Cybersecurity and records management practices as precursors to good governance in the digital age in public sector

Purpose This study examines how the advisory role of the Information and Communications Technology Authority (ICTA) influences cybersecurity and records management practices, and how these contribute to enhanced governance in Kenya's public sector. Design/methodology/approach A qualitative case study design was adopted to explore the integration of cybersecurity and records management practices within Kenya's public-sector digital governance framework. Data were collected through semi-structured interviews administered to 18 purposively selected participants, including top management, records management, ICT and information security personnel at ICTA. The data were analysed thematically to identify institutional practices, governance challenges and the extent to which cybersecurity principles are embedded in records management practices. Findings The findings reveal that integrated cybersecurity and records management practices play a critical role in strengthening good governance in Kenya's public sector. ICTA supports this integration through policies promoting role-based access control, secure audit trails, digital signatures and disaster recovery mechanisms. However, challenges persist, including inconsistent implementation across public institutions, unclear records security classification protocols, limited resources and infrequent policy updates. Practical implications The study highlights the need for harmonized implementation of cybersecurity and records management policies across public institutions. Strengthening institutional capacity, clarifying classification frameworks and regularly updating policies would enhance information management and improve governance outcomes. Originality/value This study provides original insights into cybersecurity and records management as interdependent components of digital governance within the public sector. Situated in Kenya's digital landscape, it offers evidence from a Global South perspective, contributing to debates on secure digital governance, institutional accountability and records management in emerging economies.

Authors

Institutions

Publication Details

Journal
Organizational Cybersecurity Journal Practice Process and People
Published
2026-09-28
DOI
https://doi.org/10.1108/ocj-06-2025-0021
Primary Topic
Digital and Traditional Archives Management
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

Cybersecurity and records management practices as precursors to good governance in the digital age in public sector

Tom Kwanya, Carolyne Jerop, Stephen Mutula
Organizational Cybersecurity Journal Practice Process and People
Digital and Traditional Archives Management
article

Cybersecurity and records management practices as precursors to good governance in the digital age in public sector

Tom Kwanya, Carolyne Jerop, Stephen Mutula
article en

Abstract

Purpose This study examines how the advisory role of the Information and Communications Technology Authority (ICTA) influences cybersecurity and records management practices, and how these contribute to enhanced governance in Kenya's public sector. Design/methodology/approach A qualitative case study design was adopted to explore the integration of cybersecurity and records management practices within Kenya's public-sector digital governance framework. Data were collected through semi-structured interviews administered to 18 purposively selected participants, including top management, records management, ICT and information security personnel at ICTA. The data were analysed thematically to identify institutional practices, governance challenges and the extent to which cybersecurity principles are embedded in records management practices. Findings The findings reveal that integrated cybersecurity and records management practices play a critical role in strengthening good governance in Kenya's public sector. ICTA supports this integration through policies promoting role-based access control, secure audit trails, digital signatures and disaster recovery mechanisms. However, challenges persist, including inconsistent implementation across public institutions, unclear records security classification protocols, limited resources and infrequent policy updates. Practical implications The study highlights the need for harmonized implementation of cybersecurity and records management policies across public institutions. Strengthening institutional capacity, clarifying classification frameworks and regularly updating policies would enhance information management and improve governance outcomes. Originality/value This study provides original insights into cybersecurity and records management as interdependent components of digital governance within the public sector. Situated in Kenya's digital landscape, it offers evidence from a Global South perspective, contributing to debates on secure digital governance, institutional accountability and records management in emerging economies.

Organizational Cybersecurity Journal Practice Process and People
Technical University of Kenya (KE), University of KwaZulu-Natal (ZA)
Climate action
Openalex Percentile: Top 4%
Digital and Traditional Archives Management
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.