The remainder of this paper is organized as follows. Section 2 reviews prior literature and presents a
model of how the internal audit and information security functions can work together to help organizations
achieve a cost-effective level of information security. Section 3 describes the structured interview
method and provides demographic background about the interviewees and the organizations for which
they worked. Section 4 presents the common themes that emerged from the interviews.