Free CPA ISC (Information Systems & Controls) Formula Sheet (2026)

Every CPA ISC formula you need on the test, grouped by topic, rendered with full math notation. 10 formulas across 3 topics, calibrated to the 2026 syllabus. Free forever, no signup required.

10 Formulas
3 Topics
2026 Syllabus
Free Forever
Print-ready PDF: 1080x1350 portrait, math pre-rendered, fonts embedded. Download once, study anywhere.
Download PDF →

All CPA ISC Formulas

Information Systems and Data Management 4 items
RPO vs. RTO
RPO (Recovery Point Objective): max acceptable data loss in time (how old can restored data be?).
RTO (Recovery Time Objective): max acceptable downtime.
RPO drives backup frequency; RTO drives recovery infrastructure.
MTBF and system availability
MTBF=Total Operational TimeNumber of Failures\text{MTBF} = \frac{\text{Total Operational Time}}{\text{Number of Failures}}
Availability=MTBFMTBF+MTTR\text{Availability} = \frac{\text{MTBF}}{\text{MTBF} + \text{MTTR}}
MTTR = Mean Time to Repair. Higher MTBF or lower MTTR → higher availability.
Data classification levels
Government: Top Secret → Secret → Confidential → Unclassified.
Commercial: Restricted → Confidential → Internal → Public.
Drives access controls, handling, and retention.
Backup site tiers
Cold: basic infrastructure only; lowest cost, longest RTO (days–weeks).
Warm: partial equipment; moderate cost/RTO (hours–days).
Hot: fully mirrored, real-time; highest cost, lowest RTO (minutes–hours).
Security, Confidentiality and Privacy 5 items
Access control models: DAC, MAC, RBAC
DAC (Discretionary): owner sets permissions (Windows file share).
MAC (Mandatory): security labels enforce access (gov/military).
RBAC (Role-Based): perms assigned to roles; users to roles (enterprise).
Information security risk formula
Risk=Threat×Vulnerability×Impact\text{Risk} = \text{Threat} \times \text{Vulnerability} \times \text{Impact}
Controls reduce vulnerability or impact. Risk = residual risk after controls applied.
Annual loss expectancy (ALE)
ALE=SLE×ARO\text{ALE} = \text{SLE} \times \text{ARO}
SLE\text{SLE} = Single Loss Expectancy (loss per incident), ARO\text{ARO} = Annualized Rate of Occurrence.
Control is cost-effective if cost of control < ALE reduction achieved.
NIST password guidelines (SP 800-63B)
Min length 8 (15 for admin).
No complexity rules.
No forced rotation unless compromise.
Screen against breached passwords.
Allow paste + password managers.
Encryption key sizes and strength
AES-128 adequate; AES-256 for sensitive.
RSA-2048 min; RSA-4096 long-term.
ECC-256 \approx RSA-3072.
NIST: 112-bit min through 2030; 128-bit beyond.
Considerations for SOC Engagements 1 item
SOC report types
SOC 1: ICFR — for FS auditors.
SOC 2: Trust Services Criteria (Security, Availability, Integrity, Confidentiality, Privacy).
SOC 3: Public summary of SOC 2.
Type I = design (point in time). Type II = design + operating effectiveness (period).

Frequently Asked Questions

Is the CPA ISC formula sheet free?
Yes. The full CPA ISC formula sheet is free, with no signup, no email, and no credit card required. 10 formulas across 3 topics, all rendered with the same KaTeX math notation used in the FreeFellow study app.
Can I download the CPA ISC formula sheet as a printable PDF?
Yes. A 1080x1350 portrait PDF (Instagram and LinkedIn carousel native size, also great for tablet study) is linked at the top of this page. The PDF is fully self-contained: math is pre-rendered, fonts are embedded, no internet connection needed once downloaded.
What's covered on the CPA ISC formula sheet?
Every formula is grouped by official syllabus topic, with the formula in math notation plus a one-line note on when to use it (or a watch-out from CAIA, CFA, or other prep-provider commentary). Coverage is calibrated to the 2026 syllabus and refreshed when the corpus changes.
Is this formula sheet affiliated with CPA?
No. FreeFellow is not affiliated with the CPA or any examination body. This is an independent study aid covering the published syllabus.
What else is free at FreeFellow for CPA ISC candidates?
The full question bank with detailed solutions, mixed practice, readiness tracking, lessons (where available), and the formula sheet are all free forever. Fellow ($59/quarter or $149/year per track) unlocks timed mock exams, spaced-repetition flashcards, performance analytics, AI essay grading, and a personalized study plan.
Practice CPA ISC questions free →

About FreeFellow

FreeFellow is an AI-native exam prep platform for actuarial (SOA & CAS), CFA, CFP, CPA, CAIA, and securities licensing candidates — built around modern AI as a core capability rather than as a bolt-on. Every lesson ships with AI-narrated audio. Every constructed-response item has a copy-to-AI prompt builder so candidates can paste their answer into their own ChatGPT or Claude for self-graded feedback. Fellow members get instant AI grading on essays against the official rubric (currently CFA Level III, expanding to other essay-bearing sections).

The 70% you need to pass — question bank, written solutions, lessons, formula sheet, mixed practice, readiness tracking — is free forever, with no trial period and no credit card. Become a Fellow ($59/quarter or $149/year per track) to unlock mock exams, flashcards with spaced repetition, performance analytics, AI essay grading, and a personalized study plan.