We develop an exploratory model of
the factors that influence the nature of the relationship between the
internal audit and information security functions, describe the potential
benefits organizations can derive from that relationship, and present
propositions to guide future research.