The publication of the National Cybersecurity Strategy in 2014 by the Kenyan Ministry of ICT is a really strong foundation upon which the country can build comprehensive cyber security policies and capabilities. The four goals listed in the strategy (enhancing the nation's cybersecurity posture, building national capability, foster information sharing and collaboration, and finally, providing national leadership) are probably the four key challenges for most countries. At the time, the accompanying maturity model suggested that Kenya was on the lowest tier of progress in respect of most evaluation areas. Whilst progress appears to have been made across a broad front; implementation is probably not as far forward as would have been expected over the intervening five years. The passing of the Computer Misuse & Cyber Crimes Act in 2018 was one of the exceptions. The CBK and SASRA guidelines on cyber security best practice in the financial sector are also exceptions. The passing the 2019 Data Protection Act (modelled on the EU's GDPR) and the establishment of the Data Protection Commissioner role are both signs of further progress. Anecdotal evidence that the Ministry of Interior has a mandate to oversee cyber security in the public and private sectors.
Initiative | Owner / Lead | Highlights | Key Date(s) | Website | |
---|---|---|---|---|---|
National ICT Policy | Ministry of Information, Communications and Technology | Security objectives: establishing cybersecurity... | 2019 | https://www.ict.go.ke/wp-content/uploads/2019/1... | |
Data Protection Act | Data Protection Commissioner | This law came into force on 25 Nov 19 and build... | 2019 | http://kenyalaw.org/kl/fileadmin/pdfdownloads/A... | |
SASRA Guidelines on Cyber Security Risk Management | Sacco Societies Regulatory Authority | These guidelines set the minimum standards that... | 2018 | https://www.sasra.go.ke/ | |
Guidelines on Cybersecurity for Payment Service Providers | Central Bank Of Kenya (CBK) | Categories of Payment Service Providers | Gover... | 2019 | https://www.centralbank.go.ke/wp-content/upload... | |
Computer Misuse & Cyber Crimes Act 2018 | Ministry of Information, Communications and Technology | Criminalizes abuse of persons on social media, ... | 2018 | http://kenyalaw.org/kl/fileadmin/pdfdownloads/A... | |
CBK Guidance Note on Cybersecurity for Banking Sector | Central Bank Of Kenya (CBK) | Governance – Roles of the Board of Directors, ... | 2017 | https://www.centralbank.go.ke/uploads/banking_c... | |
Proposed National Cyber Security Agency | Ministry of Information, Communications and Technology | Proposed National Cybersecurity Agency | This a... | 2016 | ||
Sacco Societies Regulatory Authority Guideline | Sacco Societies Regulatory Authority (agency executive John Mwaka, ) | Overview of Risk Management Framework Requireme... | 2015 | https://www.sasra.go.ke/index.php/resources/gui... | |
National Cyber Security Strategy | Ministry of Information, Communications and Technology | Specifies four goals: | Enhance the nation's cy... | 2015 | https://www.ke-cirt.go.ke/knowledgebase-2/statu... | |
The Kenya National ICT Masterplan 2014 - 2017 | Kenyan Government | Under varied objectives, strategies include to:... | 2015 | http://icta.go.ke/national-ict-masterplan/ | |
Communications Authority (CA) | Ministry of Information, Communications and Technology | The Authority was established by the Kenya Comm... | 2013 | www.icta.go.ke | |
Ministerial Strategic Plan (2013 - 2017) | Ministry of Information, Communications and Technology | Key Strategic Issues: : Inadequate policy, lega... | 2013 | https://www.ict.go.ke/wp-content/uploads/2016/0... | |
Kenya Information and communication Act 2009 | Ministry of Information, Communications and Technology | 2014 | Provides for the establishment of the C... | 2013 | https://ca.go.ke/wp-content/uploads/2018/02/Ken... | |
National Computer Security Incident Response Team (KE-CIRT/CC) | Communication Commission of Kenya (CCK) | Communications Authority of Kenya Multi-agency ... | 2012 | https://www.ke-cirt.go.ke/index.php/about-us/ | |
National Police Service (NPS) | Ministry of Interior | One of the police service’s strategic priority ... | 2011 | http://www.nationalpolice.go.ke/ | |
Ministry of Information, Communications and Technology | Ministry of Information, Communications and Technology (MOICT) | Responsible for formulating, administering, man... | 2004 | https://ict.go.ke/ | |
IST-Africa | Ministry of Higher Education, Science and Technology | Supported by the European Commission (EC) and A... | 2002 | http://www.ist-africa.org/home/default.asp | |
National Communications Secretariat | Kenyan Government | A policy advisory body to the government on mat... | 1999 | https://ncs.go.ke/ | |
National Intelligence Services (NIS) | Ministry of interior | National Intelligence Services (NIS) The NIS id... | 1998 | https://www.nis.go.ke/ |