CPA ISC · Security, Confidentiality and Privacy · Free Lesson

Regulations, Standards and Frameworks

Free CPA ISC (Information Systems & Controls) lesson in Security, Confidentiality and Privacy. 51 min read, ~7,665 words.

An organization's CISO presents a compliance matrix showing adherence to HIPAA, PCI DSS, and NIST CSF. The external auditor asks: "Which controls satisfy multiple frameworks, and where are the gaps?" Answering that question requires understanding what each regulation mandates, how each framework structures its requirements, and where responsibilities overlap.

AICPA Representative Tasks (verbatim). 1. Remembering & Understanding, Recall the covered entities and permitted uses and disclosures of the HIPAA Security and Privacy Rules. 2. Remembering & Understanding, Recall the scope of the General Data Protection Regulation (GDPR) and the six principles and key concepts for personal data. 3. Remembering & Understanding, Recall the requirements of the PCI DSS. 4. Remembering & Understanding, Recall the three parts of the NIST CSF (Core, Tiers, Organizational Profiles). 5.

HIGH-FREQUENCY: The Health Insurance Portability and Accountability Act (HIPAA) protects protected health information (PHI). The exam tests who is covered and what disclosures are permitted.

Covered Entities. Three categories are directly regulated:

Business Associates. Any person or entity that performs functions involving PHI on behalf of a covered entity.

Read the full lesson, free →
Worked examples and practice. Free with a free account, no card.

Common mistakes

Bottom line

Exam shortcut

HIPAA disclosure mnemonic: "TPO plus public." Treatment, Payment, Operations are always permitted; public interest exceptions (law enforcement, public health, judicial) require specific circumstances. Marketing requires authorization. GDPR principles as a data lifecycle. Lawfulness (why collect?) → Purpose limitation (for what?) → Data minimization (how much?) → Accuracy (is it right?) → Storage limitation (how long?) → Integrity/confidentiality (is it protected?). Framework hierarchy. NIST CSF = risk framework (what to manage).

The full lesson (about 7,665 words, 51 min read) adds 10 worked examples, all 8 common mistakes, a self-check, free in the app.

Learning objectives

Browse all free CPA ISC lessons or jump into free CPA ISC practice questions.