CPA ISC (Information Systems and Controls) is the IT-focused Discipline section. Best for candidates pursuing IT audit, cybersecurity, or technology advisory. Upload your study materials and exclam.ai builds a fully guided plan.
4 hours. 82 MCQs and 6 TBSs. Scored 60% MCQs / 40% TBSs. Passing score: 75.
The 3 areas tested on ISC, with approximate weights from the 2026 AICPA Blueprint. Each area is broken into groups, topics, and representative tasks in the full Blueprint PDF.
IT infrastructure, business processes, data management, and emerging technologies in accounting systems.
Information security frameworks, access controls, encryption, incident response, and privacy regulations.
SOC 1, SOC 2, and SOC 3 engagements: planning, performing, and reporting on controls at service organizations.
The AICPA Blueprint specifies what percentage of ISC tests each Bloom's skill level. Use this to calibrate how much pure memorization vs application vs analysis practice you need.
| Skill level | Weight |
|---|---|
| Remembering and Understanding | 55–65% |
| Application | 20–30% |
| Analysis | 10–20% |
Upload your ISC review notes and exclam.ai generates flashcards weighted by area percentages. Heavy areas get more cards; light areas get proportionally fewer.
If ISC is Application and Analysis heavy, quizzes generate accordingly — not just pure recall drills.
exclam.ai remembers what you know from FAR when you start AUD. Concepts that overlap (ratios, internal control) don't restart from zero.
exclam.ai works alongside any of these review courses. Upload your session notes — we don't reproduce or redistribute commercial review content.
Moderately technical but not deeply so. You need to understand IT infrastructure concepts, security frameworks (NIST, ISO, COBIT), and SOC engagements at a practical level. No programming or deep network security required. Most CPAs without IT backgrounds pass with focused prep.
Candidates targeting IT audit, SOC practice, cybersecurity consulting, or tech advisory roles. Big 4 IT audit practices often prefer ISC candidates. If you have any IT background, ISC is typically the easiest Discipline to pass.
Yes. Privacy regulations (GDPR, CCPA, HIPAA) are part of the Security, Confidentiality, and Privacy area. Focus on high-level requirements and CPA responsibilities — not deep legal analysis.
Upload your review course notes and exclam.ai builds a fully guided plan aligned to the AICPA Blueprint.