COBIT 2019 Foundation — Question 106
Which of the following must be done FIRST when implementing a culture and behavior governance component to ensure good governance and management of
IT?
Answer options
- A. Define an approach for assessing the level of compliance.
- B. Define a set of desirable or undesirable behaviors.
- C. Determine the capability levels.
Correct answer: B
Explanation
Defining a set of desirable or undesirable behaviors is crucial as it establishes the foundational expectations for the organization's IT culture. Without this clear definition, it would be challenging to assess compliance levels or determine capability levels effectively, as the criteria for evaluation would be unclear.