Much has been written about assurance, but mainly by those who provide it - the professionals such as internal auditors, accountants and information security technologists for the purpose of advancing their professional practices. Less is written for or by those in governance who need it for the effective discharge of their responsibilities. It is