidentiality and privacy regulations, standards and frameworks.
  • Identify cyber threats and attacks and determine preventive, detective and corrective mitigation controls.
  • Test IT security controls and respond to security incidents.
  • Plan, perform and report on SOC 1, SOC 2 and SOC 3 engagements.

Course details

Level
advanced
What's included
  • 12 lessons
  • Progress tracking
  • Certificate of completion

Requirements

  • Working knowledge of auditing and internal control (AUD-level).
  • Plan roughly 16 hours of study for the lessons, before practice questions.

Student reviews

New

No reviews yet — be the first once you enrol.

Curriculum

  1. 01

    Lesson 1: IT Infrastructure and Enterprise/Accounting Information Systems

    Core IT architecture components, cloud computing service and deployment models, cloud service provider responsibilities, COSO's view of cloud governance, ERP and accounting information systems, process improvement opportunities, and testing a business process against its documented flowchart or narrative.

    85m
  2. 02

    Lesson 2: Availability and Change Management

    Business resiliency, disaster recovery and business continuity planning, mirroring and replication, business impact analysis, availability measures, data backup types, change management tools and environments, conversion approaches, patch management, and testing change control policies including CI/CD.

    90m
  3. 03

    Lesson 3: Data Management

    Data extraction methods, data storage types and database schemas, the data life cycle, relational database integrity and normalization, examining SQL queries for relevance and completeness, integrating data from multiple sources, and investigating business process models for improvement opportunities.

    90m
  4. 04

    Lesson 4: Regulations, Standards and Security Frameworks

    HIPAA, GDPR, PCI DSS, NIST CSF, the NIST Privacy Framework, NIST SP 800-53, CIS Controls and COBIT 2019 — what each covers, who it applies to and how the frameworks relate to one another.

    85m
  5. 05

    Lesson 5: Threats and Attacks

    Threat agent classification, attack types and techniques, the stages of a cyber-attack, cybersecurity risks in cloud, IoT and mobile environments, threat modeling, and applying threat analysis to an entity's third-party connections and systems.

    85m
  6. 06

    Lesson 6: Mitigation and Security Testing

    Network and endpoint protection, vulnerability management, layered security, least-privilege and zero-trust, acceptable use policy, COSO-based cyber risk assessment, control selection, identification/authorization techniques, and security awareness and control-testing procedures used in a SOC 2 engagement.

    85m
  7. 07

    Lesson 7: Confidentiality and Privacy Protections

    Encryption fundamentals and applications, the distinction between confidentiality and privacy, methods for protecting confidential data in the system development life cycle, data loss prevention, the financial and operational impact of a data breach, controls and practices across the data life cycle, and testing confidentiality/privacy controls in a SOC 2 engagement.

    85m
  8. 08

    Lesson 8: Incident Response

    The distinction between security events and incidents, insurance as a risk-mitigation strategy, the common contents of an incident response plan, and procedures for testing whether an entity responded to incidents in accordance with its plan.

    75m
  9. 09

    Lesson 9: SOC Engagement Foundations — Trust Services Criteria, Subject Matter and Assertions

    The purpose and organization of the Trust Services Criteria; the subject matters a practitioner may be engaged on; management assertions across Type 1 and Type 2 engagements; the purpose and intended users of SOC 1, SOC 2, SOC 3 and SOC for Cybersecurity reports; independence considerations among the service auditor, service organization and subservice organizations; and how materiality is determined and used in a SOC engagement.

    85m
  10. 10

    Lesson 10: Risk Assessment, Subservice Organizations and System Descriptions

    Risk assessment requirements for the service organization and the service auditor; criteria for subservice organization status; the inclusive and carve-out methods and CSOCs; service commitments and system requirements; subsequently discovered facts; and the purpose and sections of a system description.

    80m
  11. 11

    Lesson 11: Complementary User Entity Controls, Representations and Subsequent Events

    Complementary user entity controls (CUECs); obtaining management's written representations; understanding system boundaries; procedures over incident and complaint reporting channels; comparing the description to suitable or description criteria; and determining the effect of subsequent events.

    80m
  12. 12

    Lesson 12: Reporting on SOC Engagements

    The effect of CUECs on the SOC report; carve-out versus inclusive reporting of CSOCs; types of opinions and report modifications for identified deficiencies; preparing results of control testing including exceptions; and the appropriate form and content of a SOC 1 or SOC 2 report.

    85m