Master of Science in IT Security and Audit
The Master of Science in IT Security and Audit is a postgraduate programme that prepares professionals for advanced practice in information security, cybersecurity, IT audit, and risk management. The programme combines security theory with practical cybersecurity, digital forensics, and IT audit application.
Core areas include information systems security, network security, digital forensics, IT audit and assurance, risk management, cryptography, governance and compliance, penetration testing, incident response, research methods, and thesis. Students engage with both security theory and practical laboratory and industry work through coursework and research.
The programme is offered by Kabarak University, Strathmore University, and the University of Nairobi. Kabarak offers MSc in IT Security and Audit at Nakuru City Campus, Strathmore offers MSc in Information Systems Security through the School of Computing and Engineering Sciences, and UoN offers MSc in Information Systems with security and audit modules. Kabarak and Strathmore are private universities, while UoN is public.
Students develop competencies in information systems security, network security, digital forensics, IT audit and assurance, risk management, cryptography, governance and compliance, and penetration testing. The programme includes coursework, examinations, laboratory work, industry placements, and a supervised research thesis.
Kabarak charges KES 80,000/semester (KES 160,000/year, KES 320,000 total) for IT security and audit. Strathmore charges approximately KES 704,250/year (KES 1,408,500 total) for information systems security. UoN charges approximately KES 486,000/year (KES 972,000 total) for information systems. Entry requires a Bachelor's degree with Second Class Honours Upper Division in computer science, IT, or related fields from a recognised university.
Graduates pursue careers as information security analysts, cybersecurity engineers, IT auditors, digital forensics analysts, penetration testers, security consultants, and chief information security officers across financial institutions, government agencies, consulting firms, technology companies, and universities.
Skills Required
- Information Systems Security and Risk Management
- Network Security and Defence Architecture
- Digital Forensics and Incident Response
- IT Audit and Compliance Assurance
- Cryptography and Cryptographic Protocols
- Penetration Testing and Vulnerability Assessment
- Security Governance and Policy Development
- Malware Analysis and Threat Intelligence
- Research Methods in Information Security
- Academic Writing and Thesis Research
Key Subjects
- Information Systems Security and Risk Management
- Network Security and Defence Architecture
- Digital Forensics and Incident Response
- IT Audit and Compliance Assurance
- Cryptography and Cryptographic Protocols
- Penetration Testing and Vulnerability Assessment
- Security Governance and Policy Development
- Malware Analysis and Threat Intelligence
- Research Methods in Information Security
- Thesis Research
Certifications
- CISSP Certification
- CISA Certification
Specializations
Digital Forensics
Focuses on digital forensics, covering digital investigation, evidence collection, analysis, reporting, and managing digital forensics.
Network Security
Examines network security, covering network architecture, infrastructure security, traffic analysis, firewalls, and managing network security.
IT Audit and Assurance
Covers IT audit, covering audit planning, controls testing, compliance, assurance, reporting, and managing IT audit.
Cybersecurity Management
Focuses on cybersecurity management, covering security governance, risk management, policy, strategy, and managing cybersecurity.
Penetration Testing
Examines penetration testing, covering vulnerability assessment, exploitation, reporting, remediation, and managing penetration testing.
Security Governance and Compliance
Covers security governance, covering governance frameworks, compliance, regulations, standards, and managing security governance.
- Duration
- 2 years
- Public, up to
- Ksh 486,000
- Private, up to
- Ksh 704,250
- Job market
- Very high
The programme
What you study, how long it takes, and how it is delivered.
Practicalities
- Study mode
- Full-time, Part-time
- Attachment
- 0 months
- Average class
- 25 students
- Award
- Masters
What you study
10 subjects- Information Systems Security and Risk Management
- Network Security and Defence Architecture
- Digital Forensics and Incident Response
- IT Audit and Compliance Assurance
- Cryptography and Cryptographic Protocols
- Penetration Testing and Vulnerability Assessment
- Security Governance and Policy Development
- Malware Analysis and Threat Intelligence
- Research Methods in Information Security
- Thesis Research
Modules
12 in the programmeInformation Systems Security and Risk Management
Year 1Semester 13 creditsCore
Examines confidentiality, integrity, availability, access control, security models, risk identification, and managing information security.
Network Security and Defence Architecture
Year 1Semester 13 creditsCore
Covers network architecture, firewalls, IDS/IPS, VPN, network traffic analysis, and managing network security.
Research Methods in Information Security
Year 1Semester 13 creditsCore
Covers research design, data collection, analysis, security research methods, and conducting information security research, preparing students for their thesis.
Cryptography and Cryptographic Protocols
Year 1Semester 23 creditsCore
Examines symmetric encryption, asymmetric encryption, hash functions, digital signatures, key management, and managing cryptography.
Digital Forensics and Incident Response
Year 1Semester 23 creditsCore
Covers digital investigation, evidence collection, preservation, analysis, reporting, incident handling, and managing digital forensics.
IT Audit and Compliance Assurance
Year 1Semester 23 creditsCore
Examines audit planning, controls testing, compliance, assurance, COBIT, ISO 27001, and managing IT audit.
Penetration Testing and Vulnerability Assessment
Year 1Semester 23 creditsCore
Covers vulnerability assessment, exploitation, Metasploit, Nmap, reporting, remediation, and managing penetration testing.
Security Governance and Policy Development
Year 2Semester 13 creditsCore
Examines governance frameworks, ISO 27001, NIST, regulations, standards, policy development, and managing security governance.
Malware Analysis and Threat Intelligence
Year 2Semester 13 creditsCore
Covers malware types, analysis techniques, reverse engineering, threat intelligence, indicators of compromise, and managing malware analysis.
Software Security and Secure Coding
Year 2Semester 13 creditsCore
Examines secure coding, OWASP, SQL injection, XSS, CSRF, secure SDLC, and managing software security.
Cloud Security and Virtualisation Security
Year 2Semester 13 creditsCore
Covers cloud security models, AWS/Azure security, container security, virtualisation security, and managing cloud security.
Research Thesis
Year 2Semester 29 creditsCore
Original supervised research thesis on an IT security and audit topic, demonstrating mastery of research methods and security knowledge, assessed through written submission and oral defence.
Specialisations
Digital Forensics
Focuses on digital forensics, covering digital investigation, evidence collection, analysis, reporting, and managing digital forensics.
Network Security
Examines network security, covering network architecture, infrastructure security, traffic analysis, firewalls, and managing network security.
IT Audit and Assurance
Covers IT audit, covering audit planning, controls testing, compliance, assurance, reporting, and managing IT audit.
Cybersecurity Management
Focuses on cybersecurity management, covering security governance, risk management, policy, strategy, and managing cybersecurity.
Penetration Testing
Examines penetration testing, covering vulnerability assessment, exploitation, reporting, remediation, and managing penetration testing.
Security Governance and Compliance
Covers security governance, covering governance frameworks, compliance, regulations, standards, and managing security governance.
A day as a student
A typical day during the MSc in IT Security and Audit programme combines lectures, laboratory sessions, practical workshops, industry placements, seminars, and independent study. Sessions cover information security, network security, digital forensics, and IT audit. Information systems security sessions examine confidentiality, integrity, availability, access control, security models, and managing information security. Network security sessions cover network architecture, firewalls, IDS/IPS, VPN, network traffic analysis, and managing network security. Digital forensics sessions cover digital investigation, evidence collection, preservation, analysis, reporting, and managing digital forensics. IT audit sessions cover audit planning, controls testing, compliance, assurance, COBIT, and managing IT audit. Risk management sessions cover risk identification, assessment, mitigation, treatment, monitoring, and managing security risk. Cryptography sessions cover symmetric encryption, asymmetric encryption, hash functions, digital signatures, protocols, and managing cryptography. Governance and compliance sessions cover governance frameworks, ISO 27001, NIST, regulations, standards, and managing security governance. Penetration testing sessions cover vulnerability assessment, exploitation, Metasploit, reporting, remediation, and managing penetration testing. Incident response sessions cover incident handling, forensics, malware analysis, threat intelligence, and managing incident response. Research methods sessions prepare students for their thesis, covering research design, data collection, and analysis. Laboratory sessions provide hands-on experience with Kali Linux, Wireshark, Nmap, Metasploit, and forensic tools. Practical workshops provide hands-on experience with penetration testing, digital forensics, security auditing, and incident response. Industry placements at financial institutions, security firms, and government agencies provide real-world exposure. Seminars and discussion groups provide opportunities for debating current issues in cybersecurity. Guest lectures from experienced security professionals, auditors, and forensics experts provide practical insights. The programme culminates in a supervised research thesis on an IT security and audit topic.
The trade offs
In its favour
- Very high demand for IT security professionals with Kenya's digital transformation, cyber threats, financial sector regulations, and data protection laws.
- Programme offered by three universities (Kabarak, Strathmore, UoN), including both private and public options.
- Kabarak University offers very competitive fees at KES 80,000/semester (KES 160,000/year) for IT security and audit.
- Graduates are eligible for globally recognised CISSP and CISA professional certifications, enhancing career prospects.
Against it
- Strathmore fees are significantly higher at approximately KES 704,250/year (KES 1,408,500 total) for information systems security.
- UoN programme is MSc Information Systems with security and audit as modules, not a dedicated IT security programme.
- Programme requires computer science, IT, or related background, which limits access for non-related graduates.
- Rapidly evolving threat landscape requires continuous learning and certification beyond the programme.
What it costs
Tuition at both ends of the market, and how to pay for it.
What it costs, and where
Against 241 social sciences coursesAnnual tuition in Kenyan shillings, rounded. The upright tick is the median for this field, so a bar sitting entirely to its right is an expensive programme by the standards of its own subject.
The fine print
UoN 972K/2yr~486K/yr. Moi 187K. Strathmore 1.4M/2yr704K/yr. Kabarak 160K/yr. Src: uonbi, strathmore
HELB postgraduate loans are available for Kenyan students. Kabarak University may offer bursaries for eligible students. Strathmore University offers scholarships for postgraduate students. Some technology companies and security firms may sponsor staff for postgraduate study.
Funding options
HELB Postgraduate Loan
Kabarak University Bursary
Strathmore Scholarships
Scholarships
3 recordedHELB Postgraduate Loan
LoanKsh 200,000Kenyan
Kenyan students pursuing postgraduate studies at recognised universities.
Kabarak University Bursary
ScholarshipKsh 100,000Kenyan
Kabarak University offers bursaries for eligible postgraduate students.
Strathmore Scholarships
ScholarshipKsh 200,000Kenyan
Strathmore University offers scholarships for postgraduate students demonstrating academic excellence and financial need.
Getting in
The grades, the alternatives, and who accredits the award.
What you need
- KCSE mean grade
- N/A (Postgraduate)
- Alternative entry
- Most universities require Upper Second Class Honours in computer science, IT, or related fields. Lower Second Division holders with relevant experience or postgraduate diplomas are considered. Strathmore also requires an interview. Contact respective universities for specific admission requirements.
How you are assessed
4 componentsCoursework and Continuous Assessment
Coursework30% of the mark
Continuous assessment through coursework assignments, laboratory reports, practical exercises, seminar presentations, and class participation.
Written Examinations
Examination70% of the mark
Written examinations covering information security, network security, digital forensics, IT audit, and cryptography.
Practical and Laboratory Assessment
Practical30% of the mark
Practical assessment through laboratory exercises, penetration testing, digital forensics, security auditing, and demonstrating security skills.
Research Thesis
Research100% of the mark
Original supervised research thesis on an IT security and audit topic, demonstrating mastery of research methods and security knowledge, assessed through written submission and oral defence.
Accreditation
The programme is accredited by the Commission for University Education (CUE). Kabarak University and Strathmore University (both private) and the University of Nairobi (public) offer MSc in IT Security and Audit, Information Systems Security, or related programmes. All programmes meet CUE standards for postgraduate training in IT security and audit. Graduates are eligible for CISSP and CISA professional certifications.
Accredited by
Commission for University Education (CUE)
Academic accreditationRequired
Programme accredited by CUE. Kabarak University and Strathmore University (both private) and the University of Nairobi (public) offer MSc in IT Security and Audit, Information Systems Security, or related programmes. All programmes meet CUE standards for postgraduate training in IT security and audit. Graduates are eligible for CISSP and CISA professional certifications.
Where it leads
The roles it opens, and what you leave with.
Where graduates go
6 rolesInformation Security Analyst
Very high demandKsh 180,000 to Ksh 800,000
Analyses security threats, overseeing monitoring, detection, response, vulnerability management, and managing information security.
Cybersecurity Engineer
Very high demandKsh 180,000 to Ksh 800,000
Designs and implements security solutions, overseeing architecture, deployment, testing, and managing cybersecurity engineering.
IT Auditor
High demandKsh 160,000 to Ksh 700,000
Conducts IT audits, overseeing audit planning, controls testing, compliance, reporting, and managing IT audit.
Digital Forensics Analyst
High demandKsh 170,000 to Ksh 750,000
Conducts digital investigations, overseeing evidence collection, analysis, reporting, and managing digital forensics.
Penetration Tester
High demandKsh 180,000 to Ksh 800,000
Conducts penetration testing, overseeing vulnerability assessment, exploitation, reporting, remediation, and managing penetration testing.
Security Consultant
High demandKsh 170,000 to Ksh 750,000
Provides security consulting, overseeing assessment, advisory, design, implementation, and managing security consulting.
Graduate outcomes
Graduates pursue careers as information security analysts, cybersecurity engineers, IT auditors, digital forensics analysts, penetration testers, security consultants, and chief information security officers across financial institutions, government agencies, consulting firms, technology companies, and universities.
Where these fields lead
8 careers- Career Guidance & Labour Market Information CounselorEducation11Low exposure
- School Guidance CounselorEducation17Low exposure
- CrystallographerScience19Low exposure
- StatisticsScience20Low exposure
- Motor Vehicle MechanicEducation21Low exposure
- MycologistScience21Low exposure
- OceanographerScience21Low exposure
- Computational BiologistScience22Low exposure
Tools you will learn
Kali Linux
SoftwarePrimary
Kali Linux for penetration testing, covering Nmap, Metasploit, Burp Suite, Wireshark, and managing penetration testing.
Wireshark
Software
Wireshark for network analysis, covering packet capture, traffic analysis, protocol analysis, and managing network security.
Metasploit
Software
Metasploit for exploitation, covering vulnerability exploitation, payload generation, post-exploitation, and managing penetration testing.
EnCase
Software
EnCase for digital forensics, covering evidence collection, preservation, analysis, reporting, and managing digital forensics.
Industry links
Common misconceptions
IT security is just about installing antivirus software.
IT security covers comprehensive governance, risk management, audit, forensics, cryptography, penetration testing, and incident response beyond just antivirus software.
This programme is only for hackers.
IT security skills are valuable for auditors, risk managers, governance professionals, consultants, researchers, and educators beyond just penetration testers.
IT security has limited career prospects in Kenya.
With Kenya's digital transformation, cyber threats, financial sector regulations, and data protection laws, demand for IT security professionals is very high in Kenya.
IT audit is just about checking passwords.
IT audit covers comprehensive controls testing, compliance, assurance, governance, risk assessment, and COBIT frameworks.
Digital forensics is just about recovering deleted files.
Digital forensics covers comprehensive evidence collection, preservation, analysis, reporting, chain of custody, and legal proceedings.
Cryptography is just about encryption.
Cryptography covers comprehensive symmetric and asymmetric encryption, hash functions, digital signatures, key management, and cryptographic protocols.
Related courses
Further reading
Fees and entry marks for Master of Science in IT Security and Audit are restated every intake. Save it and the app keeps this version, so you can see what changed when it does.