In summary, although internal auditors and information systems security professionals at all four
institutions indicated that they thought that top management was supportive of information security in
principle, only at the one for-profit institution was there agreement that top management supplemented
their general statements of support with measurable resources and appropriate incentives.