CPA Exam Prep — ISC: Information Systems and Controls
Complete preparation for the ISC Discipline section, built on the 2027 AICPA blueprint.
Enrollment
Free
Enroll freeAlready a student? Student login
- Lifetime access
- Progress tracking
- Certificate from ATMF Exam Prep
About this course
Twelve lessons across the three official ISC Areas: information systems and data management; security, confidentiality and privacy; and SOC engagements — with knowledge checks after every lesson and a graded assessment at the end of each module.
What you'll learn
- Explain IT infrastructure, enterprise and accounting information systems, availability and change management.
- Apply data management concepts, including data life cycle, relational databases and data integration.
- Identify security, confidentiality and privacy regulations, standards and frameworks.
- Identify cyber threats and attacks and determine preventive, detective and corrective mitigation controls.
- Test IT security controls and respond to security incidents.
- Plan, perform and report on SOC 1, SOC 2 and SOC 3 engagements.
Course details
- Level
- advanced
- What's included
- 12 lessons
- Progress tracking
- Certificate of completion
Requirements
- Working knowledge of auditing and internal control (AUD-level).
- Plan roughly 16 hours of study for the lessons, before practice questions.
Student reviews
NewNo reviews yet — be the first once you enrol.
Curriculum
- 0185m
Lesson 1: IT Infrastructure and Enterprise/Accounting Information Systems
Core IT architecture components, cloud computing service and deployment models, cloud service provider responsibilities, COSO's view of cloud governance, ERP and accounting information systems, process improvement opportunities, and testing a business process against its documented flowchart or narrative.
- 0290m
Lesson 2: Availability and Change Management
Business resiliency, disaster recovery and business continuity planning, mirroring and replication, business impact analysis, availability measures, data backup types, change management tools and environments, conversion approaches, patch management, and testing change control policies including CI/CD.
- 0390m
Lesson 3: Data Management
Data extraction methods, data storage types and database schemas, the data life cycle, relational database integrity and normalization, examining SQL queries for relevance and completeness, integrating data from multiple sources, and investigating business process models for improvement opportunities.
- 0485m
Lesson 4: Regulations, Standards and Security Frameworks
HIPAA, GDPR, PCI DSS, NIST CSF, the NIST Privacy Framework, NIST SP 800-53, CIS Controls and COBIT 2019 — what each covers, who it applies to and how the frameworks relate to one another.
- 0585m
Lesson 5: Threats and Attacks
Threat agent classification, attack types and techniques, the stages of a cyber-attack, cybersecurity risks in cloud, IoT and mobile environments, threat modeling, and applying threat analysis to an entity's third-party connections and systems.
- 0685m
Lesson 6: Mitigation and Security Testing
Network and endpoint protection, vulnerability management, layered security, least-privilege and zero-trust, acceptable use policy, COSO-based cyber risk assessment, control selection, identification/authorization techniques, and security awareness and control-testing procedures used in a SOC 2 engagement.
- 0785m
Lesson 7: Confidentiality and Privacy Protections
Encryption fundamentals and applications, the distinction between confidentiality and privacy, methods for protecting confidential data in the system development life cycle, data loss prevention, the financial and operational impact of a data breach, controls and practices across the data life cycle, and testing confidentiality/privacy controls in a SOC 2 engagement.
- 0875m
Lesson 8: Incident Response
The distinction between security events and incidents, insurance as a risk-mitigation strategy, the common contents of an incident response plan, and procedures for testing whether an entity responded to incidents in accordance with its plan.
- 0985m
Lesson 9: SOC Engagement Foundations — Trust Services Criteria, Subject Matter and Assertions
The purpose and organization of the Trust Services Criteria; the subject matters a practitioner may be engaged on; management assertions across Type 1 and Type 2 engagements; the purpose and intended users of SOC 1, SOC 2, SOC 3 and SOC for Cybersecurity reports; independence considerations among the service auditor, service organization and subservice organizations; and how materiality is determined and used in a SOC engagement.
- 1080m
Lesson 10: Risk Assessment, Subservice Organizations and System Descriptions
Risk assessment requirements for the service organization and the service auditor; criteria for subservice organization status; the inclusive and carve-out methods and CSOCs; service commitments and system requirements; subsequently discovered facts; and the purpose and sections of a system description.
- 1180m
Lesson 11: Complementary User Entity Controls, Representations and Subsequent Events
Complementary user entity controls (CUECs); obtaining management's written representations; understanding system boundaries; procedures over incident and complaint reporting channels; comparing the description to suitable or description criteria; and determining the effect of subsequent events.
- 1285m
Lesson 12: Reporting on SOC Engagements
The effect of CUECs on the SOC report; carve-out versus inclusive reporting of CSOCs; types of opinions and report modifications for identified deficiencies; preparing results of control testing including exceptions; and the appropriate form and content of a SOC 1 or SOC 2 report.