Measuring the adoption of Enterprise Security Risk Management in Kenya’s higher education using the ASIS ESRM Maturity Model

Show simple item record

dc.contributor.author Amuya, Levis Omusugu
dc.contributor.author Kariuki, Peterson Mwai
dc.date.accessioned 2024-02-26T05:32:51Z
dc.date.available 2024-02-26T05:32:51Z
dc.date.issued 2024-02
dc.identifier.citation Amuya, L.O., Kariuki, P.M. Measuring the adoption of Enterprise Security Risk Management in Kenya’s higher education using the ASIS ESRM Maturity Model. Secur J (2024). https://doi.org/10.1057/s41284-024-00418-4 en_US
dc.identifier.uri https://doi.org/10.1057/s41284-024-00418-4
dc.identifier.uri http://repository.dkut.ac.ke:8080/xmlui/handle/123456789/8462
dc.description.abstract Enterprise Security Risk Management (ESRM) is gaining popularity in industry circles, especially after the American Society of Industrial Security (ASIS International) elevated it as its strategic priority in 2016. However, research on its adoption has attracted little attention, especially in universities which are often characterized by outstanding variations in culture, structure, and more. In this paper, we conduct a self-assessment of ESRM maturity in Kenya’s accredited universities using process metrics of the 2019 ASIS ESRM Maturity Model and insights from university security executives. The findings reveal that more than 35% of accredited universities have achieved advanced levels of ESRM adoption, with over 57% at average or middle levels, predominantly at Level 3. Public accredited universities exhibit higher ESRM adoption levels compared to their private counterparts. The study also identifies variations in the terminology used, with 60% using “Security Risk Management (SRM),” 35% using “University Risk Management,” and a minority adopting ESRM. The discomfort with the “enterprise” term indicates a need for awareness and sensitization programs. We argue that benchmarking with optimized ESRM adopters and increasing awareness and integration of ESRM in strategic planning and institutional governance are crucial for comprehensive security risk management in higher education. en_US
dc.language.iso en en_US
dc.publisher Security Journal en_US
dc.title Measuring the adoption of Enterprise Security Risk Management in Kenya’s higher education using the ASIS ESRM Maturity Model en_US
dc.type Article en_US


Files in this item

This item appears in the following Collection(s)

Show simple item record

Search DSpace


Advanced Search

Browse

My Account