jonwinterburn wrote: » I'm currently studying for CISSP. I have the SSCP, which I took for two reasons: to prepare me for CISSP, and because I'm from a technical background, and SSCP is more technical than CISSP. So I think the two go well together. Moving forward, I aim to gain the CISA. The impression I get is that if you are a CISSP and want to take the management route, the best additional cert is CISM, or if you are taking the audit route, then the best additional cert is CISA. Both CISA and CISM are available from ISACA - https://www.isaca.org (US) https://www.isaca.org.uk (UK).