Skip to main content
Back to career paths
Intermediate to advanced
Career path

GRC and IT Audit

A governance, risk, and audit path that starts with security fundamentals and progresses into professional risk and audit credentials.

Target role

GRC and IT Audit Professional

Estimated path time

Varies by experience and study pace

Path overview

Use foundational security knowledge as context for controls and risk, then specialize through audit, risk, and security-management credentials.

Step-by-step path

Follow the sequence in order unless a step is marked optional.

4 steps
1

CompTIA Security+

Build a security foundation that provides context for controls, threats, and risk.

CybersecurityFoundational
View CompTIA Security+
2

ISACA CISA or ISACA CRISC

Choose an audit-focused or risk-focused specialization based on the work you want to perform.

3

ISACA CISM

Progress toward security governance and management knowledge.

GRC and AuditAdvanced
View ISACA CISM
4

Practical activity

Practical activity

Apply the path in a governance, risk, and audit portfolio exercise.

Practical activity

Create a fictional-company risk register, policy review, and audit checklist.

Continue building this career path

Explore the certification areas used in this roadmap, then compare training and study resources for your next step.