Internal audits are a vital function for ensuring that cyber threats are reduced to an acceptable level (i.e., risk appetite). This session will describe what good looks like and what bad looks like (from an audit perspective). This covers auditing techniques, risk management, control assessment and reporting cyber maturity. It will draw on industry standards, specifically CIS Controls and FAIR.