Section 2: 35–45%I6
Information Security Programs and Frameworks
Exam insight
Every control in ISC exists to protect information, and the AICPA expects you to reason from the basics, the CIA triad and defense in depth. Frameworks such as NIST CSF and ISO 27001 give you the vocabulary that nearly every other security question on the exam assumes you already know.
What AICPA wants you to know
- 1Define the three components of the CIA triad and identify which one a given control protects.
- 2Explain defense in depth and why layering controls is more effective than any single control.
- 3List and order the core functions of the NIST Cybersecurity Framework, including the Govern function added in CSF 2.0.
- 4Distinguish ISO 27001 (a certifiable management system standard) from a control framework.
- 5Apply the principle of least privilege and explain its role in a security program.
- 6Describe how security governance, policies, and risk assessment fit together.
Patterns in this topic
The exam re-skins the same archetypes. Recognize these here, then drill them in the Pattern Lab.
Exam tip
Study smarter: before you expand each card, cover the screen and try to recall what the concept means from its title alone. Retrieving it from memory builds the recall the exam actually tests, and it beats re-reading.