Which function within the IT corporate structure is responsible for classifying information using an agreed-upon classification scheme for a new data collection system?
Which of the following industry sectors can be characterized by a low level of regulation and a high level of focus on cost?
Answer : A
The industry sector is a design factor that describes the type of business or economic activity that an enterprise engages in. The industry sector influences the governance and management of information and technology in terms of the specific standards, guidelines, regulations, best practices, challenges, opportunities, etc., that are applicable or relevant for that sector. The industry sector that can be characterized by a low level of regulation and a high level of focus on cost is nonprofit enterprises. Nonprofit enterprises are organizations that operate for a social or environmental purpose rather than for profit. Nonprofit enterprises typically have a low level of regulation compared to other sectors such as financial, health care, public, etc., which have more stringent and complex compliance requirements regarding their information and technology activities. Nonprofit enterprises also have a high level of focus on cost, as they have limited resources and funding, and they need to optimize their spending and demonstrate their accountability and transparency to their donors, beneficiaries, partners, etc. Therefore, nonprofit enterprises need to ensure that their information and technology governance system is efficient, effective, and value-driven. Reference:: COBIT 2019 Design Guide: page 45-46 : COBIT 2019 Framework: Introduction and Methodology: page 33-34
A CIO of a global enterprise has been mandated by the board to change the IT organizational structure from a divisional model to a centralized model and adopt outsourcing as required. The CIO identifies specific design factors that increase the importance of certain governance and management objectives. Which of the following is MOST likely to increase as a result?
Answer : B
The capability levels are a measure of how well an enterprise performs its information and technology governance and management processes in terms of process attributes such as process performance, process definition, process deployment, process measurement, process control, process optimization etc. The capability levels range from 0 (incomplete) to 5 (optimizing), indicating the degree of maturity and effectiveness of an enterprise's information and technology governance and management processes. The capability levels are most likely to increase as a result of identifying specific design factors that increase the importance of certain governance and management objectives. The design factors are the characteristics or conditions that influence how an enterprise designs and implements its information and technology governance system using COBIT 2019. The design factors include aspects such as enterprise strategy archetype; enterprise goals; IT-related goals; risk profile; IT deployment; threat landscape; compliance requirement; operating environment; size of enterprise; culture; stakeholders; etc. By identifying specific design factors that increase the importance of certain governance and management objectives, an enterprise can tailor its information and technology governance system to suit its context and needs. This will also help to improve its capability levels for those governance and management objectives that are prioritized by the design factors. For example, if an enterprise identifies that its IT deployment design factor is cloud-based or hybrid-based, it may increase the importance of certain governance and management objectives such as managed availability and capacity (BAI04), managed service agreements (APO09), managed security services (DSS05), etc., which are relevant for managing cloud-based or hybrid-based IT solutions. By tailoring its information and technology governance system to address those governance and management objectives more effectively, the enterprise can also increase its capability levels for those processes. Reference:: COBIT 2019 Design Guide: page 33-48 : COBIT 2019 Process Assessment Model: page 11-13
When tailoring a governance system for an enterprise, which of the following is MOST important to consider for an operating environment with a high compliance requirement?