Master of Science in Information Systems Security
The Master of Science in Information Systems Security is a postgraduate programme that trains graduates in cybersecurity, information systems security, digital forensics, and network security. The programme prepares graduates for advanced careers in information security management, cybersecurity analysis, digital forensics, and security governance.
Core areas include information systems security, network security, digital forensics, software security, cryptography, security governance, risk management, penetration testing, incident response, and research methods. Students engage with both technical and managerial aspects of IT security, blending academic teaching with industry input and practical skills.
The programme is offered by Strathmore University through its School of Computing and Engineering Sciences. Strathmore is a private university in Nairobi. The programme has been developed with global and local key players in the IT security industry and is delivered via video conferencing and face-to-face sessions by internationally recognised experts.
Students develop competencies in information security, network security, digital forensics, software security, risk management, and security governance. The programme includes 7 modules with coursework, practical assessments, examinations, and a research project.
The programme is delivered over two years on a part-time basis, with classes running from 5:30pm to 8:30pm EAT. Total programme fee is KES 1,408,500 payable over 6 semesters. Intakes are in May and September. Interview fee is KES 2,500.
Graduates pursue careers as information security managers, cybersecurity analysts, digital forensics investigators, network security engineers, security consultants, and lecturers in banks, telecommunications companies, government, consulting firms, and universities.
Skills Required
- Information Systems Security and Governance
- Network Security and Infrastructure Protection
- Digital Forensics and Investigation
- Software Security and Secure Coding
- Cryptography and Cryptographic Protocols
- Risk Management and Security Assessment
- Penetration Testing and Vulnerability Assessment
- Incident Response and Threat Management
- Security Policy and Compliance
- Information Security Research Methods
Key Subjects
- Information Systems Security
- Network Security
- Digital Forensics
- Software Security
- Cryptography
- Security Governance and Risk Management
- Penetration Testing
- Incident Response
- Security Policy and Compliance
- Information Security Research Methods
Certifications
- ISC2 CISSP Certification
- ISACA CISM Certification
Specializations
Digital Forensics
Focuses on digital forensics, digital investigation, forensic methods, evidence preservation, forensic tools, and implementing technical security mechanisms to protect critical data.
Network Security
Examines network security, network architecture security, network infrastructure protection, network traffic security, firewalls, IDS/IPS, and securing network environments.
Software Security
Covers software security, secure coding, application security, operating system security, software vulnerabilities, and enhancing security in information systems and applications.
Security Governance and Risk Management
Focuses on security governance, risk management, security policies, compliance, security standards, ISO 27001, and managing and governing information security in organisations.
Penetration Testing
Examines penetration testing, vulnerability assessment, ethical hacking, security testing, exploitation, and identifying and addressing security vulnerabilities.
Incident Response and Threat Management
Covers incident response, threat management, security monitoring, threat intelligence, security operations, and detecting, responding to, and managing security incidents.
- Duration
- 2 years
- Public, up to
- Ksh 266,000
- Private, up to
- Ksh 704,250
- Job market
- Very high
The programme
What you study, how long it takes, and how it is delivered.
Practicalities
- Study mode
- Part-time
- Attachment
- 0 months
- Average class
- 25 students
- Award
- Masters
What you study
10 subjects- Information Systems Security
- Network Security
- Digital Forensics
- Software Security
- Cryptography
- Security Governance and Risk Management
- Penetration Testing
- Incident Response
- Security Policy and Compliance
- Information Security Research Methods
Modules
12 in the programmeInformation Systems Security Foundations
Year 1Semester 13 creditsCore
Examines information systems security principles, security frameworks, security governance, security policies, security models, and understanding and managing information systems security.
Network Security
Year 1Semester 13 creditsCore
Covers network security, network architecture security, network infrastructure protection, firewalls, IDS/IPS, VPNs, network traffic analysis, and securing network environments.
Cryptography and Cryptographic Protocols
Year 1Semester 13 creditsCore
Examines cryptographic algorithms, symmetric and asymmetric cryptography, cryptographic protocols, public key infrastructure, digital signatures, encryption, and applying cryptography in information security.
Digital Forensics and Investigation
Year 1Semester 23 creditsCore
Covers digital forensics, digital investigation methods, forensic tools, evidence preservation, disk forensics, memory forensics, network forensics, mobile forensics, and implementing technical security mechanisms.
Software Security and Secure Coding
Year 1Semester 23 creditsCore
Examines software security, secure coding, application security, OWASP Top 10, software vulnerabilities, buffer overflows, injection attacks, and enhancing security in information systems and applications.
Risk Management and Security Assessment
Year 1Semester 23 creditsCore
Covers security risk assessment, risk analysis, risk treatment, ISO 27005, threat modelling, vulnerability assessment, and managing and assessing security risks in organisations.
Penetration Testing and Ethical Hacking
Year 2Semester 13 creditsCore
Examines penetration testing, ethical hacking, vulnerability assessment, exploitation, metasploit, Nmap, Burp Suite, and identifying and addressing security vulnerabilities.
Incident Response and Threat Management
Year 2Semester 13 creditsCore
Covers incident response, incident handling, security monitoring, SIEM, threat intelligence, security operations, and detecting, responding to, and managing security incidents.
Security Governance and Compliance
Year 2Semester 13 creditsCore
Examines security governance, ISO 27001, security standards, compliance, audit, security metrics, security strategy, and governing and managing information security in organisations.
Information Security Research Methods
Year 2Semester 13 creditsCore
Covers research methods for information security, experimental design, security evaluation, data analysis, and conducting information security research, preparing students for their research project.
Cloud Security and Emerging Technologies
Year 2Semester 23 creditsCore
Examines cloud security, cloud security architecture, container security, IoT security, AI in security, blockchain security, and securing emerging technologies.
Research Project
Year 2Semester 26 creditsCore
Original research project on an information systems security topic, demonstrating mastery of security concepts and research methods, assessed through written submission and oral defence.
Specialisations
Digital Forensics
Focuses on digital forensics, digital investigation, forensic methods, evidence preservation, forensic tools, and implementing technical security mechanisms to protect critical data.
Network Security
Examines network security, network architecture security, network infrastructure protection, network traffic security, firewalls, IDS/IPS, and securing network environments.
Software Security
Covers software security, secure coding, application security, operating system security, software vulnerabilities, and enhancing security in information systems and applications.
Security Governance and Risk Management
Focuses on security governance, risk management, security policies, compliance, security standards, ISO 27001, and managing and governing information security in organisations.
Penetration Testing
Examines penetration testing, vulnerability assessment, ethical hacking, security testing, exploitation, and identifying and addressing security vulnerabilities.
Incident Response and Threat Management
Covers incident response, threat management, security monitoring, threat intelligence, security operations, and detecting, responding to, and managing security incidents.
A day as a student
A typical day during the MSc Information Systems Security programme at Strathmore begins with evening classes from 5:30pm to 8:30pm, as the programme is delivered on a part-time basis. Students attend video conferencing and face-to-face sessions delivered by internationally recognised experts and faculty. Information systems security sessions cover security principles, security frameworks, security governance, security policies, and understanding and managing information systems security. Network security sessions examine network architecture security, network infrastructure protection, firewalls, IDS/IPS, VPNs, network traffic analysis, and securing network environments. Digital forensics sessions cover digital investigation methods, forensic tools, evidence preservation, disk forensics, memory forensics, network forensics, mobile forensics, and implementing technical security mechanisms. Software security sessions examine secure coding, application security, OWASP, software vulnerabilities, buffer overflows, injection attacks, and enhancing security in applications. Cryptography sessions cover cryptographic algorithms, cryptographic protocols, public key infrastructure, digital signatures, encryption, and applying cryptography in information security. Risk management sessions examine security risk assessment, risk analysis, risk treatment, ISO 27005, and managing and assessing security risks. Penetration testing sessions cover ethical hacking, vulnerability assessment, exploitation, metasploit, Nmap, Burp Suite, and identifying and addressing security vulnerabilities. Incident response sessions examine incident response, incident handling, security monitoring, SIEM, threat intelligence, and detecting, responding to, and managing security incidents. Security governance sessions cover security governance, ISO 27001, security standards, compliance, audit, security metrics, and governing and managing information security. Practical sessions provide hands-on experience with security tools, forensic tools, penetration testing tools, and security assessment. The programme is structured in 7 modules with an average of 5 units per module, blending academic teaching, industry input, and practical skills. Guest lectures from KE-CIRT analysts, ISACA professionals, ISC2 certified experts, and cybersecurity industry leaders provide real-world insights. The two-year programme includes a research project.
The trade offs
In its favour
- Strathmore's MSc ISS is developed with global and local IT security industry players, delivered by internationally recognised experts, ensuring industry-relevant curriculum.
- Kenya's growing digital economy, cyber threats, data protection requirements, and KE-CIRT operations create very high demand for qualified information security professionals.
- Programme covers both technical and managerial aspects of IT security, providing versatile skills for both technical and management career paths.
- Part-time delivery (5:30pm-8:30pm) accommodates working professionals, allowing students to continue working while studying.
Against it
- Total programme fee of KES 1,408,500 is relatively expensive compared to public university postgraduate programmes.
- Only one university (Strathmore) offers this specific programme, limiting choice and geographic access for prospective students.
- Programme requires IT or related background and is ideally suited for information security professionals, which may exclude some graduates.
- Information security is a rapidly evolving field, requiring continuous learning and updating of knowledge beyond the programme.
What it costs
Tuition at both ends of the market, and how to pay for it.
What it costs, and where
Against 191 technology coursesAnnual tuition in Kenyan shillings, rounded. The upright tick is the median for this field, so a bar sitting entirely to its right is an expensive programme by the standards of its own subject.
The fine print
Strathmore MSc ISS 704K/yr (sces.strathmore.edu). TUK ICT 266K/yr (eafinder.com). JKUAT unverified.
Strathmore University offers scholarships and financial aid options for eligible students. HELB postgraduate loans are available for Kenyan students. ISC2 supports information security professional development. ISACA supports IT governance and security professional development. SANS Institute supports cybersecurity training. The programme's cybersecurity focus attracts significant industry and professional body funding.
Funding options
Strathmore Financial Aid
HELB Postgraduate Loan
ISC2 Certification Funding
Scholarships
3 recordedStrathmore Financial Aid
GrantKsh 500,000Kenyan
Strathmore University offers scholarships and financial aid options for eligible students demonstrating academic merit and financial need.
HELB Postgraduate Loan
LoanKsh 200,000Kenyan
Kenyan students pursuing postgraduate information systems security studies at recognised universities.
ISC2 Certification Funding
GrantKsh 400,000
ISC2 supports information security professional development, providing funding for training and certifications like CISSP globally.
Getting in
The grades, the alternatives, and who accredits the award.
What you need
- KCSE mean grade
- N/A (Postgraduate)
- Alternative entry
- The programme is designed for IT professionals and graduates wanting leadership positions in information security. Two-year part-time programme (classes 5:30pm-8:30pm EAT). 7 modules with average 5 units per module. Total fee KES 1,408,500 over 6 semesters. Interview fee KES 2,500. Intakes in May and September. Delivered via video conferencing and face-to-face sessions.
How you are assessed
4 componentsCoursework and Assignments
Coursework30% of the mark
Continuous assessment through coursework assignments, security analysis projects, case studies, practical exercises, and class participation.
Written Examinations
Examination30% of the mark
Written examinations covering information security, network security, forensics, and risk management, conducted at end of each module.
Practical Security Assessment
Practical40% of the mark
Assessment of practical security exercises, penetration testing, forensic analysis, security assessments, and hands-on security projects.
Research Project
Research100% of the mark
Original research project on an information systems security topic, demonstrating mastery of security concepts and research methods, assessed through written submission and oral defence.
Accreditation
The programme is accredited by the Commission for University Education (CUE). Strathmore University offers MSc in Information Systems Security through its School of Computing and Engineering Sciences, developed with global and local IT security industry players. The programme meets CUE standards for postgraduate information systems security training. CA regulates cyber security through KE-CIRT and ODPC enforces data protection in Kenya.
Accredited by
Commission for University Education (CUE)
Academic accreditationRequired
Programme accredited by CUE. Strathmore University offers MSc in Information Systems Security through its School of Computing and Engineering Sciences, developed with global and local IT security industry players. The programme meets CUE standards for postgraduate information systems security training.
International Information System Security Certification Consortium (ISC2)
Professional accreditation
ISC2 provides CISSP, CCSP, SSCP certifications. Graduates may benefit from ISC2 professional certifications for career advancement in information security.
Where it leads
The roles it opens, and what you leave with.
Where graduates go
6 rolesInformation Security Manager
Very high demandKsh 150,000 to Ksh 650,000
Manages information security in organisations, overseeing security strategy, policies, controls, compliance, and ensuring information assets are protected.
Cybersecurity Analyst
Very high demandKsh 130,000 to Ksh 550,000
Monitors and analyses cyber threats, overseeing threat detection, incident analysis, security monitoring, and supporting cyber defence operations.
Digital Forensics Investigator
High demandKsh 130,000 to Ksh 550,000
Conducts digital forensics investigations, overseeing evidence collection, forensic analysis, investigation reports, and supporting legal and disciplinary proceedings.
Network Security Engineer
High demandKsh 130,000 to Ksh 550,000
Designs and implements network security, overseeing firewalls, IDS/IPS, VPNs, network security architecture, and ensuring network infrastructure protection.
Security Consultant
High demandKsh 140,000 to Ksh 600,000
Provides security consulting services, overseeing security assessments, risk analysis, security architecture, and advising organisations on information security.
University Lecturer
High demandKsh 130,000 to Ksh 500,000
Teaches information systems security in universities, conducting research and training future information security professionals.
Graduate outcomes
Graduates pursue careers as information security managers, cybersecurity analysts, and digital forensics investigators in banks, telecommunications companies, government, and consulting firms.
Where these fields lead
8 careers- Career Guidance & Labour Market Information CounselorEducation11Low exposure
- School Guidance CounselorEducation17Low exposure
- CrystallographerScience19Low exposure
- StatisticsScience20Low exposure
- Motor Vehicle MechanicEducation21Low exposure
- MycologistScience21Low exposure
- OceanographerScience21Low exposure
- Computational BiologistScience22Low exposure
Tools you will learn
Kali Linux
SoftwarePrimary
Penetration testing and security auditing platform with pre-installed security tools including Nmap, Metasploit, Wireshark, Burp Suite, and John the Ripper.
Wireshark
SoftwarePrimary
Network protocol analyser for network traffic analysis, packet capture, network troubleshooting, and network security analysis.
Metasploit
Software
Penetration testing framework for exploitation, vulnerability verification, security testing, and penetration testing of information systems.
Autopsy
Software
Digital forensics platform for disk forensics, file system analysis, evidence examination, and digital investigation.
Industry links
Common misconceptions
Information systems security is just about installing antivirus software.
The programme involves network security, digital forensics, cryptography, risk management, governance, penetration testing, and research, covering comprehensive information security, not just antivirus.
This programme is only for IT graduates.
The programme is suited for information security professionals, network administrators, and graduates who want leadership positions in information security, from IT, computer science, and related fields.
There is limited demand for cybersecurity professionals in Kenya.
Kenya's growing digital economy, cyber threats, data protection requirements, and KE-CIRT operations create very high demand for qualified information security professionals.
Cybersecurity is only a technical field.
The programme covers both technical and managerial aspects of IT security, including governance, risk management, policy, compliance, and leadership.
A master's in information security is redundant after IT certifications.
The master's provides comprehensive security knowledge, research capability, and career progression to senior security management and CISO positions beyond what certifications offer.
Information security has no career prospects outside IT companies.
Every organisation with digital assets needs information security professionals, including banks, government, healthcare, manufacturing, NGOs, and consulting firms.
Related courses
Further reading
- Strathmore University — School of Computing and Engineering Sciences
- Communications Authority of Kenya (CA) — Cyber Security
- Office of the Data Protection Commissioner (ODPC)
- National Kenya Computer Incident Response Team (KE-CIRT)
- Information Systems Audit and Control Association (ISACA) Kenya Chapter
- International Information System Security Certification Consortium (ISC2)
- SANS Institute
Fees and entry marks for Master of Science in Information Systems Security are restated every intake. Save it and the app keeps this version, so you can see what changed when it does.