Keywords: IT security metrics, IT security elements, metrics models, metrics dashboard, merics algorithms, goal question metrics, security mesaurement scaling


It is a common management principle that one can only manage and improve what one can measure. Studies indicate that information technology security management could be improved if appropriate security metrics which are based on elements of information technology security are used. The objectives of this study were: to identify the major elements of information technology security, and to develop suitable information technology security metric’s model based on major elements for universities in Kenya. Methodology  involved  a review of secondary publications to ascertain the major information technology security.  Ten percent of universities in Kenya were sampled for data collection. Purposive sampling was conducted for data collection using questionnaire and an interview schedule. In each sampled university, 13 operation areas related to information systems were considered, giving a total of 91 resepondents. Data was collected from the team leader of each operation area, then  analysed using SPSS, where regression model in Tobin's Q equation was adopted. The regression analysis helped to generate coefficients that constituted security metrics' model and prototype. In conclusion, while the level of implementation of IT security elements was found to contribute to the metrics, information security policy was found to contributes as twice. Therefore, it is recommended that the developed IT security metrics model  should be used together with the security policy for better information systems security management.


