Information Systems and Controls ISC Becker Supplemental Course
-
WELCOME. PLEASE START HERE!
1. Welcome to Farhat Lectures -
2. How to Use This Course & Resources
-
3. Choosing the Right CPA Discipline
-
4. CPA Exam Study Tips & Common Questions
-
🚀Introduce Yourself1 Topic
-
🚨🚨🚨2026 AICPA Released Questions1 Topic
-
ISC1 : M1 : National Institute of Standards and Technology Frameworks📖NIST Cybersecurity Framework: Govern Function 12 Topics|1 Quiz
-
📖NIST Cybersecurity Framework Identify Function 22 Topics|1 Quiz
-
📖NIST Cybersecurity Framework Protect Function 32 Topics|1 Quiz
-
📖NIST Cybersecurity Framework Detect Function 42 Topics|1 Quiz
-
📖NIST Cybersecurity Framework Respond Function 52 Topics|1 Quiz
-
📖NIST Cybersecurity Framework Recover Function 62 Topics|1 Quiz
-
📖NIST Cybersecurity Framework Profile2 Topics|1 Quiz
-
📖NIST: 4 Tiers2 Topics|1 Quiz
-
📖NIST Privacy Framework2 Topics|1 Quiz
-
📖NIST SP 800-532 Topics|1 Quiz
-
🚨🚨HOW TO SOLVE SIMULATIONS (TUTORIAL + VIDEO EXAMPLES)✅ CPA Exam Simulation Tutorial + 2024 and 2025 AICPA Video Questions.5 Topics|2 Quizzes
-
ISC1 : M2 : Privacy and Data Security Standards📖Intro to Data Privacy laws and Data breaches4 Topics|1 Quiz
-
📖Health Insurance Portability and Accountability Act (HIPAA)2 Topics|1 Quiz
-
📖PCIDSS2 Topics|1 Quiz
-
📖GDPR2 Topics|1 Quiz
-
ISC1 : M3 : Center for Internet Security Critical Security Controls: Part 1📖Intro to Center for Internet Security and Implementation Groups 1, 2 and 34 Topics|1 Quiz
-
📖Center for Internet Security (CIS) 1 to 96 Topics|1 Quiz
-
ISC1 : M4 : Center for Internet Security Critical Security Controls: Part 2📖CIS Controls 10 to 122 Topics
-
📖CIS Controls 13 to 152 Topics
-
📖CIS Controls 16 to 182 Topics
-
ISC1 : M5 : COBIT 2019 Framework📖The 6 principles of COBIT2 Topics
-
📖COBIT 7 Information Criteria2 Topics|2 Quizzes
-
ISC2 : M1 : IT Infrastructure📖IT Architectures: operating systems, servers etc.2 Topics|1 Quiz
-
📖Introduction to Cloud Computing2 Topics
-
📖Cloud Computing Deployment, Risks and Benefits2 Topics|1 Quiz
-
🎯AICPA Questions: Cloud Computing1 Quiz
-
📖Role and responsibilities of cloud service providers2 Topics|1 Quiz
-
📖How COSO Frameworks Address Cloud Computing Governance2 Topics|1 Quiz
-
ISC2 : M2 : Enterprise and Accounting Information Systems📖Enterprise Resource Planning / ERP Architecture4 Topics|1 Quiz
-
🎯AICPA Questions: Enterprise and Accounting Information Systems1 Quiz
-
📖Introduction to Accounting Information System (Business Cycles)2 Topics
-
📖Revenue Cycle2 Topics|1 Quiz
-
📖Expenditure Cycle2 Topics|1 Quiz
-
📖Payroll and H/R cycle2 Topics|1 Quiz
-
📖Manufacturing/production Cycle2 Topics|1 Quiz
-
📖Financing, Reporting and General Ledger Cycle2 Topics
-
📖Shared Services, Outsourcing & Offshoring2 Topics|1 Quiz
-
ISC2 : M3 : Availability, Resiliency, and Disaster Recovery📖Introduction to Business Resiliency2 Topics|1 Quiz
-
📖Business Resiliency Crisis Management2 Topics|1 Quiz
-
📖Business Resiliency: Disaster Recovery Plan DRP2 Topics|1 Quiz
-
📖Business Resiliency System Controls2 Topics|1 Quiz
-
🎯AICPA Questions: Business Continuity Plan1 Quiz
-
ISC2 : M4 : Change Management📖Change Management and Process of Change Management2 Topics|1 Quiz
-
🎯AICPA Questions: Change Management1 Quiz
-
📖Risks and Mitigations to Change Management2 Topics
-
📖System Development Life Cycle (SDLC)2 Topics|1 Quiz
-
📖Waterfall and Agile Methodology2 Topics|1 Quiz
-
📖Purpose Of Testing Change Management2 Topics|1 Quiz
-
📖Software System Testing2 Topics|1 Quiz
-
ISC2: M5: INTRODUCTION TO DATA COLLECTION & THE DATA LIFE CYCLE📖Data Life Cycle2 Topics|1 Quiz
-
ISC2: M6: DATA STORAGE & DATABASE DESIGN📖Database Systems2 Topics|1 Quiz
-
📖Flat Files Vs Structured Data2 Topics|1 Quiz
-
📖Business Intelligence Tools For Databases2 Topics|1 Quiz
-
📖Primary & Foreign Key3 Topics|1 Quiz
-
🎯AICPA Previously Released Questions1 Quiz
-
ISC2: M7: DATA EXTRACTION, INTEGRATION, & PROCESS DOCUMENTATION📖Data Definition Language: Create & Alter2 Topics
-
📖Data Definition Language: Drop, Truncate, Rename2 Topics
-
📖Data Manipulation Language: Insert, Update & Delete2 Topics
-
📖Data Control Language: Grant & Revoke2 Topics
-
📖Transaction Control Language: Commit Rollback & Save Point2 Topics|1 Quiz
-
📖1 To 1 Relationship In SQL Database2 Topics
-
📖1 To Many Relationship In SQL Database2 Topics
-
📖Many To Many Relationship In SQL Databasse2 Topics|1 Quiz
-
📖Business Process Modeling Notation2 Topics
-
📖Data Normalization8 Topics|1 Quiz
-
ISC3: M1: THREATS & ATTACKS📖Cyber Security2 Topics|1 Quiz
-
📖Threat Actors2 Topics|1 Quiz
-
📖Network Based Attacks2 Topics|1 Quiz
-
📖Host Based Attacked2 Topics|1 Quiz
-
📖Malware Attacks2 Topics|1 Quiz
-
📖Social Engineering Attacks2 Topics|1 Quiz
-
📖Application Based Attacks2 Topics|1 Quiz
-
📖Phishing Attacks2 Topics|1 Quiz
-
📖Physical Attacks2 Topics|1 Quiz
-
📖Supply Chain Attacks2 Topics|1 Quiz
-
📖Stages Of Cyber Attacks2 Topics|1 Quiz
-
📖Risks Related To Cloud Computing2 Topics|1 Quiz
-
📖Risks Related To Mobile Technology2 Topics|1 Quiz
-
📖Risks Related To Internet Of Things2 Topics|1 Quiz
-
📖Threat Modeling2 Topics|1 Quiz
-
ISC3: M2: MITIGATION OF THREATS & ATTACKS📖COSO & Cybersecurity2 Topics|1 Quiz
-
📖ERM: Cybersecurity2 Topics
-
📖Security Policies (Cybersecurity)2 Topics|1 Quiz
-
📖Security Policies: Acceptable Use Policies2 Topics|1 Quiz
-
📖Bring Your Own Device Policies2 Topics|1 Quiz
-
📖Network Components2 Topics|1 Quiz
-
📖Network Security2 Topics|1 Quiz
-
📖Authorization & Authentication2 Topics|1 Quiz
-
📖Identification & Authentication2 Topics|1 Quiz
-
📖Vulnerability Management2 Topics|1 Quiz
-
📖Vulnerability Scanning2 Topics|1 Quiz
-
📖Defense In Depth2 Topics
-
📖Redundancy & Diversification2 Topics
-
📖Preventive Controls2 Topics
-
📖Access Controls2 Topics|1 Quiz
-
📖Detective Controls2 Topics|1 Quiz
-
📖Corrective Controls2 Topics|1 Quiz
-
ISC3: M3: SECURITY TESTING📖Risk Management Framework2 Topics
-
📖Security Assessment Reports2 Topics|1 Quiz
-
📖Security Assessment Evaluators, Process & Evidence2 Topics|1 Quiz
-
📖Security Awareness2 Topics|1 Quiz
-
📖Evaluating Security Awareness2 Topics|1 Quiz
-
ISC3: M4: CONFIDENTIALITY & PRIVACY📖Confidentiality & Privacy2 Topics|1 Quiz
-
📖Protecting Confidential Data2 Topics|1 Quiz
-
📖Data Obfuscation SDLC2 Topics|1 Quiz
-
📖Data Encryption2 Topics
-
📖Hashing & Cipher Techniques2 Topics
-
📖Data Loss Prevention2 Topics|1 Quiz
-
📖Data At Rest & Data Deletion2 Topics
-
📖Walkthrough Of Org. Security, Confidentiality & Privacy2 Topics|1 Quiz
-
📖SOC 2 Engagement2 Topics|1 Quiz
-
ISC3: M5: INCIDENT RESPONSE📖Incident Respond Plan2 Topics|1 Quiz
-
📖Incident Response Plan (IRP): People2 Topics|1 Quiz
-
📖Events & Incidents2 Topics
-
📖7 Steps Responding To An Incident2 Topics|1 Quiz
-
📖Test IRP2 Topics|1 Quiz
-
📖Cyber Insurance2 Topics|1 Quiz
-
ISC4: M1: SOC ENGAGEMENT CATEGORIES & TYPES📖SOC 1, 2 & 32 Topics
-
📖Type 1 & Type 2 Opinion2 Topics|1 Quiz
-
📖Trust Service Criteria2 Topics
-
📖Attestation Engagements ISC2 Topics
-
📖COSO & TSC2 Topics|1 Quiz
-
📖TSC Additional Criteria2 Topics|1 Quiz
-
ISC4: M2: REPORTING ON SOC ENGAGEMENTS: PART 1📖Service Organization Control (SOC) Engagement2 Topics|1 Quiz
-
📖Unqualified Opinion2 Topics
-
📖Types Of Opinion In A SOC Engagement2 Topics|1 Quiz
-
📖Description Of SOC 12 Topics|1 Quiz
-
📖Description Of SOC 22 Topics|1 Quiz
-
📖Description Of Cybersecurity2 Topics
-
📖Management Assertions In A SOC Engagement2 Topics|1 Quiz
-
📖SOC 1 Type 1 Report2 Topics
-
📖SOC 1 Type 2 Report2 Topics
-
📖SOC 2 Type 2 Report2 Topics
-
ISC4: M3: REPORTING ON SOC ENGAGEMENTS: PART 2📖Carve-Out & Include Method2 Topics|1 Quiz
-
📖CUECs2 Topics|1 Quiz
-
📖SOC Reports: Complementary Subservice & User Controls2 Topics
-
📖SOC Reports: Qualified Or Adverse2 Topics
-
📖SOC Reports: Qualified Or Disclaimer2 Topics
-
ISC4: M4: PLANNING & RISK ASSESSMENT IN A SOC ENGAGEMENT📖SOC 1 Management Responsibilities2 Topics
-
📖SOC 2 Management Responsibilities2 Topics|1 Quiz
-
📖Service Auditor’s Responsibilities2 Topics|1 Quiz
-
📖Independence & SOC Engagements2 Topics|1 Quiz
-
📖Materiality In SOC Engagement2 Topics|1 Quiz
-
📖System Requirements2 Topics
-
📖Service Commitments2 Topics|1 Quiz
-
📖SOC Risk Assessment2 Topics|1 Quiz
-
ISC4: M5: PERFORMING SOC ENGAGEMENTS📖SOC Engagement: Response To The Assessed Level Of Risk2 Topics|1 Quiz
-
📖SOC Description 12 Topics|1 Quiz
-
📖SOC Description 22 Topics|1 Quiz
-
📖Control Design2 Topics
-
📖Test Of Effectiveness2 Topics
-
📖Evaluate The Procedures2 Topics|1 Quiz
-
📖Subsequent Events In A SOC Engagement2 Topics|1 Quiz
-
📖Presentation Letter (SOC Engagement)2 Topics|1 Quiz
Participants 2343
Instructions on how to complete the quiz:
- Click on “Start Quiz” to start.
- “Check” to submit your answer and reveal the solution.
- “Skip Question” to skip the question for now.
- “Review” to mark question for review later.
- “Feedback” to inquire about the question or provide us your feedback.
- Please make sure to reference the number of the question in your inquiry such as # 4
- “Quiz Summary” to finish/submit the whole quiz
Quiz Summary
0 of 9 Questions completed
Questions:
Information
You have already completed the quiz before. Hence you can not start it again.
Quiz is loading…
You must sign in or sign up to start the quiz.
You must first complete the following:
Results
Results
0 of 9 Questions answered correctly
Your time:
Time has elapsed
You have reached 0 of 0 point(s), (0)
Earned Point(s): 0 of 0, (0)
0 Essay(s) Pending (Possible Point(s): 0)
| Average score |
|
| Your score |
|
Categories
- Not categorized 0%
- Review / Skip
- Answered
- Correct
- Incorrect
-
Question 1 of 9
1. Question
Scenario:
SecureCPA, a mid-sized accounting firm, is expanding its services to handle government contracts requiring compliance with NIST-based cybersecurity frameworks. The managing partner has tasked the IT governance committee with ensuring that the firm fully understands its regulatory landscape, business drivers, and stakeholder expectations.Which GOVERN (GV) category is the firm primarily addressing in this stage of implementation?
CorrectIncorrect -
Question 2 of 9
2. Question
Scenario:
At TaxSure LLC, the cybersecurity incident response plan failed during a ransomware attack. A post-incident review revealed that several team members were unsure who had the authority to shut down infected systems, causing delays and increasing exposure.Which GOVERN (GV) category should the firm have strengthened to prevent this governance failure?
CorrectIncorrect -
Question 3 of 9
3. Question
Scenario:
AuditFirmCo has implemented a cybersecurity policy that includes password complexity requirements and multi-factor authentication. However, an internal audit found that 40% of users were not in compliance, and enforcement mechanisms were lacking.What is the most appropriate GOVERN (GV) response to ensure compliance?
CorrectIncorrect -
Question 4 of 9
4. Question
Scenario:
A CPA firm’s board is reviewing the quarterly cybersecurity report which includes metrics on incident response times, employee training compliance, and policy violations. The board uses this information to assess management’s performance.Which GOVERN (GV) category is most directly demonstrated in this scenario?
CorrectIncorrect -
Question 5 of 9
5. Question
Scenario:
LedgerPro, a CPA firm, uses third-party tax software to handle sensitive client data. During due diligence, it discovers the vendor does not encrypt data in transit. The firm halts onboarding until this risk is mitigated.Which GOVERN (GV) category is being applied in this decision?
CorrectIncorrect -
Question 6 of 9
6. Question
Scenario:
Precision Ledger, a national CPA firm, integrates its cybersecurity risk assessments with its existing enterprise risk management (ERM) framework. As a result, cybersecurity is considered alongside operational, financial, and compliance risks during annual planning.Which GOVERN (GV) category is most directly exemplified in this integration?
CorrectIncorrect -
Question 7 of 9
7. Question
Scenario:
At B&C Tax Consultants, the board of directors publicly commits to building a strong cybersecurity culture. The managing partner champions employee training, pushes for secure-by-design processes, and frequently discusses cybersecurity performance with leadership.What core concept of the GOVERN (GV) function is being demonstrated here?
CorrectIncorrect -
Question 8 of 9
8. Question
Scenario:
During an IRS audit of a CPA firm, investigators discover that vendor access logs are missing, cybersecurity roles are undocumented, and no one claims accountability for critical decisions. The firm has policies in place but lacks consistent follow-through.Which GOVERN (GV) category is most likely deficient in this case?
CorrectIncorrect -
Question 9 of 9
9. Question
Scenario:
A CPA firm is assessing a new payroll service provider. As part of its procurement process, it reviews the vendor’s SOC 2 Type II report, evaluates data encryption practices, and verifies breach notification procedures.Which GOVERN (GV) category is best represented by this scenario?
CorrectIncorrect
Responses
You must be logged in to post a comment.
Hello, I could not quite grasp the concept of GOVERN (GV) functions.
Aren’t there only the following lists?:
1. GV.OC
2. GV.RM
3. GV.RR
4. GV.PO
5. GV. OV
6. GV. CM
Why is the answer choice “Leadership Commitment” when the question itself is asking which of the GV function is being demonstrated here? I figured that the answer is “GV.OV” as it encompasses both [1] the external overview from independent auditor through SOC 2 report AND [2] internal overview from the board members through the reviewing process
in which the executive leadership and boards continuously monitor, evaluate, and adjust an organization’s cybersecurity strategy.
Why is the answer C, but NOT A?
Hello Ye Rim,
You are mixing two different levels of the CSF, and that is what is causing the confusion.
In NIST CSF 2.0, the GOVERN (GV) function contains these categories: GV.OC, GV.RM, GV.RR, GV.PO, GV.OV, and GV.SC. So yes, GV.OV (Oversight) is a real GV category, but GV.CM is not a GV category; DE.CM belongs to the DETECT function.
The reason the answer is C. Leadership Commitment is that this question is not asking for the GV category code. It is asking for the core concept being demonstrated. The fact pattern says the board publicly commits, the managing partner champions training, pushes secure-by-design processes, and frequently talks about cybersecurity performance. That is top-management commitment and tone at the top. NIST describes this under GV.RR-01: organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware and continually improving.
By contrast, GV.OV (Oversight) is about using the results of cybersecurity risk management activities and performance to inform, improve, and adjust strategy. In other words, oversight is more about reviewing outcomes and making adjustments, not about the leadership team actively setting the tone and driving the culture.
Therefore, the short answer is:
A (Oversight) would fit better if the question focused on review, evaluation, audit results, or strategy adjustment.
C (Leadership Commitment) fits better here because the facts emphasize tone at the top, active sponsorship, and culture-building.
Hope this helps!