🇺🇸 Certified Public Accountant (CPA) · flashcards
Certified Public Accountant (CPA) Information Systems and Controls (ISC) — Discipline Flashcards
70 question-and-answer cards covering Information Systems and Controls (ISC) — Discipline as it is examined in Certified Public Accountant (CPA). 24 of them are printed below, taken from across the deck — no signup, no paywall on the preview.
24 sample cards from the Information Systems and Controls (ISC) — Discipline deck
Sampled from the end of the deck, so these are different cards from the ones shown on the syllabus page.
Classify the three types of application controls by transaction stage.
Input controls (validation, edit checks at data entry), processing controls (ensuring accurate computation/updating), and output controls (ensuring complete, accurate, authorized distribution of results).
What is an automated control versus a manual control, and what is a key advantage of automated controls?
Automated controls are performed by the system without human intervention; manual controls require people. Automated controls are consistent and reliable — if designed properly and ITGCs are effective, a single test of one instance ('benchmarking') may suffice.
Distinguish testing the design effectiveness from testing the operating effectiveness of a control.
Design effectiveness: whether the control, if operating as intended, would prevent or detect material misstatements. Operating effectiveness: whether the control actually operated as designed over the period (consistently, by authorized persons).
List common procedures for testing operating effectiveness of controls, from least to most persuasive.
Inquiry (least persuasive), observation, inspection/examination of evidence, and reperformance (most persuasive). Inquiry alone is never sufficient to test operating effectiveness.
How does the frequency of a control affect the auditor's sample size?
Generally, the more frequently a control operates, the larger the sample needed. For example, a control operating many times daily requires a larger sample than an annually performed control (which may need a sample of one).
Differentiate a control deficiency, a significant deficiency, and a material weakness.
Control deficiency: control fails to prevent/detect misstatements timely. Significant deficiency: important enough to merit attention by those charged with governance. Material weakness: reasonable possibility of a material misstatement not being prevented/detected.
When evaluating an IT control deficiency, what two factors determine its severity?
The likelihood (could a misstatement occur?) and the magnitude/potential impact (how large could the misstatement be?). Compensating controls may reduce the severity of an identified deficiency.
What is a compensating control?
An alternative control that mitigates the risk created by a deficient or missing primary control. It can reduce the severity of a deficiency but must be evaluated for its own effectiveness.
What does a SOC 1 engagement report on, and under what standard?
A SOC 1 reports on a service organization's controls relevant to a user entity's internal control over financial reporting (ICFR). It is performed under SSAE 18 (AT-C section 320).
Who are the intended users of a SOC 1 report?
Restricted-use report: management of the service organization, user entities (customers), and the user entities' auditors. It is not for general public distribution.
What does a SOC 2 report address, and to whom is it provided?
SOC 2 reports on controls relevant to the Trust Services Criteria (security, availability, processing integrity, confidentiality, privacy). It is a restricted-use report for knowledgeable parties (customers, regulators, partners).
List the five Trust Services Criteria categories used in SOC 2.
Security (the only mandatory/common criteria), Availability, Processing Integrity, Confidentiality, and Privacy. The service organization selects which apply beyond Security.
Which Trust Services Criterion is always included in a SOC 2 engagement?
Security (also called the 'common criteria'). The other four (availability, processing integrity, confidentiality, privacy) are optional and selected based on the services provided and user needs.
Contrast SOC 2 with SOC 3 reports.
Both use the Trust Services Criteria, but SOC 2 is a detailed, restricted-use report (includes the auditor's tests and results). SOC 3 is a short, general-use report suitable for public distribution (no detailed test results).
Distinguish a Type 1 from a Type 2 SOC report.
Type 1: reports on the fairness of the description and suitability of control design at a point in time. Type 2: also tests and reports on the operating effectiveness of controls over a period of time (typically 6–12 months).
Why does a user auditor generally prefer a Type 2 over a Type 1 SOC report?
A Type 2 provides evidence that controls operated effectively over a period, which the user auditor can use to reduce control risk. A Type 1 only covers design at a point in time and gives no operating-effectiveness assurance.
What are complementary user entity controls (CUECs)?
Controls the service organization assumes the user entity (customer) will implement for the service organization's controls to achieve the control objectives/criteria. The user entity is responsible for these, and the user auditor must consider them.
What is a subservice organization, and what are the two methods of addressing it in a SOC report?
A subservice organization is a vendor used by the service organization to perform some services. The two methods: the inclusive method (subservice controls described/tested in the report) and the carve-out method (subservice excluded, relying on CSOCs).
Define complementary subservice organization controls (CSOCs).
Under the carve-out method, CSOCs are controls the service organization assumes the subservice organization has implemented (and excludes from its own report) that are necessary to meet the control objectives or trust services criteria.
What is the difference between the inclusive and carve-out methods for subservice organizations?
Inclusive method: the subservice organization's relevant controls are described and tested within the service organization's SOC report. Carve-out method: those controls are excluded from the description and testing, with reliance placed on CSOCs.
Define encryption and contrast symmetric with asymmetric encryption.
Encryption converts plaintext into unreadable ciphertext using a key. Symmetric: same key encrypts and decrypts (fast, key-distribution challenge). Asymmetric: a public/private key pair (public encrypts, private decrypts) enabling secure exchange and digital signatures.
What is a firewall and how does it differ from an intrusion detection system (IDS)?
A firewall filters and controls network traffic based on rules (preventive). An IDS monitors traffic and alerts on suspicious activity (detective). An IPS (intrusion prevention system) can also actively block detected threats.
What is change management and what are its key control steps?
A formal ITGC process for controlling modifications to systems. Key steps: request and authorization, testing in a non-production environment, approval, and controlled migration to production by independent personnel — with documentation throughout.
What is a business impact analysis (BIA) in continuity planning?
A BIA identifies critical business functions and processes, the impact of their disruption over time, and recovery priorities. It drives the setting of RTOs and RPOs and the allocation of recovery resources.
What this deck covers
The Information Systems and Controls (ISC) — Discipline deck follows the Certified Public Accountant (CPA) Information Systems and Controls (ISC) — Discipline syllabus — 4 chapters and 19 topics — so questions land on material that is genuinely examinable rather than trivia around it. That works out to roughly 17.5 cards per chapter.
Answers are written to be recallable, not just readable — averaging about 222 characters, which is long enough to carry the reasoning and short enough to say out loud.
A deck like this earns its keep on the second and third pass. Read the syllabus first so you know the shape of the subject, then use the cards to find the specific facts that have not stuck.
Information Systems and Controls (ISC) — Discipline flashcards FAQ
How many Information Systems and Controls (ISC) — Discipline flashcards are in this Certified Public Accountant (CPA) deck?
70 cards. This page previews 24 of them, sampled evenly across the deck so you can judge the difficulty before installing anything.
Are these Certified Public Accountant (CPA) flashcards free?
Yes. The preview here is free to read with no signup, and the full 70-card deck is free inside the Examius app.
What do the Information Systems and Controls (ISC) — Discipline cards cover?
They follow the Certified Public Accountant (CPA) Information Systems and Controls (ISC) — Discipline syllabus — 4 chapters and 19 topics — so the questions track what is actually examinable.
How should I use these flashcards?
Read the syllabus first so you know the shape of the subject, then drill the deck. Examius schedules each card with spaced repetition, so cards you keep missing come back sooner and ones you know drift further apart.