CISA Governance and Management of IT Practice Question
A company is implementing IT governance based on COBIT 2019. Which of the following design factors would have the GREATEST impact on the governance system design?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The industry and regulatory environment.
According to COBIT 2019, the industry and regulatory environment is a key design factor that significantly influences the governance system design, as it dictates compliance and risk management requirements. Options A, B, and C are factors but have a lesser impact compared to industry and regulatory considerations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The IT infrastructure complexity.
Why it's wrong here
Infrastructure complexity is an enterprise design factor, but COBIT 2019 weights enterprise strategy and goals as the greatest drivers of governance system design. Complexity alone would be the correct focus when tailoring governance for highly heterogeneous, multi-vendor environments rather than strategic alignment.
- ✗
The size of the organization.
Why it's wrong here
Organisation size is a design factor, yet COBIT 2019 identifies enterprise strategy, goals and risk profile as the factors with the greatest influence on governance design. Size would be the correct emphasis when scaling governance artefacts for a small or mid-sized enterprise.
- ✗
The number of IT staff.
Why it's wrong here
Staff headcount is a people-related factor that informs capability and resourcing, not one of COBIT 2019's design factors such as enterprise strategy, risk profile, threat landscape, compliance requirements and IT-related issues. It is tempting because staffing levels feel central to governance, and headcount would matter when sizing the governance implementation itself.
- ✓
The industry and regulatory environment.
Why this is correct
Industry and regulatory environment design factors shape mandatory compliance obligations and risk appetite, so they most strongly determine governance system design. They drive which COBIT components and focus areas are tailored, outweighing enterprise-specific factors such as size or threat landscape.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.