# CPA ISC Study Plan — Information Systems and Controls (Discipline)

CPA ISC Discipline study plan aligned to the 2026 AICPA Blueprint. IT systems, security, privacy, SOC engagements. For IT audit and advisory paths.

Canonical URL: https://exclam.ai/cpa/isc/

[CPA](https://exclam.ai/cpa/index.md)›ISC

ISC·discipline

Updated August 2026

CPA ISC (Information Systems and Controls) is the IT-focused Discipline section. Best for candidates pursuing IT audit, cybersecurity, or technology advisory. Upload your study materials and exclam.ai builds a fully guided plan.

Typical prep

~130h

Timeline

~10w

Areas

3

Type

discipline

[Back to CPA hub](https://exclam.ai/cpa/index.md)

[ISC in 30 days? Retaking this section or behind schedule — see the cram plan + retaker advice. See cram options](https://exclam.ai/cpa/isc/cram/index.md) [2026 CPA Blueprints + 30-month credit window. What changed, what didn't, plus the policy update affecting your credit timer. See 2026 changes](https://exclam.ai/cpa/changes-2026/index.md)

## Exam format

4 hours. 82 MCQs and 6 TBSs. Scored 60% MCQs / 40% TBSs. Passing score: 75.

## ISC areas (AICPA Blueprint)

The 3 areas tested on ISC, with approximate weights from the 2026 AICPA Blueprint. Each area is broken into groups, topics, and representative tasks in the full Blueprint PDF.

1

### Information Systems and Data Management

35–45%

IT infrastructure, business processes, data management, and emerging technologies in accounting systems.

Key topics

- •IT infrastructure (hardware, software, networks)
- •System development lifecycle (SDLC)
- •Business process understanding
- •Data lifecycle (collection, storage, processing, analysis)
- •Data governance and quality
- •Database concepts (relational, NoSQL)
- •Emerging technologies (AI, blockchain, RPA)
- •Cloud computing concepts

2

### Security, Confidentiality, and Privacy

35–45%

Information security frameworks, access controls, encryption, incident response, and privacy regulations.

Key topics

- •Security frameworks (NIST, ISO 27001, COBIT)
- •Access controls (authentication, authorization)
- •Encryption concepts
- •Network security (firewalls, IDS/IPS)
- •Incident response and business continuity
- •Privacy regulations (GDPR, CCPA, HIPAA)
- •Risk assessment methodologies
- •Third-party risk management

3

### Considerations for System and Organization Controls (SOC) Engagements

15–25%

SOC 1, SOC 2, and SOC 3 engagements: planning, performing, and reporting on controls at service organizations.

Key topics

- •SOC 1 (Type 1 and Type 2) engagements
- •SOC 2 Trust Services Criteria
- •SOC 3 reports
- •Complementary user entity controls
- •Subservice organizations
- •Risk assessment for service organizations
- •Testing controls at service organizations
- •SOC report drafting

## Bloom's skill-level distribution

The AICPA Blueprint specifies what percentage of ISC tests each Bloom's skill level. Use this to calibrate how much pure memorization vs application vs analysis practice you need.

| Skill level | Weight |
| --- | --- |
| Remembering and Understanding | 55–65% |
| Application | 20–30% |
| Analysis | 10–20% |

## How exclam.ai helps with ISC

### Area-weighted flashcards

Upload your ISC review notes and exclam.ai generates flashcards weighted by area percentages. Heavy areas get more cards; light areas get proportionally fewer.

### Skill-level-tuned quizzes

If ISC is Application and Analysis heavy, quizzes generate accordingly — not just pure recall drills.

### Adaptive review across sections

exclam.ai remembers what you know from FAR when you start AUD. Concepts that overlap (ratios, internal control) don't restart from zero.

## Popular ISC review courses

exclam.ai works alongside any of these review courses. Upload your session notes, we don't reproduce or redistribute commercial review content.

Becker

Upload your notes

Wiley/UWorld

Upload your notes

Gleim

Upload your notes

Surgent

Upload your notes

## ISC study plan

One adaptive CPA study plan with a built-in timeline toggle — pick a 6-, 8-, 12-, 16-, or 20-week window and the schedule recomputes for your section and exam date.

[Open the CPA study plan](https://exclam.ai/cpa/index.md)

## Other Discipline sections

[BAR Business Analysis and Reporting 3 areas · ~150h](https://exclam.ai/cpa/bar/index.md)

[TCP Tax Compliance and Planning 3 areas · ~130h](https://exclam.ai/cpa/tcp/index.md)

## ISC questions

How technical is ISC?

Moderately technical but not deeply so. You need to understand IT infrastructure concepts, security frameworks (NIST, ISO, COBIT), and SOC engagements at a practical level. No programming or deep network security required. Most CPAs without IT backgrounds pass with focused prep.

Who should pick ISC over BAR or TCP?

Candidates targeting IT audit, SOC practice, cybersecurity consulting, or tech advisory roles. Big 4 IT audit practices often prefer ISC candidates. If you have any IT background, ISC is typically the easiest Discipline to pass.

Does ISC include privacy regulations like GDPR?

Yes. Privacy regulations (GDPR, CCPA, HIPAA) are part of the Security, Confidentiality, and Privacy area. Focus on high-level requirements and CPA responsibilities — not deep legal analysis.
