Trace CPA ISC Risks Through Controls, Evidence, and SOC Boundaries
Prepare for CPA ISC with 2026 content weights, 82 MCQs, six TBSs, four-hour pacing, risk-control-evidence mapping, data topics, and SOC analysis.
- No credit card required
- 5-day free trial
- Pass guarantee
At a glance
ISC is available as one of the three Disciplines. Its January 1, 2026 Blueprint sets a four-hour section with 82 MCQs, six simulations, and a 60-to-40 score split between those formats. Systems and Data Management and the Security, Confidentiality, and Privacy area each carry 35% to 45%; SOC engagement considerations carry 15% to 25%. Use a repeatable control chain: identify the asset and threat, state the objective, assess design, locate operating evidence, interpret exceptions, and honor the reporting boundary.
ISC exam format
Prepare for both multiple-choice decisions and task-based simulations.
Section type
Discipline
Choose one of three Disciplines
Testing time
4 hours
Plan time for all five testlets
Multiple-choice questions
82 MCQs
60% of your section score
Task-based simulations
6 TBSs
40% of your section score
What ISC covers
Connect all 3 content areas to the work you need to practice.
| Area | Allocation |
|---|---|
| Systems, information, and data management | 35% to 45% |
| Core question: How do systems, processes, and data produce reliable information? | |
| Security, Confidentiality and Privacy | 35% to 45% |
| Core question: Which threats matter, and how are information objectives protected? | |
| SOC Engagement Considerations | 15% to 25% |
| Core question: What does the engagement cover, and what evidence supports the report? | |
Work through an example for ISC
Terminated-user risk-control-evidence board
A five-part access case that distinguishes preventive and detective controls, analyzes two exceptions, and limits the conclusion to the evidence.
Case assumptions
Assume a company requires human resources to send a termination notice to identity administration, which must disable application access within four hours. A monthly review compares terminated employees with active accounts. In a sample month, 40 employees left, two accounts remained active beyond four hours, and the reviewer documented follow-up one week later.
Step 1 of 5
Risk
- Case evidence
- Former employees retain active access
- Required analysis
- Unauthorized use could occur after termination
Choose your next step
Build your study routine
Bring lessons, videos, flashcards, and question practice together in MiloPrep.
Get Started FreeTry ISC practice questions
Work through free ISC questions and review the explanations behind your answers.
Start free practiceFind your CPA plan
Compare free access and paid plans to choose the tools that fit your routine.
Compare CPA plansExplore the ISC study notes
Open a topic for the full explanation, worked example, or study checklist.
Evaluate ISC as a Discipline choice
After the AUD, FAR, and REG Core, the fourth section is one chosen Discipline, and ISC is one of those three choices. Evaluate fit through the representative tasks in the Blueprint effective January 1, 2026.
ISC fits work that combines systems, data, security, privacy, controls, and assurance boundaries. Familiarity with technology vocabulary is not enough. The candidate must connect a risk to a control objective, evaluate the activity and evidence, and decide what an exception means.
Run a timed sample across all three content areas. Classify errors as terminology, system flow, threat identification, control design, evidence interpretation, or engagement boundary. Compare that profile with the other Discipline choices.
ISC fit decision
Systems and control reasoning are strengths
Test a mixed ISC set
Include both selected-response and document-based tasks.
Vocabulary is strong but application is weak
Measure the transfer gap
Require risk, objective, evidence, and exception analysis.
Timed mixed work remains accurate
ISC may fit
Confirm the choice against BAR and TCP evidence.
Allocate study across data, security, and SOC work
The 2026 ISC Blueprint assigns 35% to 45% to Information Systems and Data Management, 35% to 45% to Security, Confidentiality and Privacy, and 15% to 25% to Considerations for System and Organization Controls Engagements.
The first area requires understanding how systems and data support processes and reporting. The second focuses on protecting information and responding to threats. The SOC area requires clear awareness of engagement purpose, criteria, responsibilities, controls, evidence, and the boundary of a report.
Use the ranges to set an initial schedule, but track task-level performance. A smaller allocation still needs coverage, particularly when unfamiliar report language or responsibility boundaries cause systematic errors.
2026 ISC content allocation and core question
| Area | Allocation | Core question |
|---|---|---|
| Systems, information, and data management | 35% to 45% | How do systems, processes, and data produce reliable information? |
| Security, Confidentiality and Privacy | 35% to 45% | Which threats matter, and how are information objectives protected? |
| SOC Engagement Considerations | 15% to 25% | What does the engagement cover, and what evidence supports the report? |
Respect the 60% MCQ and 40% TBS balance
ISC contains 82 MCQs split into two testlets of 41. Six TBSs appear across the final three testlets in a one, three, and two pattern. MCQs account for 60% of the section score, while TBSs account for 40%.
MCQs can efficiently test definitions, responsibility boundaries, risk-control relationships, and evidence conclusions. TBSs can require navigating policies, logs, diagrams, exception reports, control descriptions, or report excerpts.
The larger MCQ weight does not justify skipping TBSs. Pair a selected-response set with a case that asks you to identify a control gap, interpret evidence, or map a process to an engagement conclusion.
ISC format and score weight
MCQs
82 items and 60%
Two testlets of 41 reward accurate distinction across many concepts.
TBSs
6 simulations and 40%
Three testlets test evidence, documents, and multi-step control analysis.
Preparation rule
Practice both formats
Use the blueprint task, not score weight alone, to choose the format.
Use the asset-to-evidence control chain
Begin with the information asset, process, or service under review. State the threat or failure event in concrete terms, then connect it to an objective such as authorized access, complete processing, accurate data, availability, confidentiality, or timely recovery.
Evaluate whether the control is suitably designed to prevent, detect, or correct that event. Identify who performs it, what triggers it, the frequency, the information used, and what evidence remains after operation.
Interpret exceptions last. An exception must be connected to the control objective, affected population, period, and possible consequence. A screenshot or log is not automatically sufficient merely because it exists.
ISC control-reasoning chain
Asset and process
Define what information or service needs protection.
Threat or failure
Describe how the objective could be defeated.
Control objective
State the condition the process must maintain.
Control activity
Assess design, performer, trigger, frequency, and inputs.
Evidence and exception
Determine what operation evidence shows and what any failure means.
Separate design, implementation, and operation
A control description can sound appropriate without proving that it was placed into use or operated throughout the relevant period. Keep design, implementation, and operation as separate questions.
For design, ask whether the activity could address the identified risk if performed as described. For implementation, identify evidence that the control exists and has been put into use. For operation, inspect performance over the relevant population or period and evaluate exceptions.
Label the conclusion at the level the evidence supports. Do not convert one observed execution into a broad period conclusion without a defensible basis.
Three control questions need different evidence
Design
Could the control meet the objective?
Inspect the activity, performer, frequency, inputs, and response.
Implementation
Was it placed into use?
Confirm the process exists beyond a written description.
Operation
Did it perform as required?
Use period-appropriate evidence and evaluate exceptions.
Complete the terminated-user access case
Assume a company requires human resources to send a termination notice to identity administration, which must disable application access within four hours. A monthly review compares terminated employees with active accounts. In a sample month, 40 employees left, two accounts remained active beyond four hours, and the reviewer documented follow-up one week later.
The risk is unauthorized post-termination access. The preventive control is timely deprovisioning; the detective control is the terminated-user reconciliation. Evidence should include the population of terminations, notice timestamps, disablement timestamps, reviewer sign-off, exceptions, and remediation.
The two late accounts are not resolved by reporting the 95% timely rate. Analyze duration, access used during the gap, system sensitivity, why the primary control failed, and whether the monthly review was timely enough to meet its objective. The case conclusion must distinguish design from observed operation.
Terminated-user control and evidence board
| Element | Case evidence | Required analysis |
|---|---|---|
| Risk | Former employees retain active access | Unauthorized use could occur after termination |
| Preventive control | Disable access within four hours of notice | Test notice-to-disable timestamps |
| Detective control | Monthly termination-to-account reconciliation | Assess population, review timing, and follow-up |
| Exception | 2 of 40 accounts disabled late | Inspect duration, activity, cause, and sensitivity |
| Conclusion | Design and operation assessed separately | State the level supported by the evidence |
Rehearse the four-hour control-evidence sequence
ISC provides four hours of testing time. Set checkpoint times for the two 41-question MCQ testlets and reserve a controlled block for the six TBSs. The one-three-two distribution should be visible in practice plans.
For a TBS, read the requirement first, inventory each policy, log, diagram, description, and exception report, then create a risk-control-evidence grid. This prevents a compelling exhibit from being used for the wrong objective.
A readiness rehearsal should cover all three content areas, both item types, timed work, and at least one complete case from asset and threat through control evidence and a bounded conclusion.
- Set end-time checkpoints for both 41-question MCQ testlets.
- Reserve time for six TBSs in a one-three-two sequence.
- Define the asset, threat, and objective before judging a control.
- Separate design, implementation, and operation conclusions.
- Map each exhibit to the specific assertion it supports.
- State exceptions, consequence, and engagement boundary.
FAQ
Is ISC required for every CPA candidate?
No. The required Core is AUD, FAR, and REG; ISC competes with BAR and TCP for the single Discipline position in the four-section route.
How many questions are on the 2026 CPA ISC section?
ISC contains 82 MCQs in two testlets of 41 and six TBSs distributed one, three, and two across the final three testlets.
How are ISC MCQs and TBSs weighted?
MCQs account for 60% of the ISC score, while TBSs account for 40%.
What are the 2026 ISC content-area weights?
Systems and Data Management and the Security, Confidentiality, and Privacy area each carry a 35% to 45% range. SOC engagement considerations account for the remaining 15% to 25% range.
How long is the CPA ISC section?
ISC provides four hours of testing time. Practice explicit MCQ transitions and protect enough time for all six TBSs.
Put your ISC plan into practice.
Start your CPA study routine with MiloPrep.
Get Started FreeSource check
Official sources
This guide was researched independently from the official materials below. Requirements can vary by jurisdiction, and a newer official rule always takes priority.