CPA Evolution ISC Cram Cheat Sheet
Master the most heavily tested IT controls, cybersecurity architectures, SOC engagement rules, and attestation standards on the CPA Evolution ISC discipline exam. Structured into 6 high-yield tables with exam traps and pro tips.
SOC 1 vs. SOC 2 vs. SOC 3 Master Comparison Matrix
SOC Standards Core| Report Type | Governing Standard | Core Subject Matter / Scope | Intended Audience & Distribution | Detailed Testing Disclosed? |
|---|---|---|---|---|
| SOC 1 | SSAE No. 18 (AT-C 320) | Internal Control over Financial Reporting (ICFR). Focuses on transactions affecting general ledgers. | Restricted Use: User entity management, user entity financial statement auditors. | Yes (Type 2 details all controls, tests, and results). |
| SOC 2 | SSAE 18 (AT-C 105/205) + TSP Section 100 | Trust Services Criteria (Security mandatory; Availability, Processing Integrity, Confidentiality, Privacy optional). | Restricted Use: Management, existing customers, regulators, prospective customers under NDA. | Yes (Type 2 details all controls, tests, and results). |
| SOC 3 | SSAE 18 (AT-C 105/205) + TSP Section 100 | Trust Services Criteria (same criteria as SOC 2). | General Use: Unrestricted public distribution. Used for marketing, websites, seal display. | No (Summary report only; omits detailed test descriptions and results). |
| SOC for Cybersecurity | AICPA Cybersecurity Framework | Enterprise-wide cybersecurity risk management program (broad entity-level governance). | General or Specified Use: Board of directors, audit committees, investors, business partners. | No (Reports on program description and control criteria effectiveness). |
💡 CPA ISC Pro Tip: On the CPA ISC exam, if the outsourced system impacts the user entity's general ledger, balance sheet, or financial statements (e.g. payroll, loan servicing), choose SOC 1. If it involves technology, cloud hosting, SaaS, or data privacy without direct ICFR impact, choose SOC 2.
SOC Type 1 vs. Type 2 Examination Standards
Attestation Types| Attribute | Type 1 Examination | Type 2 Examination | Audit Impact / Practical Value |
|---|---|---|---|
| Time Horizon | As of a specific point in time (e.g., as of September 30). | Throughout a specified period of time (minimum 6 months, typically 12 months). | Type 2 provides longitudinal assurance that controls operated continuously over time. |
| Suitability of Design | Tested and reported. | Tested and reported. | Both evaluate whether controls are designed appropriately to achieve criteria. |
| Operating Effectiveness | NOT tested or reported. | TESTED and reported in detail. | Type 1 provides ZERO evidence of operating effectiveness. External auditors require Type 2. |
| Testing Procedures | Inquiry, inspection of design documents, walkthrough of one transaction. | Inquiry, observation, inspection of samples throughout period, and reperformance. | Inquiry alone is NEVER sufficient in a Type 2 examination. |
| Bridge / Gap Letters | Not applicable (point in time). | Applicable (covers gap between period-end and user's fiscal year-end, max 3 months). | Bridge letters are signed by service organization management, NOT the CPA firm. |
💡 CPA ISC Pro Tip: Remember that a Type 1 report cannot be used by financial statement auditors to reduce control risk below maximum because operating effectiveness was never tested.
AICPA Trust Services Criteria (TSC) 5 Categories
Trust Services Core| TSC Category | Code Series | Mandatory or Optional? | Core Objective / Scope | Key Control Focus Areas |
|---|---|---|---|---|
| Security (Common Criteria) | CC1.1 – CC9.2 | MANDATORY in all SOC 2 reports | Information and systems are protected against unauthorized access, unauthorized disclosure, and damage. | COSO 17 principles, logical access (MFA/IAM), physical security, change management, firewalls, encryption. |
| Availability | A1.1 – A1.3 | Optional add-on | Information and systems are available for operation and use to meet entity commitments. | Capacity planning, environmental controls (UPS/HVAC/generators), data backups, BCP/DRP testing, RTO/RPO. |
| Processing Integrity | PI1.1 – PI1.5 | Optional add-on | System processing is complete, valid, accurate, timely, and authorized to meet objectives. | Input validation (limit/range checks), error handling, automated run-to-run reconciliation, batch totals. |
| Confidentiality | C1.1 – C1.2 | Optional add-on | Information designated as confidential is protected as committed or agreed (B2B). | Data classification, encryption in transit/at rest, access restrictions on business IP, NDA enforcement. |
| Privacy | P1.1 – P8.1 | Optional add-on | Personal information (PII) is collected, used, retained, disclosed, and disposed of per GAPP (B2C). | Notice, choice/consent, collection limitation, use/retention, access, disclosure to 3rd parties, quality, monitoring. |
💡 CPA ISC Pro Tip: Never confuse Confidentiality with Privacy! Confidentiality protects organizational data, trade secrets, and intellectual property. Privacy protects Personally Identifiable Information (PII) belonging to natural persons based on GAPP.
COSO Internal Control 17 Principles & ITGC Mapping
COSO & ITGC| COSO Component | Key Principle | IT General Control (ITGC) Domain | Specific Control Implementation |
|---|---|---|---|
| Control Environment | Principle 5: Enforces Accountability | Security Governance & Organization | Clear IT reporting lines to Board, acceptable use policies, background checks, mandatory security training. |
| Risk Assessment | Principle 8: Assesses Fraud Risk | Fraud & Vulnerability Management | Threat modeling (STRIDE), vulnerability scanning, penetration testing, evaluating management override risks. |
| Control Activities | Principle 11: General Controls Over Technology | Program Changes & Environment Segregation | Strict logical isolation between Dev, Test, and Prod; mandatory CAB review; tested rollback plans. |
| Control Activities | Principle 11: General Controls Over Technology | Access to Programs and Data | Principle of least privilege, MFA/FIDO2, privileged access management (PAM), quarterly user access reviews. |
| Control Activities | Principle 11: General Controls Over Technology | Computer Operations | Automated batch job scheduling, dependency halting upon abort, tape/cloud backup rotation, offsite storage. |
| Information & Comm. | Principle 13: Uses Relevant Information | Data Quality & Master Data | Single-point ERP entry, master data dual authorization, automated data pipeline run-to-run balancing. |
| Monitoring Activities | Principle 16: Evaluates Internal Control | Security Operations & Audit | SIEM log correlation, Database Activity Monitoring (DAM), independent internal and external SOC audits. |
💡 CPA ISC Pro Tip: COSO Principle 11 is the direct anchor for ITGCs. On the exam, when asked which COSO principle mandates technology change control, access control, and IT operational controls, the answer is always Principle 11.
NIST Cybersecurity Framework 2.0 Core Functions & Controls
Cybersecurity Core| CSF 2.0 Function | Code | Strategic Purpose | Key Categories & Control Activities |
|---|---|---|---|
| Govern | GV | Establish and monitor the organization's cybersecurity risk management strategy, expectations, and policy. | Organizational Context, Risk Management Strategy, Cybersecurity Supply Chain Risk (C-SCRM), Roles & Policy. |
| Identify | ID | Understand cybersecurity risk to systems, people, assets, data, and capabilities. | Asset Management (CMDB), Business Environment, Risk Assessment, Improvement Feedback. |
| Protect | PR | Safeguard delivery of critical services and contain/counteract potential impact. | Identity Management & Access Control (IAM/MFA), Awareness Training, Data Security (Encryption), Platform Security. |
| Detect | DE | Discover and analyze potential cybersecurity attacks and compromises. | Continuous Security Monitoring, Adverse Event Analysis, Anomaly & Baseline Deviation Detection (SIEM/IDS). |
| Respond | RS | Take action regarding a detected cybersecurity incident. | Incident Management, Incident Analysis, Incident Containment, Eradication, Incident Communication. |
| Recover | RC | Restore assets and operations impacted by a cybersecurity incident. | Incident Recovery Plan Execution, System Restoration from Immutable Backups, Public Communication, Lessons Learned. |
💡 CPA ISC Pro Tip: Govern (GV) is the brand new 6th function introduced in NIST CSF 2.0 (2024). It encompasses organizational governance, executive oversight, and third-party supply chain risk management.
Cryptographic Protocols, Keys & Disaster Recovery Metrics
Technical Safeguards| Mechanism / Concept | Standard / Formula | Key Technical Characteristics | Exam Pitfall / Distinction |
|---|---|---|---|
| Symmetric Encryption | AES-256 / GCM | Single shared secret key for encryption and decryption. Fast, hardware-accelerated. Ideal for bulk data at rest. | Key distribution is difficult across open networks; storing keys alongside ciphertext destroys security. |
| Asymmetric Encryption | RSA-4096 / ECC | Public key encrypts, private key decrypts. Solves key distribution. Slow. Used for digital handshakes (TLS). | Never used for bulk database encryption due to massive CPU overhead; used in hybrid encryption. |
| Digital Signatures | RSA / ECDSA + SHA-256 | Hash document, encrypt hash with sender's private key. Verified with sender's public key. | Provides Integrity, Authenticity, and Non-Repudiation. Does NOT provide confidentiality (not encrypted). |
| Cryptographic Hashing | SHA-256 / SHA-3 | One-way mathematical function; fixed-length digest. Irreversible and collision-resistant. | Hashing is NOT encryption; it cannot be decrypted back into original plaintext. |
| Recovery Point Objective | RPO (Data Loss) | Maximum acceptable amount of data loss measured in time (e.g. 15 mins of transactions). | Dictates backup frequency and replication architecture (synchronous vs asynchronous). |
| Recovery Time Objective | RTO (Downtime) | Maximum acceptable duration of system downtime before acceptable operations resume. | Dictates alternate facility choice (Hot site = minutes/hours; Cold site = weeks). |
💡 CPA ISC Pro Tip: Remember that a digital signature does NOT encrypt the document itself. The message is readable, but any tampering breaks the signature. To achieve confidentiality AND digital signature, encrypt the message with the recipient's public key AND sign with the sender's private key.