CPA (ISC) • INFORMATION SYSTEMS

Identify Components Of IT Infrastructure

Understanding the technological backbone that supports every modern enterprise's financial operations and reporting systems.

Historical Context & Motivation

The concept of IT infrastructure has evolved dramatically over the past seven decades, transforming from room-sized mainframes used exclusively by government agencies and large banks into the distributed, cloud-enabled ecosystems that underpin virtually every financial transaction today. For CPA candidates studying information systems, understanding this evolution is essential because audit and assurance standards require professionals to evaluate the technological environment in which financial data is created, processed, stored, and reported. The trajectory of IT infrastructure directly mirrors the growing complexity of enterprise accounting systems, from manual ledgers to real-time ERP platforms.

1950s
Mainframe Era
Large corporations and government agencies deployed centralized mainframes for batch processing of payroll, billing, and general ledger transactions. Hardware, software, and data resided in a single physical location.
1980s
Client-Server Architecture
Personal computers proliferated across offices, and organizations adopted client-server models that distributed computing power. Databases moved to dedicated servers while users interacted through desktop applications.
1990s
Enterprise Resource Planning (ERP)
Vendors like SAP and Oracle integrated accounting, procurement, and human resources into unified ERP systems, demanding robust networking and standardized database platforms across the enterprise.
2006–2010
Cloud Computing Emergence
Amazon Web Services, Microsoft Azure, and Google Cloud Platform enabled organizations to rent computing resources on demand, shifting capital expenditures to operating expenditures and introducing new audit considerations.
2020s
Hybrid & Edge Infrastructure
Modern enterprises blend on-premises data centers, public cloud services, and edge devices. CPAs must now evaluate controls across multi-cloud environments and assess third-party service organization controls (SOC reports).

This historical arc raises the central question for today's CPA: given that financial data now flows across hardware, software, networks, databases, and cloud services simultaneously, how does an auditor systematically identify and evaluate each component of an organization's IT infrastructure? Answering this question requires a structured framework that maps every layer of technology to the internal controls that protect the integrity, availability, and confidentiality of financial information.

Core Principles & Definitions

IT infrastructure encompasses the entirety of hardware, software, networking, data management, and human resources that an organization relies upon to process and safeguard its information. From the CPA's perspective, these components form the IT general controls environment—the foundation upon which application-level controls for financial reporting are built. Weaknesses at the infrastructure level can undermine even the most carefully designed application controls, which is why auditing standards (such as those in PCAOB AS 2201 and AICPA AT-C 205) require an understanding of the entity's IT environment as part of risk assessment.

1

Hardware

Physical computing devices—servers, workstations, storage arrays, and networking equipment—that provide the processing power and data persistence layer. Includes both on-premises assets and collocated equipment.
2

Software

Operating systems, middleware, database management systems, and application software (ERP, CRM, financial reporting tools) that execute business logic and process transactions.
3

Networking & Telecommunications

Routers, switches, firewalls, load balancers, VPNs, and internet connections that enable data transmission between systems, users, and external parties such as banks and regulators.
4

Data Management

Databases (relational and non-relational), data warehouses, backup systems, and archival solutions that store, organize, and protect the organization's financial and operational data.
5

Human Capital & Processes

IT personnel (administrators, developers, security analysts) and governance frameworks (ITIL, COBIT) that manage change, access, and operations across the technology stack.
KEY TAKEAWAY
Think of IT infrastructure like the plumbing, electrical wiring, and structural framing of a commercial building. Just as a bank examiner inspects the vault door and the building's foundation, a CPA must evaluate not only the financial application itself but the entire underlying infrastructure—hardware, software, networks, data stores, and the people who manage them—to determine whether financial data can be trusted.

Visual Explanation — The IT Infrastructure Stack

The IT infrastructure stack illustrates how each layer builds upon the one below it. Hardware forms the physical foundation, networking connects the components, operating systems and data management provide the logical platform, and application software delivers business functionality. Human capital and governance span the entire stack.

The diagram above reveals a critical principle for CPA candidates: a control deficiency at any lower layer propagates upward. For example, if the networking layer lacks a properly configured firewall, the data management and application layers above it become vulnerable to unauthorized access, potentially compromising financial statement integrity. When performing risk assessment procedures, auditors trace the flow of financially significant transactions through each layer—from the physical server where data resides, through the network that transmits it, to the application that records journal entries—to identify where general IT controls must be tested.

How IT Infrastructure Components Interact

While IT infrastructure is not inherently mathematical in the way that, say, present-value calculations are, several quantitative frameworks help CPAs and IT auditors evaluate infrastructure adequacy. Understanding metrics such as availability, Recovery Time Objective (RTO), and Recovery Point Objective (RPO) is essential when assessing whether an organization's infrastructure can support the continuity of financial reporting operations.

SYSTEM AVAILABILITY
Availability (%) = (Total Time − Downtime) ÷ Total Time × 100
Where Total Time is the scheduled operating period and Downtime includes both planned maintenance and unplanned outages. A '99.99%' target (four nines) permits only ≈ 52.6 minutes of downtime per year.
ANNUALIZED LOSS EXPECTANCY
ALE = SLE × ARO
SLE (Single Loss Expectancy) = Asset Value × Exposure Factor. ARO (Annualized Rate of Occurrence) is the estimated frequency of the threat per year. CPAs use ALE to justify infrastructure investments in business continuity and disaster recovery plans.

These formulas underscore an important point: IT infrastructure decisions have direct financial consequences. When an organization invests in redundant servers, mirrored databases, or geographically dispersed cloud availability zones, it is effectively purchasing a reduction in its Annualized Loss Expectancy. For the CPA, the ability to connect infrastructure components to quantifiable business risk is what distinguishes a competent IS auditor from one who merely checks boxes on a control checklist.

📋 CPA Exam Relevance
The ISC section of the CPA exam frequently tests your ability to identify which IT infrastructure component is implicated in a given scenario. For instance, a question might describe a data breach and ask which layer of infrastructure—network, database, or application—likely contained the control weakness. Map each scenario to the layered stack model.

Detailed Classification of Infrastructure Components

To prepare for both the CPA exam and professional practice, it is helpful to classify IT infrastructure components along two dimensions: physical versus logical and on-premises versus cloud-based. This two-dimensional classification allows auditors to quickly determine which controls are managed internally versus those that require reliance on a service organization's SOC report.

This 2 × 2 classification matrix helps auditors determine control ownership. On-premises components are fully entity-managed, while cloud-based components operate under a shared responsibility model requiring SOC report reliance.
Summary of IT infrastructure components and their primary audit considerations
Component CategoryExamplesKey Audit Consideration
HardwareServers, workstations, storage, UPS, biometric scannersPhysical access controls, environmental controls (HVAC, fire suppression), asset inventory
Operating SystemsWindows Server, Linux (RHEL, Ubuntu), macOSPatch management, hardening configuration, privileged account management
Database SystemsSQL Server, Oracle, PostgreSQL, MongoDBAccess controls to tables/views, encryption at rest, backup frequency and integrity testing
NetworkingFirewalls, IDS/IPS, VPN gateways, DNS serversFirewall rule reviews, network segmentation, encryption in transit (TLS/SSL)
Application SoftwareSAP, Oracle Financials, QuickBooks, custom web appsSegregation of duties, input validation, change management procedures
Cloud ServicesAWS, Azure, GCP (IaaS, PaaS, SaaS)SOC 1/SOC 2 report review, shared responsibility model, data residency compliance

Worked Example — Mapping Infrastructure in an Audit Engagement

Consider the following scenario: you are a CPA performing an IT general controls assessment for Meridian Manufacturing, Inc., a mid-sized company that uses SAP S/4HANA hosted on-premises for financial reporting. The company recently migrated its payroll system to a SaaS provider (ADP Workforce Now) and uses Microsoft Azure for backup and disaster recovery. Your task is to identify and classify all IT infrastructure components relevant to the financial statement audit.

Meridian Manufacturing — IT Infrastructure Mapping
1
Step 1 — Identify Financial ApplicationsBegin by listing all applications that process financially significant transactions. At Meridian, these include SAP S/4HANA (general ledger, accounts payable, accounts receivable, inventory) and ADP Workforce Now (payroll, tax withholding). These represent the application software layer.
Two financially significant applications identified: SAP (on-premises) and ADP (SaaS cloud).
2
Step 2 — Trace Underlying Infrastructure Per ApplicationFor SAP (on-premises): the application runs on two Dell PowerEdge servers in the company's data center, using a SAP HANA database on SUSE Linux Enterprise Server. The servers connect to the corporate LAN via Cisco switches and are protected by a Palo Alto next-generation firewall. For ADP (cloud): the physical and logical infrastructure is managed by ADP; Meridian accesses it via encrypted HTTPS over the internet.
SAP stack: Dell servers → SUSE Linux → HANA DB → Cisco network → Palo Alto firewall. ADP stack: CSP-managed (SOC report required).
3
Step 3 — Map Backup and Disaster Recovery ComponentsMeridian replicates SAP database snapshots nightly to Microsoft Azure Blob Storage using Azure Site Recovery. This introduces a cloud infrastructure component (IaaS) that supports the on-premises SAP environment, meaning the auditor must also evaluate Azure's controls—typically by reviewing Microsoft's SOC 2 Type II report.
Azure DR introduces a hybrid infrastructure model; Microsoft SOC 2 report required.
4
Step 4 — Classify Components Using the 2 × 2 MatrixUsing the physical/logical and on-premises/cloud matrix from Section 5, classify each component. Dell servers, Cisco switches, and Palo Alto firewall fall into Physical + On-Premises. SUSE Linux and SAP HANA fall into Logical + On-Premises. ADP Workforce Now falls into Logical + Cloud (SaaS). Azure Blob Storage falls into Logical + Cloud (IaaS). Microsoft's and ADP's physical data center infrastructure falls into Physical + Cloud.
All four quadrants of the matrix are populated—Meridian has a hybrid infrastructure.
5
Step 5 — Determine Control Ownership and Audit ApproachFor entity-managed components (on-premises), the auditor performs direct testing of IT general controls: access management, change management, and computer operations. For cloud components (ADP, Azure), the auditor obtains and reviews the service organizations' SOC 1 and SOC 2 reports, evaluates complementary user entity controls (CUECs), and performs bridge-letter inquiries if the SOC report period does not align with the audit period.
Final output: A complete IT infrastructure map with control ownership assignments for every component.

Strengths, Limitations, and Risk Implications

Each infrastructure model—on-premises, cloud-based, or hybrid—carries distinct advantages and risks that influence the CPA's audit strategy. The table below contrasts these models across dimensions that matter most to financial statement auditors and IT governance professionals.

Comparative analysis of infrastructure models from an audit and governance perspective
DimensionOn-PremisesCloud-BasedHybrid
Control VisibilityFull visibility; direct testing possibleLimited; reliance on SOC reportsMixed; requires dual approach
ScalabilityRequires capital expenditure for capacity additionsElastic; resources scale on demand (OpEx model)Flexible burst capacity with on-prem baseline
Data ResidencyKnown physical location; simpler regulatory complianceMulti-region; potential cross-border data issuesSensitive data can remain on-prem while other workloads go to cloud
Disaster RecoveryRequires secondary site; expensive to maintainBuilt-in geo-redundancy from CSPsCloud serves as DR for on-prem workloads
Vendor DependencyLow; entity retains full operational controlHigh; lock-in risk and CSP concentration riskModerate; critical apps may have exit strategies
🔍 AUDITOR'S PERSPECTIVE
Much like a portfolio manager who diversifies investments across asset classes to manage risk, organizations increasingly adopt hybrid infrastructure to balance control, cost, and resilience. The CPA's job is to understand the full portfolio of IT components—on-prem and cloud alike—and evaluate whether the aggregate control environment adequately mitigates the risk of material misstatement in the financial statements.

Connection to Advanced IT Governance & Emerging Technologies

The foundational IT infrastructure concepts covered in this lesson serve as a gateway to more advanced topics that are increasingly relevant to CPA practice. As organizations adopt artificial intelligence, blockchain, robotic process automation (RPA), and Internet of Things (IoT) devices, the infrastructure supporting financial systems becomes more complex and demands a more sophisticated understanding from the auditor.

How foundational IT infrastructure concepts extend to emerging technologies
Foundational ConceptAdvanced ExtensionCPA Relevance
Physical servers (hardware layer)Containerization (Docker, Kubernetes) and serverless computingAudit trails become more ephemeral; controls must be embedded in CI/CD pipelines
Relational databases (data layer)Distributed ledger technology (blockchain)Immutable transaction records may reduce certain reconciliation procedures but introduce smart contract audit risks
Application software (ERP)AI/ML-powered financial analytics and automated journal entriesAuditors must evaluate model governance, training data integrity, and algorithmic bias
Network firewalls (security layer)Zero Trust architecture and micro-segmentationTraditional perimeter-based controls are replaced by identity-centric models requiring continuous authentication testing
Cloud services (IaaS/SaaS)Multi-cloud and edge computingMultiple SOC reports from different CSPs must be reconciled; data sovereignty becomes a significant compliance concern

Looking forward, the AICPA's evolving guidance—including updates to the Trust Services Criteria and the IT SOC framework—reflects the profession's recognition that IT infrastructure is no longer static. The CPA who develops a strong mental model of infrastructure components today will be well-positioned to adapt as these components evolve. On the ISC section of the CPA exam, expect questions that test not only your ability to identify current infrastructure components but also your understanding of how emerging technologies reshape the control environment.

Practice Problems

PROBLEM 1CONCEPTUAL
A CPA is conducting a risk assessment and learns that the client's general ledger application runs on an operating system that has not received security patches for over 18 months. Which layer of the IT infrastructure stack does this deficiency primarily affect, and why would it concern the auditor beyond just the operating system layer?
PROBLEM 2BASIC CALCULATION
A company's primary financial reporting server was available for 8,700 hours out of a total scheduled operating time of 8,760 hours during the past year. Calculate the server's availability percentage and determine whether it meets the 'three nines' (99.9%) availability standard.
PROBLEM 3INTERMEDIATE
Ridgeview Corp. uses Oracle Financials hosted on on-premises servers for accounts payable and receivable but recently migrated its payroll to Workday (SaaS). The company also uses AWS for data backup. For each of these three systems, classify the infrastructure as on-premises or cloud, identify which components the auditor can test directly, and specify which components require SOC report reliance.
PROBLEM 4APPLIED
During an audit of Pinnacle Financial Services, you discover that the company's ERP database (SQL Server) experienced a ransomware attack that encrypted 72 hours of transaction data. The most recent successful backup was four days old because the nightly backup to Azure had been silently failing for three nights. Pinnacle's management states the RPO is 24 hours. Calculate the Annualized Loss Expectancy (ALE) given the following: the estimated cost to reconstruct the lost data is $450,000 (SLE), and management estimates such incidents occur once every five years (ARO = 0.2). Then, discuss which IT infrastructure components failed and what controls should have prevented this outcome.
PROBLEM 5CRITICAL THINKING
A global manufacturing client is evaluating whether to migrate its entire on-premises SAP environment to a cloud-based SAP S/4HANA Cloud (SaaS) deployment. As the CPA advising on IT governance and audit implications, prepare a memorandum outline that identifies at least four IT infrastructure components that will shift from entity-managed to vendor-managed, describes the audit implications of each shift, and recommends how the client should contractually protect its ability to obtain assurance over the outsourced controls.

Lesson Summary

IT infrastructure comprises five interdependent layers: hardware (servers, storage, physical devices), networking and telecommunications (routers, firewalls, VPNs), operating systems and middleware (the software platform layer), data management (databases, backups, warehouses), and application software (ERP, financial reporting, CRM). Spanning all five layers is the critical dimension of human capital and governance—the IT personnel and frameworks (COBIT, ITIL) that ensure controls operate effectively across the entire stack.

For CPA candidates preparing for the ISC section, the essential skill is the ability to classify any IT component along two axes—physical versus logical and on-premises versus cloud—to determine whether control assurance comes from direct testing or from SOC report reliance. Remember that control weaknesses at lower layers propagate upward through the stack, and that quantitative tools like system availability calculations and Annualized Loss Expectancy help translate infrastructure risks into financial terms that management and audit committees can act upon.

Varsity Tutors • CPA (ISC) • Identify Components Of IT Infrastructure