1.2 Blueprint Navigation & Study Methodology

Key Takeaways

  • The AICPA ISC Examination Blueprint allocates exam content across three primary domains: Area I (Information Systems and Data Management, 35–45%), Area II (Security, Confidentiality, and Privacy, 35–45%), and Area III (Considerations for SOC Engagements, 15–25%).
  • The ISC exam assesses candidates exclusively across three cognitive skill levels under Bloom's Taxonomy: Remembering and Understanding (55–65%), Application (20–30%), and Analysis (10–20%), with no Evaluation-level tasks.
  • Mastering the ISC curriculum requires an estimated 120 to 160 hours of structured preparation over an 8- to 12-week study period for candidates without prior professional IT audit experience.
  • The blueprint's section introduction states that Analysis skills are tested in Area I and Area II only; Area III contains no Analysis-level representative tasks, so its SOC content is assessed at the Remembering and Understanding and Application levels.
  • A major study trap on ISC is treating IT audit concepts as abstract definitions to memorize rather than operational controls that must be evaluated within integrated business environments.
Last updated: September 2026

Blueprint Navigation & Study Methodology

Quick Summary: The AICPA ISC Examination Blueprint is the definitive syllabus for the exam. Content is divided into Area I (35–45%), Area II (35–45%), and Area III (15–25%). Testing is weighted heavily toward Remembering & Understanding (55–65%), with Application (20–30%) and Analysis (10–20%) forming the simulation backbone. Successful preparation requires 120–160 hours across an 8- to 12-week timeline.


1. Deconstructing the AICPA ISC Examination Blueprint

The AICPA Examination Blueprint serves as the authoritative contract between the AICPA Board of Examiners and CPA candidates. Every single question—whether multiple-choice or task-based simulation—is directly linked to a specific Representative Task defined in the Blueprint. Studying without mapping your progress to the Blueprint tasks risks spending critical hours on peripheral topics while neglecting heavily weighted core tasks.

┌─────────────────────────────────────────────────────────────────────────────┐
│                     AICPA ISC CONTENT AREA ALLOCATION                       │
├──────────────────────────────────────┬──────────────────────────────────────┤
│ Area I: Info Systems & Data Mgmt     │ 35% - 45%                            │
│ (Infrastructure, Cloud, ERP, ITGCs)  │ ~33-37 Scaled Points                 │
├──────────────────────────────────────┼──────────────────────────────────────┤
│ Area II: Security, Privacy & IAM     │ 35% - 45%                            │
│ (Threats, IAM, Cryptography, BCP/DR) │ ~33-37 Scaled Points                 │
├──────────────────────────────────────┼──────────────────────────────────────┤
│ Area III: SOC Engagements            │ 15% - 25%                            │
│ (SSAE 21, SOC 1/2/3, TSCs, CUECs)    │ ~18-22 Scaled Points                 │
└──────────────────────────────────────┴──────────────────────────────────────┘

Detailed Breakdown of Content Areas

Content AreaBlueprint WeightOfficial Content Groups and TopicsRepresentative Tasks (quoted from the 2026 blueprint)
Area I: Information Systems and Data Management35% – 45%A. Information systems<br/>1. IT infrastructure<br/>2. Enterprise and accounting information systems<br/>3. Availability<br/>4. Change management<br/>B. Data management (no numbered topics)• "Explain the purpose and recognize examples of key components of IT architecture (e.g., operating systems, servers, network infrastructure, end-user devices)."<br/>• "Reconcile the actual sequence of steps and the information, documents, tools and technology used in a key business process of an accounting information system ... to the documented process."<br/>• "Determine the appropriateness of the organization's data backup types (e.g., full, incremental, differential) including recovery considerations."<br/>• "Test the design and implementation of change control policies ... including those that have adopted continuous integration and continuous deployment processes."<br/>• "Examine a standard SQL query (common commands, clauses, operators, aggregate functions and string functions) to determine whether the retrieved data set is relevant and complete."
Area II: Security, Confidentiality and Privacy35% – 45%A. Regulations, standards and frameworks<br/>B. Security<br/>1. Threats and attacks<br/>2. Mitigation<br/>3. Testing<br/>C. Confidentiality and privacy<br/>D. Incident response• "Recall the three parts of the NIST CSF (Core, Tiers, Organizational Profiles)."<br/>• "Identify techniques used in a cyber-attack (e.g., buffer overflow, mobile code, cross-site scripting, SQL injections, race conditions, covert channel, replay and return-oriented attack)."<br/>• "Determine the appropriate authorization model (e.g., discretionary, role-based, mandatory) and the controls (e.g., access control list, account restrictions, physical barriers) used to implement the model in a specific scenario."<br/>• "Explain Data Loss Prevention (DLP)."<br/>• "Perform procedures to test whether the entity responded to cybersecurity incidents in accordance with the incident response plan."
Area III: Considerations for System and Organization Controls (SOC) Engagements15% – 25%A. Considerations specific to planning and performing a SOC engagement<br/>B. Considerations specific to reporting on a SOC engagement• "Recall the purpose and intended users of SOC 1®, SOC 2®, SOC 3® and SOC for Cybersecurity reports."<br/>• "Explain how materiality is determined and used in performing a SOC engagement (SOC 1®, SOC 2®)."<br/>• "Explain the considerations for deciding between, and use of, the inclusive and carve-out method for subservice organizations and complementary subservice organization controls (CSOCs)."<br/>• "Prepare a comparison of management's system description to suitable criteria in a SOC 1® engagement or to the description criteria in a SOC 2® engagement."<br/>• "Determine the appropriate form and content of a report on the examination of controls at a service organization (SOC 1®, SOC 2®)."

Read the blueprint literally. Where a representative task uses a parenthetical beginning with "e.g.", the list is illustrative. Where a parenthetical has no "e.g." — for example, "the three parts of the NIST CSF (Core, Tiers, Organizational Profiles)" — the blueprint states that the list is exhaustive for that task. That single convention tells you when to memorize a closed list and when to understand a concept.

Strategic Analysis of the Blueprint Balance

Notice the symmetry of the exam: Area I and Area II together comprise 70% to 90% of the total exam weight. These two areas establish the foundational technology, governance, cybersecurity, and operational controls.

However, candidates must not underestimate Area III (15% to 25%). While carrying the smallest percentage weighting, Area III has an exceptionally high simulation density. A single multi-tab SOC 2 simulation evaluating testing exceptions and Complementary User Entity Controls can account for 10% or more of your total simulation score. Mastering SSAE 21 and the Trust Services Criteria is mandatory for achieving a passing score of 75.


2. Cognitive Skill Levels and Bloom's Taxonomy on ISC

The AICPA constructs examination tasks according to a modified version of Bloom's Taxonomy of Educational Objectives. Understanding the cognitive skill level assigned to each topic dictates how that topic will be tested.

The Three Cognitive Skill Levels on ISC

Unlike the Auditing and Attestation (AUD) core exam—which tests up to the highest level of Evaluation (e.g., forming an independent overall audit opinion on financial statements)—the ISC blueprint tests across exactly three skill levels:

  1. Remembering and Understanding (55% – 65%): The perception and comprehension of technical IT terminology, standards, regulatory requirements, and control frameworks. Candidates must recognize definitions, match security controls to threats, identify cloud service models, and recall SSAE 21 report types.
  2. Application (20% – 30%): The practical execution or implementation of knowledge. Candidates must apply security principles to configure access permissions, formulate basic SQL queries (e.g., SELECT, FROM, WHERE, JOIN), trace data flow through ETL pipelines, or select appropriate Trust Services Criteria.
  3. Analysis (10% – 20%): The examination and study of the interrelationships of separate areas in order to identify causes and find evidence to support inferences. The blueprint's section introduction is explicit about where this skill lives: "Analysis skills are tested in Area I and Area II" — and nowhere else. Every Analysis-level representative task is a variation on detecting deficiencies in the suitability of design and deviations in the operation of controls over information systems, security, confidentiality and privacy. Area III contains no Analysis-level tasks at all; its SOC content tops out at Application (e.g., preparing a comparison of management's system description to the description criteria).

Skill Level Distribution and Question Mapping

Cognitive Skill LevelBlueprint WeightPrimary Delivery MechanismTypical Exam Prompt Characteristics
Remembering & Understanding55% – 65%Multiple-Choice Questions"Which of the following cloud models provides consumer control over operating systems?" / "Which framework defines five core functions: Identify, Protect, Detect, Respond, and Recover?"
Application20% – 30%MCQs & Basic TBSs"An auditor wants to retrieve customer orders exceeding $10,000. Which SQL clause must be added to filter the records?" / "Select the Trust Services Criteria category applicable to system processing timeliness."
Analysis10% – 20% (Areas I and II only)Task-Based Simulations"Review Exhibit 1 (Change Management Policy) and Exhibit 2 (Release Logs). For each ticket, identify whether a control deficiency exists, specify the deficiency type, and select the compensating control."

[!IMPORTANT] Blueprint Analysis Rule: Every task classified at the Analysis level in the AICPA ISC Blueprint is a prime candidate for a Task-Based Simulation — and those tasks sit exclusively in Areas I and II. The recurring Analysis phrasing is "Detect deficiencies in the suitability of the design and deviations in the operation of controls related to ...", applied to processing integrity, availability, security, and confidentiality and privacy in a SOC 2® engagement context. Expect multi-tab deficiency grids there. Area III simulations still appear, but they are built on Application-level tasks such as preparing a description-to-criteria comparison or determining the appropriate form and content of a report.


3. The 10-to-12-Week Structured Study Roadmap (120–160 Total Study Hours)

Most CPA candidates come from traditional accounting, audit, or tax backgrounds with limited exposure to low-level computer networking, database normalization, or cybersecurity architecture. For such candidates, the recommended investment is 120 to 160 total study hours, paced over a structured 10- to 12-week schedule (12–15 hours per week).

Candidates with professional IT audit backgrounds (e.g., prior CISA certification or Big Four IT audit experience) may comfortably compress this timeline to 8 weeks (90–110 hours).

Weeks 1-3          Weeks 4-6          Weeks 7-8          Weeks 9-10         Weeks 11-12
┌──────────────┐   ┌──────────────┐   ┌──────────────┐   ┌──────────────┐   ┌──────────────┐
│   PHASE 1    │──▶│   PHASE 2    │──▶│   PHASE 3    │──▶│   PHASE 4    │──▶│   PHASE 5    │
│ Area I: ITGC │   │ Area II: Sec │   │ Area III:SOC │   │ TBS Practice │   │ Mock Exams & │
│ Data, Cloud  │   │ IAM, Privacy │   │ SSAE 21, TSC │   │ Diagnostics  │   │ Final Polish │
└──────────────┘   └──────────────┘   └──────────────┘   └──────────────┘   └──────────────┘
  ~35 Hours          ~40 Hours          ~30 Hours          ~25 Hours          ~20 Hours

Week-by-Week Execution Plan

WeekContent FocusBlueprint Tasks CoveredTarget Weekly Output & Deliverables
Week 1IT Infrastructure & Cloud ModelsHardware, OS, networking protocols (TCP/IP, DNS), firewalls, cloud service models (IaaS, PaaS, SaaS), deployment architecturesComplete 150 MCQs; create comparison tables for cloud shared responsibility models.
Week 2ERPs, AIS Cycles & ITGC FrameworkEnterprise systems, transaction processing, IT General Controls (change management, logical access, computer operations), SDLC methodologiesComplete 150 MCQs; diagram the 5 phases of the SDLC and map control gates.
Week 3Data Governance, Databases & SQLRelational database architecture, keys, normalization (1NF/2NF/3NF), SQL querying (SELECT, JOIN, WHERE), ETL/ELT pipelinesComplete 150 MCQs; write out 15 manual SQL query interpretations.
Week 4Security Governance & Cyber ThreatsCybersecurity frameworks (NIST CSF 2.0, COBIT, ISO 27001), threat modeling, malware, social engineering, ransomware vectorsComplete 150 MCQs; build NIST CSF core function mapping matrix.
Week 5Identity & Access Management (IAM)Authentication, MFA mechanisms, authorization (RBAC, ABAC), privileged access management (PAM), least privilege, SoDComplete 175 MCQs; evaluate 5 sample Segregation of Duties matrices.
Week 6Cryptography, Incident Response & BCPSymmetric vs asymmetric encryption, PKI, digital signatures, TLS, incident response phases, BCP/DR, RTO, RPO, site typesComplete 175 MCQs; diagram PKI public/private key encryption workflow.
Week 7Attestation Standards & SOC FrameworkSSAE 21, AT-C 105, AT-C 205, AT-C 320, SOC 1 vs SOC 2 vs SOC 3, user auditor vs service auditor responsibilitiesComplete 150 MCQs; compare SOC 1 (ICFR) vs SOC 2 (Trust Services) objectives.
Week 8Trust Services Criteria & ReportingSecurity (Common Criteria), Availability, Processing Integrity, Confidentiality, Privacy; Type 1 vs Type 2; CUECs; subservice carve-outsComplete 150 MCQs; analyze 3 sample SOC 2 Type 2 Section IV testing tables.
Week 9Intensive TBS Diagnostic DrillsMulti-tab simulation mechanics, control deficiency grids, log analysis, SoD conflict resolution, opinion formulationComplete 20 full-length TBSs; perform timed exhibit triage drills.
Week 10Practice Exam 1 & Gap RemediationFull 4-hour simulated exam (82 MCQs + 6 TBSs) under strict exam conditions; review every missed question and near-guessScore 80%+ on mock exam; document root cause for all incorrect answers.
Week 11Practice Exam 2 & Advanced TBSsSecond full 4-hour simulated exam; review complex multi-tab exhibits in Area II and Area IIIScore 80%+ on mock exam; drill weak Blueprint tasks identified in score report.
Week 12Final Framework Review & Pacing PolishReview summary tables: NIST CSF, Trust Services Criteria, Cloud models, SQL syntax, SOC opinions; light question setsRest 24 hours prior to exam; test day logistics & Prometric check-in readiness.

4. Cognitive Traps and Study Pitfalls in ISC Preparation

Trap 1: The "Flashcard Illusion" (Rote Memorization vs. Operational Evaluation)

Many candidates attempt to study for ISC by memorizing flashcards of IT terms (e.g., memorizing what "Multi-Factor Authentication" or "Zero Trust Architecture" stands for). On exam day, the AICPA does not ask for textbook definitions. Instead, the exam presents an operational business scenario: "An organization requires MFA for all remote access. Which implementation violates this policy?" A candidate who only memorized that MFA means "two or more factors" will stumble when evaluating whether an SMS text code and a password satisfy the requirement versus a hardware security token and biometric fingerprint.

Trap 2: Neglecting Area III Because It Is "Only 15% to 25%"

Because Area I and Area II each carry 35% to 45%, some candidates spend 90% of their study time on hardware, networks, and cybersecurity, treating SOC reporting as an afterthought. This is fatal. Area III has the highest concentration of Task-Based Simulations per percentage point. A candidate who cannot differentiate between an inclusive method and a carve-out method for subservice organizations, or who cannot identify when an auditor must issue a qualified SOC 2 opinion, will lose massive simulation points.

Trap 3: Conflating ISC with Retired BEC IT Material

Candidates who previously studied for the retired BEC section often assume ISC is simply "BEC IT." This assumption leads to failure. BEC tested superficial IT vocabulary (e.g., "What is a firewall?"). ISC tests deep, professional-level IT audit concepts: evaluating firewall rule tables, analyzing packet inspection types, assessing database normalization violations, interpreting SQL queries, and understanding SSAE 21 attestation standards.

Trap 4: Postponing TBS Practice Until the Final Week

Leaving simulations to the final days creates extreme anxiety on test day. ISC simulations present 4 to 7 exhibits containing realistic corporate IT policies, Git logs, Active Directory access dumps, and SOC reports. Navigating multi-tab windows, cross-referencing timestamps, and selecting answers from 15-item dropdown lists requires practicing authentic simulations starting in Week 7.

Loading diagram...
AICPA ISC Cognitive Skill Hierarchy and Blueprint Flow
Test Your Knowledge

What is the highest cognitive skill level evaluated on the CPA Information Systems and Controls (ISC) examination according to the official AICPA Blueprint?

A
B
C
D
Test Your Knowledge

Which content area in the AICPA ISC Examination Blueprint carries the lowest percentage weighting on the exam, yet represents a disproportionate share of complex, multi-exhibit Task-Based Simulations?

A
B
C
D
Test Your Knowledge

What is the recommended total study hour commitment for a CPA candidate preparing for the ISC examination who possesses a traditional accounting background but lacks prior professional IT audit experience?

A
B
C
D