Skip to content
Nairobi · KenyaFree to read
Technology

Master of Science in Information Systems Security

The Master of Science in Information Systems Security is a postgraduate programme that trains graduates in cybersecurity, information systems security, digital forensics, and network security. The programme prepares graduates for advanced careers in information security management, cybersecurity analysis, digital forensics, and security governance.

Core areas include information systems security, network security, digital forensics, software security, cryptography, security governance, risk management, penetration testing, incident response, and research methods. Students engage with both technical and managerial aspects of IT security, blending academic teaching with industry input and practical skills.

The programme is offered by Strathmore University through its School of Computing and Engineering Sciences. Strathmore is a private university in Nairobi. The programme has been developed with global and local key players in the IT security industry and is delivered via video conferencing and face-to-face sessions by internationally recognised experts.

Students develop competencies in information security, network security, digital forensics, software security, risk management, and security governance. The programme includes 7 modules with coursework, practical assessments, examinations, and a research project.

The programme is delivered over two years on a part-time basis, with classes running from 5:30pm to 8:30pm EAT. Total programme fee is KES 1,408,500 payable over 6 semesters. Intakes are in May and September. Interview fee is KES 2,500.

Graduates pursue careers as information security managers, cybersecurity analysts, digital forensics investigators, network security engineers, security consultants, and lecturers in banks, telecommunications companies, government, consulting firms, and universities.

Skills Required

  • Information Systems Security and Governance
  • Network Security and Infrastructure Protection
  • Digital Forensics and Investigation
  • Software Security and Secure Coding
  • Cryptography and Cryptographic Protocols
  • Risk Management and Security Assessment
  • Penetration Testing and Vulnerability Assessment
  • Incident Response and Threat Management
  • Security Policy and Compliance
  • Information Security Research Methods

Key Subjects

  • Information Systems Security
  • Network Security
  • Digital Forensics
  • Software Security
  • Cryptography
  • Security Governance and Risk Management
  • Penetration Testing
  • Incident Response
  • Security Policy and Compliance
  • Information Security Research Methods

Certifications

  • ISC2 CISSP Certification
  • ISACA CISM Certification

Specializations

Digital Forensics

Focuses on digital forensics, digital investigation, forensic methods, evidence preservation, forensic tools, and implementing technical security mechanisms to protect critical data.

Network Security

Examines network security, network architecture security, network infrastructure protection, network traffic security, firewalls, IDS/IPS, and securing network environments.

Software Security

Covers software security, secure coding, application security, operating system security, software vulnerabilities, and enhancing security in information systems and applications.

Security Governance and Risk Management

Focuses on security governance, risk management, security policies, compliance, security standards, ISO 27001, and managing and governing information security in organisations.

Penetration Testing

Examines penetration testing, vulnerability assessment, ethical hacking, security testing, exploitation, and identifying and addressing security vulnerabilities.

Incident Response and Threat Management

Covers incident response, threat management, security monitoring, threat intelligence, security operations, and detecting, responding to, and managing security incidents.

Duration
2 years
Public, up to
Ksh 266,000
Private, up to
Ksh 704,250
Job market
Very high

The programme

What you study, how long it takes, and how it is delivered.

Practicalities

Study mode
Part-time
Attachment
0 months
Average class
25 students
Award
Masters

What you study

10 subjects
  • Information Systems Security
  • Network Security
  • Digital Forensics
  • Software Security
  • Cryptography
  • Security Governance and Risk Management
  • Penetration Testing
  • Incident Response
  • Security Policy and Compliance
  • Information Security Research Methods

Modules

12 in the programme
  • Information Systems Security Foundations

    Year 1Semester 13 creditsCore

    Examines information systems security principles, security frameworks, security governance, security policies, security models, and understanding and managing information systems security.

  • Network Security

    Year 1Semester 13 creditsCore

    Covers network security, network architecture security, network infrastructure protection, firewalls, IDS/IPS, VPNs, network traffic analysis, and securing network environments.

  • Cryptography and Cryptographic Protocols

    Year 1Semester 13 creditsCore

    Examines cryptographic algorithms, symmetric and asymmetric cryptography, cryptographic protocols, public key infrastructure, digital signatures, encryption, and applying cryptography in information security.

  • Digital Forensics and Investigation

    Year 1Semester 23 creditsCore

    Covers digital forensics, digital investigation methods, forensic tools, evidence preservation, disk forensics, memory forensics, network forensics, mobile forensics, and implementing technical security mechanisms.

  • Software Security and Secure Coding

    Year 1Semester 23 creditsCore

    Examines software security, secure coding, application security, OWASP Top 10, software vulnerabilities, buffer overflows, injection attacks, and enhancing security in information systems and applications.

  • Risk Management and Security Assessment

    Year 1Semester 23 creditsCore

    Covers security risk assessment, risk analysis, risk treatment, ISO 27005, threat modelling, vulnerability assessment, and managing and assessing security risks in organisations.

  • Penetration Testing and Ethical Hacking

    Year 2Semester 13 creditsCore

    Examines penetration testing, ethical hacking, vulnerability assessment, exploitation, metasploit, Nmap, Burp Suite, and identifying and addressing security vulnerabilities.

  • Incident Response and Threat Management

    Year 2Semester 13 creditsCore

    Covers incident response, incident handling, security monitoring, SIEM, threat intelligence, security operations, and detecting, responding to, and managing security incidents.

  • Security Governance and Compliance

    Year 2Semester 13 creditsCore

    Examines security governance, ISO 27001, security standards, compliance, audit, security metrics, security strategy, and governing and managing information security in organisations.

  • Information Security Research Methods

    Year 2Semester 13 creditsCore

    Covers research methods for information security, experimental design, security evaluation, data analysis, and conducting information security research, preparing students for their research project.

  • Cloud Security and Emerging Technologies

    Year 2Semester 23 creditsCore

    Examines cloud security, cloud security architecture, container security, IoT security, AI in security, blockchain security, and securing emerging technologies.

  • Research Project

    Year 2Semester 26 creditsCore

    Original research project on an information systems security topic, demonstrating mastery of security concepts and research methods, assessed through written submission and oral defence.

Specialisations

  • Digital Forensics

    Focuses on digital forensics, digital investigation, forensic methods, evidence preservation, forensic tools, and implementing technical security mechanisms to protect critical data.

  • Network Security

    Examines network security, network architecture security, network infrastructure protection, network traffic security, firewalls, IDS/IPS, and securing network environments.

  • Software Security

    Covers software security, secure coding, application security, operating system security, software vulnerabilities, and enhancing security in information systems and applications.

  • Security Governance and Risk Management

    Focuses on security governance, risk management, security policies, compliance, security standards, ISO 27001, and managing and governing information security in organisations.

  • Penetration Testing

    Examines penetration testing, vulnerability assessment, ethical hacking, security testing, exploitation, and identifying and addressing security vulnerabilities.

  • Incident Response and Threat Management

    Covers incident response, threat management, security monitoring, threat intelligence, security operations, and detecting, responding to, and managing security incidents.

A day as a student

A typical day during the MSc Information Systems Security programme at Strathmore begins with evening classes from 5:30pm to 8:30pm, as the programme is delivered on a part-time basis. Students attend video conferencing and face-to-face sessions delivered by internationally recognised experts and faculty. Information systems security sessions cover security principles, security frameworks, security governance, security policies, and understanding and managing information systems security. Network security sessions examine network architecture security, network infrastructure protection, firewalls, IDS/IPS, VPNs, network traffic analysis, and securing network environments. Digital forensics sessions cover digital investigation methods, forensic tools, evidence preservation, disk forensics, memory forensics, network forensics, mobile forensics, and implementing technical security mechanisms. Software security sessions examine secure coding, application security, OWASP, software vulnerabilities, buffer overflows, injection attacks, and enhancing security in applications. Cryptography sessions cover cryptographic algorithms, cryptographic protocols, public key infrastructure, digital signatures, encryption, and applying cryptography in information security. Risk management sessions examine security risk assessment, risk analysis, risk treatment, ISO 27005, and managing and assessing security risks. Penetration testing sessions cover ethical hacking, vulnerability assessment, exploitation, metasploit, Nmap, Burp Suite, and identifying and addressing security vulnerabilities. Incident response sessions examine incident response, incident handling, security monitoring, SIEM, threat intelligence, and detecting, responding to, and managing security incidents. Security governance sessions cover security governance, ISO 27001, security standards, compliance, audit, security metrics, and governing and managing information security. Practical sessions provide hands-on experience with security tools, forensic tools, penetration testing tools, and security assessment. The programme is structured in 7 modules with an average of 5 units per module, blending academic teaching, industry input, and practical skills. Guest lectures from KE-CIRT analysts, ISACA professionals, ISC2 certified experts, and cybersecurity industry leaders provide real-world insights. The two-year programme includes a research project.

The trade offs

In its favour

  • Strathmore's MSc ISS is developed with global and local IT security industry players, delivered by internationally recognised experts, ensuring industry-relevant curriculum.
  • Kenya's growing digital economy, cyber threats, data protection requirements, and KE-CIRT operations create very high demand for qualified information security professionals.
  • Programme covers both technical and managerial aspects of IT security, providing versatile skills for both technical and management career paths.
  • Part-time delivery (5:30pm-8:30pm) accommodates working professionals, allowing students to continue working while studying.

Against it

  • Total programme fee of KES 1,408,500 is relatively expensive compared to public university postgraduate programmes.
  • Only one university (Strathmore) offers this specific programme, limiting choice and geographic access for prospective students.
  • Programme requires IT or related background and is ideally suited for information security professionals, which may exclude some graduates.
  • Information security is a rapidly evolving field, requiring continuous learning and updating of knowledge beyond the programme.

What it costs

Tuition at both ends of the market, and how to pay for it.

What it costs, and where

Against 191 technology courses
Public266k to 266k
266k at Technical University of Kenya266k at Technical University of Kenya
Private704k to 704k
704k at Strathmore University704k at Strathmore University

Annual tuition in Kenyan shillings, rounded. The upright tick is the median for this field, so a bar sitting entirely to its right is an expensive programme by the standards of its own subject.

The fine print

Strathmore MSc ISS 704K/yr (sces.strathmore.edu). TUK ICT 266K/yr (eafinder.com). JKUAT unverified.

Strathmore University offers scholarships and financial aid options for eligible students. HELB postgraduate loans are available for Kenyan students. ISC2 supports information security professional development. ISACA supports IT governance and security professional development. SANS Institute supports cybersecurity training. The programme's cybersecurity focus attracts significant industry and professional body funding.

Funding options

  • Strathmore Financial Aid

  • HELB Postgraduate Loan

  • ISC2 Certification Funding

Scholarships

3 recorded
  • Strathmore Financial Aid

    GrantKsh 500,000Kenyan

    Strathmore University offers scholarships and financial aid options for eligible students demonstrating academic merit and financial need.

  • HELB Postgraduate Loan

    LoanKsh 200,000Kenyan

    Kenyan students pursuing postgraduate information systems security studies at recognised universities.

  • ISC2 Certification Funding

    GrantKsh 400,000

    ISC2 supports information security professional development, providing funding for training and certifications like CISSP globally.

Getting in

The grades, the alternatives, and who accredits the award.

What you need

KCSE mean grade
N/A (Postgraduate)
Alternative entry
The programme is designed for IT professionals and graduates wanting leadership positions in information security. Two-year part-time programme (classes 5:30pm-8:30pm EAT). 7 modules with average 5 units per module. Total fee KES 1,408,500 over 6 semesters. Interview fee KES 2,500. Intakes in May and September. Delivered via video conferencing and face-to-face sessions.

How you are assessed

4 components
  • Coursework and Assignments

    Coursework30% of the mark

    Continuous assessment through coursework assignments, security analysis projects, case studies, practical exercises, and class participation.

  • Written Examinations

    Examination30% of the mark

    Written examinations covering information security, network security, forensics, and risk management, conducted at end of each module.

  • Practical Security Assessment

    Practical40% of the mark

    Assessment of practical security exercises, penetration testing, forensic analysis, security assessments, and hands-on security projects.

  • Research Project

    Research100% of the mark

    Original research project on an information systems security topic, demonstrating mastery of security concepts and research methods, assessed through written submission and oral defence.

Accreditation

The programme is accredited by the Commission for University Education (CUE). Strathmore University offers MSc in Information Systems Security through its School of Computing and Engineering Sciences, developed with global and local IT security industry players. The programme meets CUE standards for postgraduate information systems security training. CA regulates cyber security through KE-CIRT and ODPC enforces data protection in Kenya.

Accredited by

  • Commission for University Education (CUE)

    Academic accreditationRequired

    Programme accredited by CUE. Strathmore University offers MSc in Information Systems Security through its School of Computing and Engineering Sciences, developed with global and local IT security industry players. The programme meets CUE standards for postgraduate information systems security training.

  • International Information System Security Certification Consortium (ISC2)

    Professional accreditation

    ISC2 provides CISSP, CCSP, SSCP certifications. Graduates may benefit from ISC2 professional certifications for career advancement in information security.

Where it leads

The roles it opens, and what you leave with.

Where graduates go

6 roles
  • Information Security Manager

    Very high demandKsh 150,000 to Ksh 650,000

    Manages information security in organisations, overseeing security strategy, policies, controls, compliance, and ensuring information assets are protected.

  • Cybersecurity Analyst

    Very high demandKsh 130,000 to Ksh 550,000

    Monitors and analyses cyber threats, overseeing threat detection, incident analysis, security monitoring, and supporting cyber defence operations.

  • Digital Forensics Investigator

    High demandKsh 130,000 to Ksh 550,000

    Conducts digital forensics investigations, overseeing evidence collection, forensic analysis, investigation reports, and supporting legal and disciplinary proceedings.

  • Network Security Engineer

    High demandKsh 130,000 to Ksh 550,000

    Designs and implements network security, overseeing firewalls, IDS/IPS, VPNs, network security architecture, and ensuring network infrastructure protection.

  • Security Consultant

    High demandKsh 140,000 to Ksh 600,000

    Provides security consulting services, overseeing security assessments, risk analysis, security architecture, and advising organisations on information security.

  • University Lecturer

    High demandKsh 130,000 to Ksh 500,000

    Teaches information systems security in universities, conducting research and training future information security professionals.

Graduate outcomes

Graduates pursue careers as information security managers, cybersecurity analysts, and digital forensics investigators in banks, telecommunications companies, government, and consulting firms.

Where these fields lead

8 careers

Tools you will learn

  • Kali Linux

    SoftwarePrimary

    Penetration testing and security auditing platform with pre-installed security tools including Nmap, Metasploit, Wireshark, Burp Suite, and John the Ripper.

  • Wireshark

    SoftwarePrimary

    Network protocol analyser for network traffic analysis, packet capture, network troubleshooting, and network security analysis.

  • Metasploit

    Software

    Penetration testing framework for exploitation, vulnerability verification, security testing, and penetration testing of information systems.

  • Autopsy

    Software

    Digital forensics platform for disk forensics, file system analysis, evidence examination, and digital investigation.

Industry links

Common misconceptions

  • Information systems security is just about installing antivirus software.

    The programme involves network security, digital forensics, cryptography, risk management, governance, penetration testing, and research, covering comprehensive information security, not just antivirus.

  • This programme is only for IT graduates.

    The programme is suited for information security professionals, network administrators, and graduates who want leadership positions in information security, from IT, computer science, and related fields.

  • There is limited demand for cybersecurity professionals in Kenya.

    Kenya's growing digital economy, cyber threats, data protection requirements, and KE-CIRT operations create very high demand for qualified information security professionals.

  • Cybersecurity is only a technical field.

    The programme covers both technical and managerial aspects of IT security, including governance, risk management, policy, compliance, and leadership.

  • A master's in information security is redundant after IT certifications.

    The master's provides comprehensive security knowledge, research capability, and career progression to senior security management and CISO positions beyond what certifications offer.

  • Information security has no career prospects outside IT companies.

    Every organisation with digital assets needs information security professionals, including banks, government, healthcare, manufacturing, NGOs, and consulting firms.

Related courses

Further reading

Keep this

Fees and entry marks for Master of Science in Information Systems Security are restated every intake. Save it and the app keeps this version, so you can see what changed when it does.