It is likely that when internal auditors possess technical knowledge, they can ask the kinds of important
questions that cause information security professionals to see the potential value of further inter action.7
Indeed, the CISO at Institution B implies as much by describing internal audit's focus to be more on
compliance than on information security issues: