GRC and IT Audit
A governance, risk, and audit path that starts with security fundamentals and progresses into professional risk and audit credentials.
Target role
GRC and IT Audit Professional
Estimated path time
Varies by experience and study pace
Path overview
Use foundational security knowledge as context for controls and risk, then specialize through audit, risk, and security-management credentials.
Step-by-step path
Follow the sequence in order unless a step is marked optional.
CompTIA Security+
Build a security foundation that provides context for controls, threats, and risk.
ISACA CISA or ISACA CRISC
Choose an audit-focused or risk-focused specialization based on the work you want to perform.
ISACA CISM
Progress toward security governance and management knowledge.
Practical activity
Practical activityApply the path in a governance, risk, and audit portfolio exercise.
Practical activity
Create a fictional-company risk register, policy review, and audit checklist.
Continue building this career path
Explore the certification areas used in this roadmap, then compare training and study resources for your next step.