• Login
    • Login
    Advanced Search
    View Item 
    •   UoN Digital Repository Home
    • Theses and Dissertations
    • Faculty of Science & Technology (FST)
    • View Item
    •   UoN Digital Repository Home
    • Theses and Dissertations
    • Faculty of Science & Technology (FST)
    • View Item
    JavaScript is disabled for your browser. Some features of this site may not work without it.

    An information security risk management gap analysis tool based on ISO/IEC 27005:2011 compliance for SMEs in Kenya

    Thumbnail
    View/Open
    Full Text. pdf (2.082Mb)
    Date
    2018
    Author
    Obwanda, Andrew E O
    Type
    Thesis
    Language
    en
    Metadata
    Show full item record

    Abstract
    While being adopted by large institutions, information security risk management is still an out of range for smaller ones like SMEs, hence the need for a free and easy to use information security risk assessment and management tool. The main objective of this study was to come up with a software tool for information security risk management based on ISO/IEC 27005:2011 standard to be used by SMEs in Kenya to do a compliance gap analysis. A detailed literature review of the current works in information security risk management and a descriptive survey using questionnaires targeted to the SMEs with a focus on their understanding of information security risk management, the tools they use and their personnel capacity to conduct an information security risk assessment as per the standard of the study was done. From the survey response came the non-functional requirements while the functional requirements came from a detailed review and analysis of the ISO/IEC 27005:2011 standard. Development of the software tool followed the Rapid Application Development (RAD) methodology. We found that even though SMEs were aware of what an information security risk management was, they lacked proper in house skills and tools to do an information security risk assessment and gauge their respective institutions compliance to global risk standards. The software tool was welcomed as a potential in being an effective tool for information security risk assessment and management.
    URI
    http://hdl.handle.net/11295/104246
    Citation
    Degree of Masters of Science in Distributed Computing Technology
    Publisher
    University of Nairobi
    Collections
    • Faculty of Science & Technology (FST) [4206]

    Copyright © 2022 
    University of Nairobi Library
    Contact Us | Send Feedback

     

     

    Useful Links
    UON HomeLibrary HomeKLISC

    Browse

    All of UoN Digital RepositoryCommunities & CollectionsBy Issue DateAuthorsTitlesSubjectsThis CollectionBy Issue DateAuthorsTitlesSubjects

    My Account

    LoginRegister

    Copyright © 2022 
    University of Nairobi Library
    Contact Us | Send Feedback