ISC
Information Systems and Controls
ISC sits at the intersection of auditing and IT — information systems, data management, and IT audit/advisory including SOC engagements. It fits candidates interested in IT audit, risk, and controls, especially those already working adjacent to technology risk.
Last updated 5 September 2026
Complete Study Material
Exam-oriented explanations for every topic
Quick Revision Notes
The 20% you need the night before
MCQ Practice
Explained, server-graded questions
Student Discussions
Ask doubts, read others' explanations
Topics
IT General Controls (ITGCs)
The four ITGC categories that support reliance on automated application controls.
Information Security Fundamentals
Coming SoonConfidentiality, integrity, and availability, and common threat types.
Data Management & Governance
Coming SoonData lifecycle, data quality, and governance frameworks.
SOC Engagements
Coming SoonSOC 1 vs SOC 2 reports, trust services criteria, and Type I vs Type II.
Business Process Automation
Coming SoonRPA, workflow automation, and control considerations for automated processes.
Systems Development Life Cycle
Coming SoonSDLC phases and change management controls.
Third-Party & Vendor Risk
Coming SoonEvaluating cloud providers and outsourced service organizations.
Data Analytics Techniques
Coming SoonUsing data analytics for continuous auditing and anomaly detection.
Emerging Technology Considerations
Coming SoonAI, blockchain, and their control and audit implications.
IT Audit Standards
Coming SoonApplying professional standards specifically to IT audit engagements.
Business Continuity & Disaster Recovery
Coming SoonBCP/DRP planning and the controls that support system availability.
Privacy Frameworks
Coming SoonData privacy regulations and their implications for controls testing.