15.2 The Eleven Design Factors
Key Takeaways
- ISACA publishes eleven design factors: enterprise strategy, enterprise goals, risk profile, I&T-related issues, threat landscape, compliance requirements, role of IT, sourcing model for IT, IT implementation methods, technology adoption strategy, and enterprise size.
- Typical strategy options are growth/acquisition, innovation, cost leadership, and client service; typical role-of-IT options are support, factory, turnaround, and strategic — do not swap those lists.
- Initial scope commonly uses factors 1–4; refined scope uses factors 5–11.
- Risk profile is weighted by risk rating; the other factors are weighted by importance.
- A cost-leader manufacturer and a first-mover digital bank can both use COBIT 2019 and must not receive the same priority profile.
Quick Answer: ISACA publishes 11 design factors: (1) enterprise strategy, (2) enterprise goals, (3) risk profile, (4) I&T-related issues, (5) threat landscape, (6) compliance requirements, (7) role of IT, (8) sourcing model for IT, (9) IT implementation methods, (10) technology adoption strategy, and (11) enterprise size. Initial scope commonly uses factors 1–4. Refined scope uses factors 5–11. Risk profile is weighted by risk rating; the other factors are weighted by importance.
Memorize the names and the typical options. A Foundation stem will not ask you to operate the design-toolkit spreadsheet. It will ask whether “cloud” is a sourcing-model option, whether “factory” is a role of IT, whether initial scope is factors 1–4, or whether two enterprises with different factors should receive the same 40-objective profile. They should not.
Hold two enterprises in your head for the rest of this chapter.
Northline Castings makes metal components for industrial equipment. Strategy is cost leadership. IT keeps the plants running — a factory role — on mostly insourced systems with a few cloud tools. Methods are traditional with pockets of hybrid. Adoption is slow adopter / cautious follower. Threat landscape and compliance sit near normal. Size is a mid-size manufacturer, not a global bank.
Aether Digital Bank is a licensed digital bank racing to be a first mover in embedded payments. Strategy mixes innovation and client service, with growth behind a recent acquisition. IT is strategic. Sourcing is hybrid leaning cloud. Methods are Agile and DevOps. Threat landscape and compliance are high. Size is large enough for formal structures, but the culture is still product-team first.
Both can adopt COBIT 2019. Neither should get Northline’s profile stamped onto Aether, or Aether’s committee stack dumped onto Northline.
The official eleven
| # | Design factor | Typical options you should recognize | What it tends to move |
|---|---|---|---|
| 1 | Enterprise strategy | Growth/acquisition, innovation, cost leadership, client service | Which value bets I&T must serve |
| 2 | Enterprise goals | The enterprise’s balanced-scorecard goals | Cascade into alignment goals, then into objectives |
| 3 | Risk profile | I&T-related risk categories rated for this enterprise | Security, risk, vendors, continuity — weighted by risk rating |
| 4 | I&T-related issues | Current problems: failed projects, shadow IT, audit findings, fragile operations | Objectives already hurting stakeholders |
| 5 | Threat landscape | Normal or high | Security services, continuity, risk optimization |
| 6 | Compliance requirements | Low, normal, or high | Compliance, assurance, and control objectives |
| 7 | Role of IT | Support, factory, turnaround, strategic | Strategy, architecture, innovation, relationships |
| 8 | Sourcing model for IT | Insourced, outsourced, cloud, hybrid | Vendors, service agreements, continuity |
| 9 | IT implementation methods | Agile, DevOps, traditional, hybrid | Change, projects, configuration, knowledge |
| 10 | Technology adoption strategy | First mover, follower, slow adopter | Innovation and architecture versus operational stability |
| 11 | Enterprise size | Large, or small and medium | Formality of structures and which variants are realistic |
Recite the eleven in that order. ISACA’s design workflow uses the numbering: 1–4 first, then 5–11. Inventing a twelfth factor, dropping enterprise size, or treating “Agile” as a strategy option is how candidates lose easy marks.
Factors 1–4: who we are and what hurts
These four commonly set the initial scope of the governance system.
1. Enterprise strategy. Typical options are growth/acquisition, innovation, cost leadership, and client service (sometimes phrased as client service/stability). Northline is cost leadership: raise APO06 Managed Budget and Costs, BAI09 Managed Assets, DSS01 Managed Operations. Aether is innovation plus client service, with a growth/acquisition overlay: raise APO04 Managed Innovation, APO02 Managed Strategy, APO03 Managed Enterprise Architecture, APO08 Managed Relationships, and the benefits-delivery side of EDM02.
Do not confuse strategy options with role of IT options. Growth is a strategy. Strategic is a role of IT. They often travel together — Aether is both innovative and strategic — but they are different factors with different typical lists.
2. Enterprise goals. These are the enterprise’s own goals, usually through the balanced scorecard language of the goals cascade. Strategy is the bet. Goals are the scored outcomes. Northline’s goals cluster on cost, quality, and reliable delivery. Aether’s goals cluster on customer experience, growth, and regulated-product speed. The cascade then points at different alignment goals and therefore different governance and management objectives. If a stem says “which design factor uses the enterprise’s documented goals,” the answer is enterprise goals, not a vague appeal to culture.
3. Risk profile. This factor asks where I&T-related risk is concentrated and how severe it is. Weighting is based on risk rating, not on a generic “importance” slider. Aether’s profile is heavy on cyber, third-party/cloud, conduct, and resilience. That rating raises APO12 Managed Risk, APO13 Managed Security, APO10 Managed Vendors, DSS05 Managed Security Services, DSS04 Managed Continuity, and EDM03 Ensured Risk Optimization. Northline still has plant-floor and availability risk, but the rating on digital-channel cyber is lower, so the toolkit should not copy Aether’s security-heavy profile just because both firms “have IT risk.”
4. I&T-related issues. This is the current-pain factor: what is already going wrong or frustrating stakeholders. Failed programs, shadow IT, recurring incidents, audit findings, and brittle change all point at specific objectives. Northline’s issues might be aging plant systems, weak asset records, and cost overruns on a warehouse upgrade — BAI09, BAI11 Managed Projects, APO06. Aether’s issues might be product teams buying SaaS on corporate cards, release collisions, and a messy data estate after the acquisition — APO10, BAI06 Managed IT Changes, APO14 Managed Data, APO03. Issues make the initial scope concrete. They do not replace strategy or risk; they show where the generic model is already failing here.
Factors 5–11: refine the picture
These seven commonly refine the scope after the first four have drawn the outline.
5. Threat landscape — normal or high. Aether is high; Northline is closer to normal. High threat pushes security, continuity, and risk optimization further up than strategy alone would.
6. Compliance requirements — low, normal, or high. Aether is a licensed bank: high. That raises MEA03 Managed Compliance With External Requirements, MEA02 Managed System of Internal Control, MEA04 Managed Assurance, and related security and data objectives. Northline has ordinary industrial and privacy duties — real, but not Aether’s supervisory stack. Do not invent a “zero compliance” enterprise as an official option; the published range is low / normal / high.
7. Role of IT — support, factory, turnaround, strategic. Support: IT is not crucial for running or innovating the business. Factory: crucial for running, not for innovating. Turnaround: not crucial for current running, crucial for future innovation. Strategic: crucial for both. Northline is factory: keep operations, assets, availability, and changes reliable. Aether is strategic: strategy, architecture, innovation, data, and business relationships must be first-class. A stem that lists support / factory / turnaround / strategic is pointing at role of IT, not at enterprise strategy.
8. Sourcing model for IT — insourced, outsourced, cloud, hybrid. Northline is mostly insourced. Aether is hybrid/cloud. Cloud and outsourcing raise APO09 Managed Service Agreements, APO10 Managed Vendors, and continuity/security around third parties. Insourcing does not make vendor objectives disappear — it lowers their relative weight.
9. IT implementation methods — Agile, DevOps, traditional, hybrid. Methods change how change, projects, configuration, and knowledge should be governed. Aether cannot copy a stage-gate-only reading of BAI06 / BAI11 and call it tailored. Northline cannot pretend a DevOps overlay is required because a consultant likes the focus-area publication. Methods refine how build-and-change objectives are realized, including through variants.
10. Technology adoption strategy — first mover, follower, slow adopter. Aether is a first mover: more APO04 and APO03, more appetite for new platforms, more need to govern experiments. Northline is a slow adopter: more operational stability, less innovation machinery. Follower sits in the middle. Adoption strategy is not the same as role of IT, even though first movers are often strategic.
11. Enterprise size — large, or small and medium. Size changes whether a three-tier committee stack is realistic, how formal policies must be, and which variants a small enterprise should use. Aether can staff architecture and risk forums. A 90-person Northline cousin should not invent a Metro-bank governance factory just to look complete. Size is a design factor, not an excuse to skip COBIT.
Initial scope versus refined scope
ISACA’s design workflow — taught in the next section — uses a two-pass read of these eleven:
- Initial scope: factors 1–4 (strategy, goals, risk profile, I&T-related issues).
- Refined scope: factors 5–11 (threat, compliance, role of IT, sourcing, methods, adoption, size).
That split is a Foundation fact. Candidates lose it by shoving sourcing or Agile into the initial four because those words feel modern, or by scoring all eleven in one undifferentiated dump so “initial” and “refined” mean nothing. The first four describe the enterprise’s intent and pain. The last seven describe the environment and the way IT is actually run. Both passes matter. They are not optional decorations.
How weighting works
The toolkit does not treat every factor as a similar slider.
- For risk profile, weighting is based on risk rating — how severe and relevant each I&T-related risk is for this enterprise.
- For the other design factors, weighting is based on importance — how strongly that factor characterizes the enterprise.
Northline’s cost-leadership strategy is important; that importance lifts cost, asset, and operations objectives. Aether’s cyber risk is highly rated; that rating lifts risk and security objectives even if someone on the product team would rather talk only about innovation. Equal weighting of all eleven “to stay neutral” is not neutrality. It is a refusal to use the published method.
Two profiles, one core model
| Lens | Northline Castings | Aether Digital Bank |
|---|---|---|
| Strategy | Cost leadership | Innovation, client service, growth/acquisition |
| Role of IT | Factory | Strategic |
| Sourcing | Mostly insourced | Hybrid / cloud |
| Methods | Traditional / hybrid | Agile / DevOps |
| Adoption | Slow adopter / follower | First mover |
| Threat / compliance | Normal / normal | High / high |
| Objectives that rise | APO06, BAI09, DSS01, BAI11, EDM04 | APO02, APO03, APO04, APO08, APO12, APO13, APO14, DSS05, MEA03, EDM02, EDM03 |
Same 40-objective spine. Different priorities. Different target capabilities. Different variants. That is what “eleven design factors” is for.
Exam traps on the named list
- Swapping option lists. Growth / innovation / cost leadership / client service is enterprise strategy. Support / factory / turnaround / strategic is role of IT. Insourced / outsourced / cloud / hybrid is sourcing. First mover / follower / slow adopter is technology adoption. Agile / DevOps / traditional / hybrid is implementation methods.
- Putting factors 5–11 in the initial-scope set. Initial is 1–4. Refined is 5–11.
- Weighting everything the same way. Risk profile uses risk rating. The others use importance.
- Copying one famous company’s profile. Northline is not a failed Aether. Aether is not a flashy Northline. Both can be faithful.
If a stem lists “enterprise strategy, risk profile, and sourcing model,” you are looking at design factors, not at a secret twelfth system principle. If it asks which factors open the design, answer 1–4. If it asks how risk is weighted, answer risk rating.
Which set lists the typical COBIT 2019 options for the enterprise-strategy design factor?
In the official COBIT 2019 design workflow, which design factors commonly determine the initial scope of the governance system?
How does the COBIT 2019 design approach typically apply weighting to design factors?