In addition, at Institution B, the internal auditor indicated that top management's inability to provide
sufficient resources is part of the reason that the internal audit function does not possess a deep level of
technical knowledge about information systems security: