🇺🇸 Certified Public Accountant (CPA) · subject

Certified Public Accountant (CPA) Information Systems and Controls (ISC) — Discipline Syllabus

Every chapter and topic of Information Systems and Controls (ISC) — Discipline examined in Certified Public Accountant (CPA) — 4 chapters, 19 topics and 9 sub-topics, plus 70 flashcards written against it.

4Chapters
19Topics
9Sub-topics
~15hEst. first pass
13%Of Certified Public Accountant (CPA)
70Flashcards

Information Systems and Controls (ISC) — Discipline syllabus — full chapter and topic list

Expand any chapter to see its topics and sub-topics. This is the whole examinable outline for Information Systems and Controls (ISC) — Discipline in Certified Public Accountant (CPA), not a summary of it.

  1. Information Systems and Data Management

    5 topics
    • IT infrastructure and architecture
      • Networks, databases, and operating systems
      • Cloud computing and hosting models
    • The system development life cycle (SDLC)
    • Data governance and data quality
    • Data lifecycle — capture, storage, and disposal
    • Enterprise resource planning systems
  2. Security, Confidentiality, and Privacy

    5 topics
    • Information security frameworks and principles
    • Access controls and identity management
      • Authentication and authorization
      • Segregation of duties in IT
    • Threats, vulnerabilities, and attack vectors
    • Privacy regulations and data protection
    • Incident response and business continuity
  3. IT General and Application Controls

    4 topics
    • IT general controls (ITGCs)
      • Change management controls
      • Logical and physical access controls
      • IT operations and backup controls
    • Application and automated controls
    • Testing the design and operating effectiveness of controls
    • Evaluating control deficiencies in IT
  4. SOC Engagements and Reporting on Controls

    5 topics
    • SOC 1 engagements for service organizations
    • SOC 2 and the trust services criteria
      • Security, availability, and processing integrity
      • Confidentiality and privacy criteria
    • Type 1 versus Type 2 reports
    • Complementary user entity and subservice controls
    • Roles of service auditor and user auditor

Information Systems and Controls (ISC) — Discipline flashcards for Certified Public Accountant (CPA)

22 of 70 cards from the Information Systems and Controls (ISC) — Discipline deck — real questions with worked answers.

  1. What are the three layers commonly used to describe IT infrastructure?

    Hardware (physical devices), software (operating systems and applications), and networks/communications. Together they form the foundation that supports an organization's information systems and data.

  2. Define IT architecture and distinguish it from IT infrastructure.

    IT architecture is the structured design/blueprint describing how hardware, software, networks, data, and people are organized and interact to meet business goals. Infrastructure is the actual physical and virtual components; architecture is the design framework governing them.

  3. Compare on-premises, cloud, and hybrid deployment models.

    On-premises: organization owns/operates hardware in-house (max control, high cost). Cloud: resources delivered over the internet by a provider (scalable, OpEx). Hybrid: a mix of on-premises and cloud, balancing control and flexibility.

  4. Name the three primary cloud service models and what the customer manages in each.

    IaaS (Infrastructure as a Service) — customer manages OS, apps, data. PaaS (Platform as a Service) — customer manages apps and data only. SaaS (Software as a Service) — customer manages only data/configuration; provider runs everything else.

  5. List the typical phases of the System Development Life Cycle (SDLC) in order.

    1) Planning/initiation, 2) Analysis (requirements), 3) Design, 4) Development (build/coding), 5) Testing, 6) Implementation/deployment, 7) Operations and maintenance (and eventual disposal).

  6. Contrast the Waterfall and Agile SDLC methodologies.

    Waterfall: sequential, each phase completed before the next, rigid, good for stable requirements. Agile: iterative, incremental sprints with continuous feedback, flexible, good for evolving requirements.

  7. What is the purpose of the testing phase in the SDLC, and name common test types?

    To verify the system meets requirements and is defect-free before release. Types: unit testing, integration testing, system testing, user acceptance testing (UAT), and regression testing.

  8. Why should segregation of duties be maintained between developers and the production environment in the SDLC?

    To prevent a developer from introducing unauthorized or malicious code directly into production. Migration to production should be performed by independent personnel, supporting change management ITGCs.

  9. Define data governance.

    The overall framework of policies, processes, roles, and standards ensuring that data is managed as an asset — covering data quality, security, availability, and usability across its lifecycle.

  10. List the key dimensions of data quality.

    Accuracy, completeness, consistency, timeliness, validity, and uniqueness (non-duplication). High-quality data conforms to these dimensions for reliable decision-making.

  11. What is the role of a data steward versus a data owner in data governance?

    Data owner: accountable executive who defines access and usage policies for a data domain. Data steward: operational role responsible for day-to-day data quality, definitions, and enforcing governance standards.

  12. Define master data and reference data.

    Master data: core business entities shared across systems (customers, vendors, products). Reference data: standardized code sets used to classify other data (country codes, currency codes, account types).

  13. List the stages of the data lifecycle.

    Capture/creation, storage, usage/processing, sharing, archival, and disposal/destruction. Controls should protect data appropriately at each stage.

  14. Distinguish data at rest, data in transit, and data in use.

    Data at rest: stored data (disks, databases) — protect with encryption. Data in transit: data moving across networks — protect with TLS/encryption. Data in use: data actively processed in memory — protect with access controls and secure processing.

  15. What is data disposal and why is secure disposal important?

    Disposal is the final lifecycle stage where data no longer needed is destroyed. Secure disposal (wiping, degaussing, shredding) prevents recovery of sensitive data, satisfying privacy laws and retention policies.

  16. Differentiate a data retention policy from a data destruction policy.

    Retention policy specifies how long data must be kept (for legal/business reasons). Destruction policy specifies how and when data is securely eliminated once retention requirements end.

  17. Define an Enterprise Resource Planning (ERP) system.

    An integrated suite of applications using a centralized database that supports core business processes (finance, HR, supply chain, manufacturing, sales) in real time across the organization.

  18. What are the main benefits and risks of an ERP system?

    Benefits: single source of truth, integrated processes, real-time reporting, efficiency. Risks: high cost/complexity, implementation failure, over-reliance on the vendor, and concentration of risk (single point of failure).

  19. Why is configuring segregation of duties critical in an ERP system?

    ERP integration means one user could control an entire transaction cycle. Role-based access and SoD configuration prevent incompatible duties (e.g., creating a vendor and approving its payment), reducing fraud risk.

  20. Name three widely used information security frameworks.

    NIST Cybersecurity Framework (CSF), ISO/IEC 27001/27002, and COBIT. The CIS Critical Security Controls are also commonly referenced.

  21. State the CIA triad and define each component.

    Confidentiality — data accessible only to authorized parties. Integrity — data is accurate and unaltered. Availability — data and systems are accessible when needed. The CIA triad is the foundation of information security.

  22. List the five core functions of the NIST Cybersecurity Framework.

    Identify, Protect, Detect, Respond, and Recover. (NIST CSF 2.0 adds a sixth function, Govern.) They provide a lifecycle approach to managing cybersecurity risk.

See more Information Systems and Controls (ISC) — Discipline flashcards →

Planning Information Systems and Controls (ISC) — Discipline for Certified Public Accountant (CPA)

Information Systems and Controls (ISC) — Discipline is about 13% of the Certified Public Accountant (CPA) syllabus by topic count — 19 of 142 topics, spread over 4 chapters. At roughly 45 minutes per topic plus 12 minutes per sub-topic, a first pass runs to about 15 hours.

The heaviest chapters are Information Systems and Data Management (5 topics), Security, Confidentiality, and Privacy (5 topics), SOC Engagements and Reporting on Controls (5 topics) . Front-load those while your energy is high; the short chapters are better revision filler later.

Work top-down: read the chapter, then tick topics off individually rather than marking the whole chapter done. Sub-topics are where silent gaps hide.

Information Systems and Controls (ISC) — Discipline (Certified Public Accountant (CPA)) FAQ

What is in the Certified Public Accountant (CPA) Information Systems and Controls (ISC) — Discipline syllabus?

Information Systems and Controls (ISC) — Discipline is split into 4 chapters — Information Systems and Data Management, Security, Confidentiality, and Privacy, IT General and Application Controls and SOC Engagements and Reporting on Controls, containing 19 topics and 9 sub-topics in total.

How many chapters are there in Information Systems and Controls (ISC) — Discipline for Certified Public Accountant (CPA)?

4 chapters. Information Systems and Controls (ISC) — Discipline accounts for about 13% of the topics in the whole Certified Public Accountant (CPA) syllabus (19 of 142).

How long should I spend on Information Systems and Controls (ISC) — Discipline for Certified Public Accountant (CPA)?

Budget around 15 hours for a first pass through Information Systems and Controls (ISC) — Discipline — about 45 minutes per topic plus 12 minutes per sub-topic across its 19 topics. Add revision cycles on top.

Are there flashcards for Certified Public Accountant (CPA) Information Systems and Controls (ISC) — Discipline?

Yes — a 70-card Information Systems and Controls (ISC) — Discipline deck. Sample cards are printed on this page, and the full deck is free in the Examius app with spaced repetition scheduling.