For identity and access management (IDAM), both human and machine access need to be secured. Enterprises place considerable focus on securing human identities, relying on usernames, passwords, smart cards, and biometrics to access machines. However, securing automated machine-to-machine communications is equally as important as many of these transactions contain sensitive, critical information. For machine identities, enterprises rely on cryptographic keys and digital certificates, such as TLS and SSH, for authentication and authorization of machine-to-machine connections. Securing machine identities is critical as machine communications are frequently at a privileged level, which in turn elevates machine identity risk. While organizations rigorously audit human access, auditing of machine identities is often overlooked. IDAM for machines is a threat vector that enterprises should address to reduce the risk of compromise by threat actors. Traditional risk management narrowly audits certificates, private keys, or SSH keys and views these methods individually rather than as a connected whole. Instead, enterprises need to take a more holistic approach to assessing machine identity risk and link audit outcomes to regulatory compliance requirements. To reduce risk, the session’s speaker has developed a cohesive risk management and audit program that addresses current security methods. For context, the session will frame why machine identity auditing has been underemphasized and why it is important to incorporate these audit practices moving forward to identify and mitigate important enterprise risks. As an example, recent Dimensional Research survey results will be shared, which demonstrate the extent organizations audit SSH key and certificate management. Results show that less than 50% of enterprises audit each individual assessment capability included in the study, and over a quarter do not audit any of the capabilities. The results indicate a lack of auditing in general, but otherwise show a focus on siloed auditing efforts through the limited extent individual capabilities are reviewed. When audits are too siloed, results are not understood in terms of broader enterprise risk or in the context of law and regulatory compliance, which often govern at a higher level. This session will highlight current machine security, inherent risks, and audit/management processes from an enterprise perspective, followed by the introduction to the new comprehensive enterprise audit work program developed by the presenter to identify machine identity risk. The program has nine objectives, ranging from scoping through conclusions, including governance, security operations, monitoring, reporting, and international considerations as examples. A discussion of the risk management/audit program will address how enterprises can evaluate their risk profile and move any noted gaps into the remediation queue. The attendees will have free access to this work program, which provides a basic framework that can—and should—be modified by auditors to fit the technology and business environment being audited. Examples will be given of real-life risk issues and attendees will be able to ask questions of the work program author.