A CFO asks the IT director whether migrating the enterprise resource planning (ERP) to the cloud reduces or increases audit risk. The IT director answers "it depends," and that answer is correct. The risk profile shifts based on which cloud model is selected, how responsibilities are divided with the provider, and whether governance frameworks extend to cover the new architecture.
AICPA Representative Tasks (verbatim). 1. Remembering & Understanding, Explain the purpose and recognize examples of key components of IT architecture (e.g., operating systems, servers, network infrastructure, end-user devices). 2. Remembering & Understanding, Explain cloud computing, including cloud computing models (infrastructure as a service (IaaS), platform as a service (PaaS), and software as a service (SaaS)) and deployment models (e.g., public, private, hybrid). 3. Remembering & Understanding, Summarize the role and responsibilities of cloud service providers. 4. Remembering & Understanding, Explain how the COSO frameworks address cloud computing governance.
Components of IT Architecture
HIGH-FREQUENCY: IT architecture is the structural design of an organization's technology environment. The exam tests four foundational layers, each with distinct control requirements.
Common mistakes
- Assuming cloud migration eliminates IT general controls. Cloud shifts who performs certain controls; it does not eliminate the need for them. The customer retains responsibility for access management, change control, and monitoring within its layer, and for monitoring the provider through SOC reports.
- Confusing service models. IaaS gives raw infrastructure; PaaS provides a development platform; SaaS delivers a finished application. The exam will describe a scenario and expect you to identify the model from context. "We deploy our own code but don't manage servers" is PaaS, not SaaS.
- Treating all SOC reports as equivalent. SOC 1 covers financial reporting controls; SOC 2 covers trust services criteria; SOC 3 is a public summary. A SOC 1 report on a payroll processor is relevant to payroll expense; a SOC 2 report on a cloud hosting provider is relevant to IT general controls.
Bottom line
- IT architecture has four layers (operating systems, servers, network infrastructure, end-user devices); each layer requires its own controls
- Cloud service models split responsibility: IaaS (customer controls OS up), PaaS (customer controls applications and data), SaaS (customer controls only data and access)
- Cloud deployment models define infrastructure sharing: public (shared, multi-tenant), private (dedicated to one organization), hybrid (a combination of both)
- Cloud providers own physical security, hardware, hypervisor, and contracted service levels; customers retain data classification, access controls, and regulatory compliance
Exam shortcut
When a question asks which layer is responsible for a control failure, map the failure to the architecture layer: stolen laptop → end-user device; SQL injection → application (customer in IaaS/PaaS, provider in SaaS); hypervisor vulnerability → provider in all cloud models; unpatched Windows Server → customer in IaaS, provider in PaaS/SaaS.
The full lesson (about 3,021 words, 20 min read) adds 2 worked examples, all 6 common mistakes, a self-check, free in the app.
Learning objectives
- I.A1
Browse all free CPA ISC lessons or jump into free CPA ISC practice questions.