CPA Evolution ISC 4-Week Study Plan
A rigorous 4-week preparation schedule calibrated to the AICPA CPA Evolution ISC Content Specification Outline. Combines weekly core study objectives, milestone targets, and an essential First-5-Minute Prometric Dump Sheet.
Weekly Study Agendas & Checkpoints
Area I: Enterprise Architecture, Cloud Models & Data Governance
Curriculum Focus: Master cloud service models (IaaS/PaaS/SaaS shared responsibility matrix), enterprise ERP structures, data classification tiers (Public, Internal, Confidential, Restricted), Master Data Management (MDM), and ETL data integrity pipelines.
Area I: ITGCs, Application Controls & SDLC Change Management
Curriculum Focus: COSO Internal Control framework (17 principles), IT General Controls (logical access, change management, computer operations), segregation of duties (developer vs. release engineer), automated application controls, and three-way matching.
Area II: Cybersecurity (NIST CSF 2.0), IAM & Privacy Regulations
Curriculum Focus: NIST CSF 2.0 six core functions (Govern, Identify, Protect, Detect, Respond, Recover), Zero Trust architecture, IAM/MFA/PAM controls, symmetric (AES-256) vs. asymmetric (RSA/ECC) cryptography, TLS handshakes, GDPR/CCPA privacy rights, and BCDR metrics (RTO vs. RPO).
Area III: SOC Engagements (SSAE 18/21) & Full Exam Simulation
Curriculum Focus: SOC 1 (ICFR / AT-C 320) vs. SOC 2 (TSC / AT-C 205) vs. SOC 3, Type 1 vs. Type 2 testing horizons, 5 Trust Services Criteria (Security mandatory), Complementary User Entity Controls (CUECs), subservice organization methods (carve-out vs. inclusive), and auditor reporting opinions.
The First-5-Minute Prometric Dump Sheet
As soon as your Prometric countdown begins, write down these high-yield frameworks and distinctions on your scratch paper:
1. SOC Engagement Decision Tree
- SOC 1 (AT-C 320): Direct impact on financial reporting (ICFR). Restricted use.
- SOC 2 (AT-C 205): Security, availability, privacy. Restricted use.
- SOC 3 (AT-C 205): Summary of SOC 2 for general public / marketing use.
- Type 1: Point in time (design only).
- Type 2: Period of time (≥6 mos; design + operating effectiveness).
2. 5 Trust Services Criteria (TSP 100)
- Security (Common Criteria): Always mandatory in every SOC 2.
- Availability: System operational per SLA/agreement.
- Processing Integrity: Complete, valid, accurate, timely.
- Confidentiality: Protected confidential info (contracts, IP).
- Privacy: Personal information (PII) collected/used/retained.
3. BCDR & Cryptography Essentials
- RTO (Recovery Time Objective): Maximum tolerable downtime.
- RPO (Recovery Point Objective): Maximum tolerable data loss.
- Symmetric: Single secret key (AES-256). Fast, bulk data.
- Asymmetric: Public/private keypair (RSA, ECC). Signatures, key exchange.
- Digital Signature: Sender encrypts hash with Private Key → Receiver decrypts with Public Key (integrity + non-repudiation).
4. COSO ITGC & NIST CSF 2.0
- COSO (CRIME): Control Environment, Risk Assessment, Control Activities, Info & Comm, Monitoring.
- NIST CSF 2.0: Govern, Identify, Protect, Detect, Respond, Recover.
- CUECs: Controls that service org requires user entities to implement for system controls to work.
- SDLC SoD: Developers must NEVER possess write/deploy access to Production environments.