What does control objectives mean on the CPA exam?
Control objectives. What a set of controls is supposed to achieve, stated so that it can be tested. A SOC 1 opines against control objectives; a SOC 2 opines against the trust services criteria.
Defined against AICPA AAG-SOC1.
Which CPA exam sections use control objectives?
Control objectives appears in the ISC section of the CPA exam.
Related terms
- carve-out method: Excludes a subservice organization's control objectives and controls from both the description and the scope of the service auditor's report.
- trust services criteria: The AICPA's control criteria for a SOC 2 engagement, in five categories: security, availability, processing integrity, confidentiality and privacy.
- SOC 2 report: A report on a service organization's controls against the trust services criteria, covering security plus any of availability, processing integrity, confidentiality, and privacy that are selected.
- suitably designed: The controls, if they operated as described, would achieve the stated objective.
- SOC 3 report: A general use report on the same trust services criteria as a SOC 2, without the system description or the tests and results.
- risk appetite: How much risk an organization is willing to accept in pursuit of its objectives, set by the board.