Skip to main content
Discipline section study guide

Trace CPA ISC Risks Through Controls, Evidence, and SOC Boundaries

Prepare for CPA ISC with 2026 content weights, 82 MCQs, six TBSs, four-hour pacing, risk-control-evidence mapping, data topics, and SOC analysis.

  • No credit card required
  • 5-day free trial
  • Pass guarantee

At a glance

ISC is available as one of the three Disciplines. Its January 1, 2026 Blueprint sets a four-hour section with 82 MCQs, six simulations, and a 60-to-40 score split between those formats. Systems and Data Management and the Security, Confidentiality, and Privacy area each carry 35% to 45%; SOC engagement considerations carry 15% to 25%. Use a repeatable control chain: identify the asset and threat, state the objective, assess design, locate operating evidence, interpret exceptions, and honor the reporting boundary.

ISC exam format

Prepare for both multiple-choice decisions and task-based simulations.

Section type

Discipline

Choose one of three Disciplines

Testing time

4 hours

Plan time for all five testlets

Multiple-choice questions

82 MCQs

60% of your section score

Task-based simulations

6 TBSs

40% of your section score

What ISC covers

Connect all 3 content areas to the work you need to practice.

2026 ISC content allocation and core question
AreaAllocation
Systems, information, and data management35% to 45%
Core question: How do systems, processes, and data produce reliable information?
Security, Confidentiality and Privacy35% to 45%
Core question: Which threats matter, and how are information objectives protected?
SOC Engagement Considerations15% to 25%
Core question: What does the engagement cover, and what evidence supports the report?

Work through an example for ISC

Terminated-user risk-control-evidence board

A five-part access case that distinguishes preventive and detective controls, analyzes two exceptions, and limits the conclusion to the evidence.

Case assumptions

Assume a company requires human resources to send a termination notice to identity administration, which must disable application access within four hours. A monthly review compares terminated employees with active accounts. In a sample month, 40 employees left, two accounts remained active beyond four hours, and the reviewer documented follow-up one week later.

Step 1 of 5

Risk

Case evidence
Former employees retain active access
Required analysis
Unauthorized use could occur after termination

Choose your next step

Build your study routine

Bring lessons, videos, flashcards, and question practice together in MiloPrep.

Get Started Free

Try ISC practice questions

Work through free ISC questions and review the explanations behind your answers.

Start free practice

Find your CPA plan

Compare free access and paid plans to choose the tools that fit your routine.

Compare CPA plans

Explore the ISC study notes

Open a topic for the full explanation, worked example, or study checklist.

Evaluate ISC as a Discipline choice

After the AUD, FAR, and REG Core, the fourth section is one chosen Discipline, and ISC is one of those three choices. Evaluate fit through the representative tasks in the Blueprint effective January 1, 2026.

ISC fits work that combines systems, data, security, privacy, controls, and assurance boundaries. Familiarity with technology vocabulary is not enough. The candidate must connect a risk to a control objective, evaluate the activity and evidence, and decide what an exception means.

Run a timed sample across all three content areas. Classify errors as terminology, system flow, threat identification, control design, evidence interpretation, or engagement boundary. Compare that profile with the other Discipline choices.

ISC fit decision

  • Systems and control reasoning are strengths

    Test a mixed ISC set

    Include both selected-response and document-based tasks.

  • Vocabulary is strong but application is weak

    Measure the transfer gap

    Require risk, objective, evidence, and exception analysis.

  • Timed mixed work remains accurate

    ISC may fit

    Confirm the choice against BAR and TCP evidence.

Official sources:AICPA & CIMANASBA

Allocate study across data, security, and SOC work

The 2026 ISC Blueprint assigns 35% to 45% to Information Systems and Data Management, 35% to 45% to Security, Confidentiality and Privacy, and 15% to 25% to Considerations for System and Organization Controls Engagements.

The first area requires understanding how systems and data support processes and reporting. The second focuses on protecting information and responding to threats. The SOC area requires clear awareness of engagement purpose, criteria, responsibilities, controls, evidence, and the boundary of a report.

Use the ranges to set an initial schedule, but track task-level performance. A smaller allocation still needs coverage, particularly when unfamiliar report language or responsibility boundaries cause systematic errors.

2026 ISC content allocation and core question

AreaAllocationCore question
Systems, information, and data management35% to 45%How do systems, processes, and data produce reliable information?
Security, Confidentiality and Privacy35% to 45%Which threats matter, and how are information objectives protected?
SOC Engagement Considerations15% to 25%What does the engagement cover, and what evidence supports the report?
Official sources:AICPA & CIMANASBA

Respect the 60% MCQ and 40% TBS balance

ISC contains 82 MCQs split into two testlets of 41. Six TBSs appear across the final three testlets in a one, three, and two pattern. MCQs account for 60% of the section score, while TBSs account for 40%.

MCQs can efficiently test definitions, responsibility boundaries, risk-control relationships, and evidence conclusions. TBSs can require navigating policies, logs, diagrams, exception reports, control descriptions, or report excerpts.

The larger MCQ weight does not justify skipping TBSs. Pair a selected-response set with a case that asks you to identify a control gap, interpret evidence, or map a process to an engagement conclusion.

ISC format and score weight

  • MCQs

    82 items and 60%

    Two testlets of 41 reward accurate distinction across many concepts.

  • TBSs

    6 simulations and 40%

    Three testlets test evidence, documents, and multi-step control analysis.

  • Preparation rule

    Practice both formats

    Use the blueprint task, not score weight alone, to choose the format.

Official sources:AICPA & CIMAAICPA & CIMA

Use the asset-to-evidence control chain

Begin with the information asset, process, or service under review. State the threat or failure event in concrete terms, then connect it to an objective such as authorized access, complete processing, accurate data, availability, confidentiality, or timely recovery.

Evaluate whether the control is suitably designed to prevent, detect, or correct that event. Identify who performs it, what triggers it, the frequency, the information used, and what evidence remains after operation.

Interpret exceptions last. An exception must be connected to the control objective, affected population, period, and possible consequence. A screenshot or log is not automatically sufficient merely because it exists.

ISC control-reasoning chain

  1. Asset and process

    Define what information or service needs protection.

  2. Threat or failure

    Describe how the objective could be defeated.

  3. Control objective

    State the condition the process must maintain.

  4. Control activity

    Assess design, performer, trigger, frequency, and inputs.

  5. Evidence and exception

    Determine what operation evidence shows and what any failure means.

Official sources:AICPA & CIMANASBA

Separate design, implementation, and operation

A control description can sound appropriate without proving that it was placed into use or operated throughout the relevant period. Keep design, implementation, and operation as separate questions.

For design, ask whether the activity could address the identified risk if performed as described. For implementation, identify evidence that the control exists and has been put into use. For operation, inspect performance over the relevant population or period and evaluate exceptions.

Label the conclusion at the level the evidence supports. Do not convert one observed execution into a broad period conclusion without a defensible basis.

Three control questions need different evidence

  • Design

    Could the control meet the objective?

    Inspect the activity, performer, frequency, inputs, and response.

  • Implementation

    Was it placed into use?

    Confirm the process exists beyond a written description.

  • Operation

    Did it perform as required?

    Use period-appropriate evidence and evaluate exceptions.

Official sources:AICPA & CIMANASBA

Complete the terminated-user access case

Assume a company requires human resources to send a termination notice to identity administration, which must disable application access within four hours. A monthly review compares terminated employees with active accounts. In a sample month, 40 employees left, two accounts remained active beyond four hours, and the reviewer documented follow-up one week later.

The risk is unauthorized post-termination access. The preventive control is timely deprovisioning; the detective control is the terminated-user reconciliation. Evidence should include the population of terminations, notice timestamps, disablement timestamps, reviewer sign-off, exceptions, and remediation.

The two late accounts are not resolved by reporting the 95% timely rate. Analyze duration, access used during the gap, system sensitivity, why the primary control failed, and whether the monthly review was timely enough to meet its objective. The case conclusion must distinguish design from observed operation.

Terminated-user control and evidence board

ElementCase evidenceRequired analysis
RiskFormer employees retain active accessUnauthorized use could occur after termination
Preventive controlDisable access within four hours of noticeTest notice-to-disable timestamps
Detective controlMonthly termination-to-account reconciliationAssess population, review timing, and follow-up
Exception2 of 40 accounts disabled lateInspect duration, activity, cause, and sensitivity
ConclusionDesign and operation assessed separatelyState the level supported by the evidence
Official sources:AICPA & CIMANASBA

Rehearse the four-hour control-evidence sequence

ISC provides four hours of testing time. Set checkpoint times for the two 41-question MCQ testlets and reserve a controlled block for the six TBSs. The one-three-two distribution should be visible in practice plans.

For a TBS, read the requirement first, inventory each policy, log, diagram, description, and exception report, then create a risk-control-evidence grid. This prevents a compelling exhibit from being used for the wrong objective.

A readiness rehearsal should cover all three content areas, both item types, timed work, and at least one complete case from asset and threat through control evidence and a bounded conclusion.

  • Set end-time checkpoints for both 41-question MCQ testlets.
  • Reserve time for six TBSs in a one-three-two sequence.
  • Define the asset, threat, and objective before judging a control.
  • Separate design, implementation, and operation conclusions.
  • Map each exhibit to the specific assertion it supports.
  • State exceptions, consequence, and engagement boundary.

FAQ

Is ISC required for every CPA candidate?

No. The required Core is AUD, FAR, and REG; ISC competes with BAR and TCP for the single Discipline position in the four-section route.

How many questions are on the 2026 CPA ISC section?

ISC contains 82 MCQs in two testlets of 41 and six TBSs distributed one, three, and two across the final three testlets.

How are ISC MCQs and TBSs weighted?

MCQs account for 60% of the ISC score, while TBSs account for 40%.

What are the 2026 ISC content-area weights?

Systems and Data Management and the Security, Confidentiality, and Privacy area each carry a 35% to 45% range. SOC engagement considerations account for the remaining 15% to 25% range.

How long is the CPA ISC section?

ISC provides four hours of testing time. Practice explicit MCQ transitions and protect enough time for all six TBSs.

Put your ISC plan into practice.

Start your CPA study routine with MiloPrep.

Get Started Free
No credit card required5-day free trialPass guarantee

Source check

Official sources

This guide was researched independently from the official materials below. Requirements can vary by jurisdiction, and a newer official rule always takes priority.