Effect of Technology-Oriented Factors on ISO/IEC 27001:2022 Implementation in Public Sector Organizations in Kenya

Main Article Content

Carolyne Khatievi Lubembe https://orcid.org/0009-0009-0376-8027
Silvance Abeka https://orcid.org/0000-0002-7617-6147
Solomon Ogara https://orcid.org/0000-0002-3321-0448

Keywords

ISO/IEC 27001:2022, information security management system, system quality, information quality, technology fit, public sector, Kenya

Abstract

The effective implementation of ISO/IEC 27001:2022 in public sector organizations depends not only on the existence of an Information Security Management System (ISMS) but also on the technological conditions under which security requirements are operationalized. Drawing on the Task-Technology Fit theory, this study examined the effect of system quality, information quality and technology fit on ISO/IEC 27001:2022 implementation in public-sector organizations in Kenya. An explanatory cross-sectional design was employed among employees and management in 13 Kenyan public-sector organizations. From a target sample of 384 respondents, 343 usable responses were obtained, representing an 89.37% response rate. Reliability was established through Cronbach's alpha, while validity was assessed through face and content validity by subject matter experts. Data were collected using a structured questionnaire and analyzed using descriptive statistics and multiple linear regression.  Information accuracy recorded the highest mean (M = 4.31, SD = 0.840), whereas information being logical recorded the lowest (M = 2.66, SD = 1.180). Among technology-fit indicators, task effectiveness and efficiency had the highest mean (M = 3.90, SD = 0.953), while increased output quantity had the lowest (M = 2.84, SD = 1.190). Multiple regression showed that system quality (β = .231, p = .001), information quality (β = .222, p = .045), and technology fit (β = .222, p = .038) were positively and significantly associated with ISO/IEC 27001:2022 implementation when people- and process-oriented factors were controlled. The overall nine-factor model explained 58.4% of the variance in implementation (R² = .584; adjusted R² = .583; F(9, 333) = 29.840, p < .001). The findings demonstrate that technological conditions are key to translating ISO/IEC 27001:2022 requirements into operational information-security practices. The study contributes contextual empirical evidence from Kenya and highlights the need to evaluate information-security implementation not merely in terms of the existence of technical controls but also in terms of system reliability, information quality, and alignment between technology capabilities and organizational tasks.

Downloads

Download data is not yet available.
Abstract 2 | PDF Downloads 0

References

Alassaf, M., & Alkhalifah, A. (2026). Determinants of information security policy compliance: Integrating task-technology fit and threat avoidance appraisals in the digital workplace. Frontiers in Psychology, 17, 1861737. https://doi.org/10.3389/fpsyg.2026.1861737

Almuqrin, A. (2024). How about enhancing organizational security: Critical success factors in information security management performance. Journal of Global Information Management, 32(1), 1–18. https://doi.org/10.4018/JGIM.358745

Alrehili, A. A., & Alhazmi, O. H. (2023). ISO/IEC 27001 standard: Analytical and comparative overview. In International Conference on Advances in Data-driven Computing and Intelligent Systems (pp. 143–156). Springer Nature Singapore. https://doi.org/10.1007/978-981-99-9524-0_12

Apridiyanti, A., Suharman, H., & Adrianto, Z. (2020). Successful implementation of information systems in public sector organizations. Journal of Accounting Auditing and Business, 3(1). https://doi.org/10.24198/jaab.v3i1.25351

Araujo, M. S. D., Machado, B. A. S., & Passos, F. U. (2024). Resilience in the context of cyber security: A review of the fundamental concepts and relevance. Applied Sciences, 14(5), 2116. https://doi.org/10.3390/app14052116

Asher, A. D. (2024). Approaches for improving validity in quantitative research articles. portal: Libraries and the Academy, 24(2), 209–215. https://doi.org/10.1353/pla.2024.a923703

Ayim, O. R. (2019). The relationship between Integrated Financial Management Information System and performance of government ministries in Kenya. Kenyatta University. https://ir-library.ku.ac.ke/items/3a418aa9-47e9-4a6a-84bd-b159892cdd02

Batte, B. (2025). ISO 27001 and alternative frameworks for managing information security risks. SSRN. https://doi.org/10.2139/ssrn.5546398

Bujang, M. A., Omar, E. D., Foo, D. H. P., & Hon, Y. K. (2024). Sample size determination for conducting a pilot study to assess reliability of a questionnaire. Restorative Dentistry & Endodontics, 49(1), e3. https://doi.org/10.5395/rde.2024.49.e3

Cane, S., & McCarthy, R. (2009). Analyzing the factors that affect information systems use: A task-technology fit meta-analysis. Journal of Computer Information Systems, 50(1), 108–123. https://doi.org/10.1080/08874417.2009.11645368

Chavez, S., Anahue, J., & Ticona, W. (2024). Implementation of an ISMS based on ISO/IEC 27001:2022 to improve information security in the internet services sector. In 2024 14th International Conference on Cloud Computing, Data Science & Engineering (Confluence) (pp. 184–189). IEEE.
https://doi.org/10.1109/Confluence60223.2024.10463392

Chen, H., & Hai, Y. (2024). Exploring the critical success factors of information security management: A mixed-method approach. Information & Computer Security, 32(5), 545–572. https://doi.org/10.1108/ICS-03-2023-0034

Culot, G., Nassimbeni, G., Podrecca, M., & Sartor, M. (2021). The ISO/IEC 27001 information security management standard: Literature review and theory-based research agenda. The TQM Journal, 33(7), 76–105. https://doi.org/10.1108/TQM-09-2020-0202

DeLone, W. H., & McLean, E. R. (2003). The DeLone and McLean model of information systems success: A ten-year update. Journal of Management Information Systems, 19(4), 9–30. https://doi.org/10.1080/07421222.2003.11045748

Djebbar, F., & Nordström, K. (2023). A comparative analysis of industrial cybersecurity standards. IEEE Access, 11, 85315–85332. https://doi.org/10.1109/ACCESS.2023.3303205

Efunwoye, I. O., Gogate, M., Hussain, A., Asim, M., Ahmad, J., Hussain, A., & Dashtipour, K. (2025). Evaluating the efficacy and applicability of contemporary cybersecurity frameworks and standards. In Cybersecurity, Cybercrimes, and Smart Emerging Technologies (pp. 365–372). CRC Press. https://doi.org/10.1201/9781003614197-33

Forero, C. G. (2024). Cronbach's alpha. In Encyclopedia of Quality of Life and Well-being Research (pp. 1505–1507). Springer. https://doi.org/10.1007/978-3-031-17299-1_622

Gichubi, P. M., Maake, B., & Chweya, R. (2024). Cybersecurity framework for Kenyan universities in conformity with ISO/IEC 27001:2022 standard. Open Access Library Journal, 11(8), 1–16. https://doi.org/10.4236/oalib.1110810

Goodhue, D. L., & Thompson, R. L. (1995). Task-technology fit and individual performance. MIS Quarterly, 19(2), 213–236. https://doi.org/10.2307/249689

Hassan, M., Saeedi, K., Almagwashi, H., & Alarifi, S. (2022). Information security risk awareness survey of non-governmental organization in Saudi Arabia. In The International Research & Innovation Forum (pp. 39–71). Springer. https://doi.org/10.1007/978-3-031-19560-0_4

Indeje, W., & Qin, Z. (2011). Stakeholder perception of information systems development success in the public sector. Management Science and Engineering, 5(2). https://doi.org/10.3968/j.mse.1913035X20110502.004

Islam, M. M., Bhuiyan, M. R. I., Islam, S. H., Tabassum, M. N., & Billah, M. (2026). Unlocking the mediating and moderating role of information security in information systems: A combined TAM, ISM, and HBM model. Human Behavior and Emerging Technologies, 2026(1), 5593002.
https://doi.org/10.1155/hbe2/5593002

Jeyaraj, A. (2022). A meta-regression of task-technology fit in information systems research. International Journal of Information Management, 65, 102493. https://doi.org/10.1016/j.ijinfomgt.2022.102493

Kamil, Y., Lund, S., & Islam, M. S. (2023). Information security objectives and the output legitimacy of ISO/IEC 27001: Stakeholders' perspective on expectations in private organizations in Sweden. Information Systems and e-Business Management, 21(3), 699–722. https://doi.org/10.1007/s10257-
023-00646-y

Kaporo, S. K. (2024). Electronic records management and security of public leaders' confidential information in Tanzania: A case of the President's Office, Ethics Secretariat [Master's thesis, University of Dodoma].

Karoki, G. K., Mwingirwa, I. M., & Kamau, S. (2025). Cyber espionage vulnerabilities in Kenya's e-government ecosystem: A case study of a public institution. The Eastern Africa Journal of Policy and Strategy, 89–105.

Keefa, B., Mayoka, G. K., Nkamwesiga, L., & Nyamadi, M. (2024). Information security in higher education institutions: A systematic literature review. ORSEA Journal, 302–320. https://doi.org/10.56279/orseaj.C2024.18

Kennedy, I. (2022). Sample size determination in test-retest and Cronbach alpha reliability estimates. British Journal of Contemporary Education, 2(1), 17–29. https://doi.org/10.52589/BJCE-FY266HK9

Kiarie, N. (2024). Enhancing digital resilience: A cybersecurity readiness assessment of Kenyan TVET institutions. Journal of the Kenya National Commission for UNESCO, 5(1). https://doi.org/10.62049/jkncu.v5i1.191

Leme, R. D. S., de Souza Pinto, J., Zanon, L. G., Sigahi, T. F., Moraes, G. H. S. M. D., Moro, S. R., & Anholon, R. (2026). Information security management: A fuzzy DEMATEL analysis of the new ISO/IEC 27001:2022 controls. Information & Computer Security, 34(3), 413–434. https://doi.org/10.1108/ICS-10-
2024-0269

Mirtsch, M. (2023). Adoption of the information security management system standard ISO/IEC 27001—A study among German organizations. International Journal for Quality Research, 17(3), 747–768. https://doi.org/10.24874/IJQR17.03-08

Nadir, R., Kartini, & Tawakkal. (2024). Model kesuksesan sistem informasi DeLone & McLean terhadap Sistem Informasi Pemerintah Daerah (SIPD) pada Pemda Kabupaten Wajo. Prosiding Seminar Nasional Terapan Riset Inovatif, 9(2), 175–184.

Ohndyl, G. O., Kimuyu, J., & Sidha, Z. (2023). Information security threats to e-government services in Kenya. Global Journal of Human-Social Science: H Interdisciplinary, 23(7).

Owusu, A. (2023). Assessing the impact of e-government systems from citizens' perspective: Evidence from Ghana. Electronic Government, an International Journal, 19(3), 376–400. https://doi.org/10.1504/EG.2023.130583

Owusu, A., & Akpe-Doe, C. (2022). Assessing the effectiveness of e-government services in Ghana: A case of the Registrar General's Department. International Journal of Electronic Government Research, 18(1), 1–23. https://doi.org/10.4018/IJEGR.289827

Oyugi, T. O. (2012). Influence of task technology fit framework on adoption of project management information system in non-governmental organizations' projects in Nakuru town. University of Nairobi. https://erepository.uonbi.ac.ke/items/57bf3d8c-6e66-44a1-af1d-1d0f3811afc0

Plate, A. (2025). ISMS: A management framework for information security. In Encyclopedia of Cryptography, Security and Privacy (pp. 1305–1307). Springer Nature Switzerland. https://doi.org/10.1007/978-3-030-71522-9_289

Rahimli, R. S. (2025). Security and privacy in information processing [Doctoral dissertation].

Rohan, R., Pal, D., Hautamäki, J., Funilkul, S., Chutimaskul, W., & Thapliyal, H. (2023). A systematic literature review of cybersecurity scales assessing information security awareness. Heliyon, 9(3), e14234. https://doi.org/10.1016/j.heliyon.2023.e14234

Sausi, J. M., Kitali, E. J., & Mtebe, J. S. (2021). Evaluation of local government revenue collection information system success in Tanzania. Digital Policy, Regulation and Governance, 23(5), 437–455. https://doi.org/10.1108/DPRG-04-2021-0055

Sekti, B. A. (2026). IT service information security management. In Cases on Information Systems Service Management (pp. 61–94). IGI Global Scientific Publishing. https://doi.org/10.4018/979-8-3373-2352-7.ch003

Shaikh, F. A., & Siponen, M. (2023). Information security risk assessments following cybersecurity breaches: The mediating role of top management attention to cybersecurity. Computers & Security, 124, 102974. https://doi.org/10.1016/j.cose.2022.102974

Skinner, E., & Dancis, J. (2026). Descriptive and explanatory designs. In Human Development—Revision.

Soliman, W., & Mohammadnazar, H. (2022). New insights into the justifiability of organizational information security policy noncompliance: A case study. In Proceedings of the 55th Hawaii International Conference on System Sciences (pp. 6812–6821). University of Hawaiʻi. https://doi.org/10.24251/HICSS.2022.823

Spruill, C., Khalil, M., & Olatunbosun, S. (2024). Models for security management. In World Congress in Computer Science, Computer Engineering & Applied Computing (pp. 354–361). Springer Nature Switzerland. https://doi.org/10.1007/978-3-031-85933-5_26

Suorsa, M., & Helo, P. (2023). Information security failures measured and ISO/IEC 27001:2022 controls ranked by general data protection regulation penalty analysis. In 2023 11th International Conference on Cyber and IT Service Management (CITSM) (pp. 1–5). IEEE. https://doi.org/10.1109/CITSM60085.2023.10455413

Taherdoost, H. (2022). Understanding cybersecurity frameworks and information security standards—A review and comprehensive overview. Electronics, 11(14), 2181. https://doi.org/10.3390/electronics11142181

Tewamba, H. N., Kamdjoug, J. R. K., Bitjoka, G. B., Wamba, S. F., & Mi Bahanag, N. N. (2019). Effects of information security management systems on firm performance. American Journal of Operations Management and Information Systems, 4(3), 99–108. https://doi.org/10.11648/j.ajomis.20190403.15

Vakhula, O., Kurii, Y., Opirskyy, I. R., & Susukailo, V. (2024). Security as code concept for fulfilling ISO/IEC 27001:2022 requirements. In Proceedings of the Workshop on Cybersecurity Providing in Information and Telecommunication Systems (CPITS 2024) (pp. 59–72). https://doi.org/10.55056/ceur-ws.org/Vol-3654/paper6.pdf

Yee, C. K., & Zolkipli, M. F. (2021). Review on confidentiality, integrity and availability in information security. Journal of ICT in Education, 8(2), 34–42. https://doi.org/10.37134/jictie.vol8.2.4.2021