Effect of Technology-Oriented Factors on ISO/IEC 27001:2022 Implementation in Public Sector Organizations in Kenya
Main Article Content
Keywords
ISO/IEC 27001:2022, information security management system, system quality, information quality, technology fit, public sector, Kenya
Abstract
The effective implementation of ISO/IEC 27001:2022 in public sector organizations depends not only on the existence of an Information Security Management System (ISMS) but also on the technological conditions under which security requirements are operationalized. Drawing on the Task-Technology Fit theory, this study examined the effect of system quality, information quality and technology fit on ISO/IEC 27001:2022 implementation in public-sector organizations in Kenya. An explanatory cross-sectional design was employed among employees and management in 13 Kenyan public-sector organizations. From a target sample of 384 respondents, 343 usable responses were obtained, representing an 89.37% response rate. Reliability was established through Cronbach's alpha, while validity was assessed through face and content validity by subject matter experts. Data were collected using a structured questionnaire and analyzed using descriptive statistics and multiple linear regression. Information accuracy recorded the highest mean (M = 4.31, SD = 0.840), whereas information being logical recorded the lowest (M = 2.66, SD = 1.180). Among technology-fit indicators, task effectiveness and efficiency had the highest mean (M = 3.90, SD = 0.953), while increased output quantity had the lowest (M = 2.84, SD = 1.190). Multiple regression showed that system quality (β = .231, p = .001), information quality (β = .222, p = .045), and technology fit (β = .222, p = .038) were positively and significantly associated with ISO/IEC 27001:2022 implementation when people- and process-oriented factors were controlled. The overall nine-factor model explained 58.4% of the variance in implementation (R² = .584; adjusted R² = .583; F(9, 333) = 29.840, p < .001). The findings demonstrate that technological conditions are key to translating ISO/IEC 27001:2022 requirements into operational information-security practices. The study contributes contextual empirical evidence from Kenya and highlights the need to evaluate information-security implementation not merely in terms of the existence of technical controls but also in terms of system reliability, information quality, and alignment between technology capabilities and organizational tasks.
Downloads
References
Almuqrin, A. (2024). How about enhancing organizational security: Critical success factors in information security management performance. Journal of Global Information Management, 32(1), 1–18. https://doi.org/10.4018/JGIM.358745
Alrehili, A. A., & Alhazmi, O. H. (2023). ISO/IEC 27001 standard: Analytical and comparative overview. In International Conference on Advances in Data-driven Computing and Intelligent Systems (pp. 143–156). Springer Nature Singapore. https://doi.org/10.1007/978-981-99-9524-0_12
Apridiyanti, A., Suharman, H., & Adrianto, Z. (2020). Successful implementation of information systems in public sector organizations. Journal of Accounting Auditing and Business, 3(1). https://doi.org/10.24198/jaab.v3i1.25351
Araujo, M. S. D., Machado, B. A. S., & Passos, F. U. (2024). Resilience in the context of cyber security: A review of the fundamental concepts and relevance. Applied Sciences, 14(5), 2116. https://doi.org/10.3390/app14052116
Asher, A. D. (2024). Approaches for improving validity in quantitative research articles. portal: Libraries and the Academy, 24(2), 209–215. https://doi.org/10.1353/pla.2024.a923703
Ayim, O. R. (2019). The relationship between Integrated Financial Management Information System and performance of government ministries in Kenya. Kenyatta University. https://ir-library.ku.ac.ke/items/3a418aa9-47e9-4a6a-84bd-b159892cdd02
Batte, B. (2025). ISO 27001 and alternative frameworks for managing information security risks. SSRN. https://doi.org/10.2139/ssrn.5546398
Bujang, M. A., Omar, E. D., Foo, D. H. P., & Hon, Y. K. (2024). Sample size determination for conducting a pilot study to assess reliability of a questionnaire. Restorative Dentistry & Endodontics, 49(1), e3. https://doi.org/10.5395/rde.2024.49.e3
Cane, S., & McCarthy, R. (2009). Analyzing the factors that affect information systems use: A task-technology fit meta-analysis. Journal of Computer Information Systems, 50(1), 108–123. https://doi.org/10.1080/08874417.2009.11645368
Chavez, S., Anahue, J., & Ticona, W. (2024). Implementation of an ISMS based on ISO/IEC 27001:2022 to improve information security in the internet services sector. In 2024 14th International Conference on Cloud Computing, Data Science & Engineering (Confluence) (pp. 184–189). IEEE.
https://doi.org/10.1109/Confluence60223.2024.10463392
Chen, H., & Hai, Y. (2024). Exploring the critical success factors of information security management: A mixed-method approach. Information & Computer Security, 32(5), 545–572. https://doi.org/10.1108/ICS-03-2023-0034
Culot, G., Nassimbeni, G., Podrecca, M., & Sartor, M. (2021). The ISO/IEC 27001 information security management standard: Literature review and theory-based research agenda. The TQM Journal, 33(7), 76–105. https://doi.org/10.1108/TQM-09-2020-0202
DeLone, W. H., & McLean, E. R. (2003). The DeLone and McLean model of information systems success: A ten-year update. Journal of Management Information Systems, 19(4), 9–30. https://doi.org/10.1080/07421222.2003.11045748
Djebbar, F., & Nordström, K. (2023). A comparative analysis of industrial cybersecurity standards. IEEE Access, 11, 85315–85332. https://doi.org/10.1109/ACCESS.2023.3303205
Efunwoye, I. O., Gogate, M., Hussain, A., Asim, M., Ahmad, J., Hussain, A., & Dashtipour, K. (2025). Evaluating the efficacy and applicability of contemporary cybersecurity frameworks and standards. In Cybersecurity, Cybercrimes, and Smart Emerging Technologies (pp. 365–372). CRC Press. https://doi.org/10.1201/9781003614197-33
Forero, C. G. (2024). Cronbach's alpha. In Encyclopedia of Quality of Life and Well-being Research (pp. 1505–1507). Springer. https://doi.org/10.1007/978-3-031-17299-1_622
Gichubi, P. M., Maake, B., & Chweya, R. (2024). Cybersecurity framework for Kenyan universities in conformity with ISO/IEC 27001:2022 standard. Open Access Library Journal, 11(8), 1–16. https://doi.org/10.4236/oalib.1110810
Goodhue, D. L., & Thompson, R. L. (1995). Task-technology fit and individual performance. MIS Quarterly, 19(2), 213–236. https://doi.org/10.2307/249689
Hassan, M., Saeedi, K., Almagwashi, H., & Alarifi, S. (2022). Information security risk awareness survey of non-governmental organization in Saudi Arabia. In The International Research & Innovation Forum (pp. 39–71). Springer. https://doi.org/10.1007/978-3-031-19560-0_4
Indeje, W., & Qin, Z. (2011). Stakeholder perception of information systems development success in the public sector. Management Science and Engineering, 5(2). https://doi.org/10.3968/j.mse.1913035X20110502.004
Islam, M. M., Bhuiyan, M. R. I., Islam, S. H., Tabassum, M. N., & Billah, M. (2026). Unlocking the mediating and moderating role of information security in information systems: A combined TAM, ISM, and HBM model. Human Behavior and Emerging Technologies, 2026(1), 5593002.
https://doi.org/10.1155/hbe2/5593002
Jeyaraj, A. (2022). A meta-regression of task-technology fit in information systems research. International Journal of Information Management, 65, 102493. https://doi.org/10.1016/j.ijinfomgt.2022.102493
Kamil, Y., Lund, S., & Islam, M. S. (2023). Information security objectives and the output legitimacy of ISO/IEC 27001: Stakeholders' perspective on expectations in private organizations in Sweden. Information Systems and e-Business Management, 21(3), 699–722. https://doi.org/10.1007/s10257-
023-00646-y
Kaporo, S. K. (2024). Electronic records management and security of public leaders' confidential information in Tanzania: A case of the President's Office, Ethics Secretariat [Master's thesis, University of Dodoma].
Karoki, G. K., Mwingirwa, I. M., & Kamau, S. (2025). Cyber espionage vulnerabilities in Kenya's e-government ecosystem: A case study of a public institution. The Eastern Africa Journal of Policy and Strategy, 89–105.
Keefa, B., Mayoka, G. K., Nkamwesiga, L., & Nyamadi, M. (2024). Information security in higher education institutions: A systematic literature review. ORSEA Journal, 302–320. https://doi.org/10.56279/orseaj.C2024.18
Kennedy, I. (2022). Sample size determination in test-retest and Cronbach alpha reliability estimates. British Journal of Contemporary Education, 2(1), 17–29. https://doi.org/10.52589/BJCE-FY266HK9
Kiarie, N. (2024). Enhancing digital resilience: A cybersecurity readiness assessment of Kenyan TVET institutions. Journal of the Kenya National Commission for UNESCO, 5(1). https://doi.org/10.62049/jkncu.v5i1.191
Leme, R. D. S., de Souza Pinto, J., Zanon, L. G., Sigahi, T. F., Moraes, G. H. S. M. D., Moro, S. R., & Anholon, R. (2026). Information security management: A fuzzy DEMATEL analysis of the new ISO/IEC 27001:2022 controls. Information & Computer Security, 34(3), 413–434. https://doi.org/10.1108/ICS-10-
2024-0269
Mirtsch, M. (2023). Adoption of the information security management system standard ISO/IEC 27001—A study among German organizations. International Journal for Quality Research, 17(3), 747–768. https://doi.org/10.24874/IJQR17.03-08
Nadir, R., Kartini, & Tawakkal. (2024). Model kesuksesan sistem informasi DeLone & McLean terhadap Sistem Informasi Pemerintah Daerah (SIPD) pada Pemda Kabupaten Wajo. Prosiding Seminar Nasional Terapan Riset Inovatif, 9(2), 175–184.
Ohndyl, G. O., Kimuyu, J., & Sidha, Z. (2023). Information security threats to e-government services in Kenya. Global Journal of Human-Social Science: H Interdisciplinary, 23(7).
Owusu, A. (2023). Assessing the impact of e-government systems from citizens' perspective: Evidence from Ghana. Electronic Government, an International Journal, 19(3), 376–400. https://doi.org/10.1504/EG.2023.130583
Owusu, A., & Akpe-Doe, C. (2022). Assessing the effectiveness of e-government services in Ghana: A case of the Registrar General's Department. International Journal of Electronic Government Research, 18(1), 1–23. https://doi.org/10.4018/IJEGR.289827
Oyugi, T. O. (2012). Influence of task technology fit framework on adoption of project management information system in non-governmental organizations' projects in Nakuru town. University of Nairobi. https://erepository.uonbi.ac.ke/items/57bf3d8c-6e66-44a1-af1d-1d0f3811afc0
Plate, A. (2025). ISMS: A management framework for information security. In Encyclopedia of Cryptography, Security and Privacy (pp. 1305–1307). Springer Nature Switzerland. https://doi.org/10.1007/978-3-030-71522-9_289
Rahimli, R. S. (2025). Security and privacy in information processing [Doctoral dissertation].
Rohan, R., Pal, D., Hautamäki, J., Funilkul, S., Chutimaskul, W., & Thapliyal, H. (2023). A systematic literature review of cybersecurity scales assessing information security awareness. Heliyon, 9(3), e14234. https://doi.org/10.1016/j.heliyon.2023.e14234
Sausi, J. M., Kitali, E. J., & Mtebe, J. S. (2021). Evaluation of local government revenue collection information system success in Tanzania. Digital Policy, Regulation and Governance, 23(5), 437–455. https://doi.org/10.1108/DPRG-04-2021-0055
Sekti, B. A. (2026). IT service information security management. In Cases on Information Systems Service Management (pp. 61–94). IGI Global Scientific Publishing. https://doi.org/10.4018/979-8-3373-2352-7.ch003
Shaikh, F. A., & Siponen, M. (2023). Information security risk assessments following cybersecurity breaches: The mediating role of top management attention to cybersecurity. Computers & Security, 124, 102974. https://doi.org/10.1016/j.cose.2022.102974
Skinner, E., & Dancis, J. (2026). Descriptive and explanatory designs. In Human Development—Revision.
Soliman, W., & Mohammadnazar, H. (2022). New insights into the justifiability of organizational information security policy noncompliance: A case study. In Proceedings of the 55th Hawaii International Conference on System Sciences (pp. 6812–6821). University of Hawaiʻi. https://doi.org/10.24251/HICSS.2022.823
Spruill, C., Khalil, M., & Olatunbosun, S. (2024). Models for security management. In World Congress in Computer Science, Computer Engineering & Applied Computing (pp. 354–361). Springer Nature Switzerland. https://doi.org/10.1007/978-3-031-85933-5_26
Suorsa, M., & Helo, P. (2023). Information security failures measured and ISO/IEC 27001:2022 controls ranked by general data protection regulation penalty analysis. In 2023 11th International Conference on Cyber and IT Service Management (CITSM) (pp. 1–5). IEEE. https://doi.org/10.1109/CITSM60085.2023.10455413
Taherdoost, H. (2022). Understanding cybersecurity frameworks and information security standards—A review and comprehensive overview. Electronics, 11(14), 2181. https://doi.org/10.3390/electronics11142181
Tewamba, H. N., Kamdjoug, J. R. K., Bitjoka, G. B., Wamba, S. F., & Mi Bahanag, N. N. (2019). Effects of information security management systems on firm performance. American Journal of Operations Management and Information Systems, 4(3), 99–108. https://doi.org/10.11648/j.ajomis.20190403.15
Vakhula, O., Kurii, Y., Opirskyy, I. R., & Susukailo, V. (2024). Security as code concept for fulfilling ISO/IEC 27001:2022 requirements. In Proceedings of the Workshop on Cybersecurity Providing in Information and Telecommunication Systems (CPITS 2024) (pp. 59–72). https://doi.org/10.55056/ceur-ws.org/Vol-3654/paper6.pdf
Yee, C. K., & Zolkipli, M. F. (2021). Review on confidentiality, integrity and availability in information security. Journal of ICT in Education, 8(2), 34–42. https://doi.org/10.37134/jictie.vol8.2.4.2021