📖 ABSTRACT/OVERVIEW
State government ICT infrastructures across Nigeria face escalating cybersecurity threats, including ransomware, data breaches, and insider threats, yet most state-level ICT departments operate without formalised cybersecurity governance frameworks aligned to international standards. This study developed a cybersecurity governance framework tailored for Nigerian state government ICT environments, drawing on case assessments from Kano, Enugu, and Rivers States. A framework development methodology was employed, combining structured interviews with 18 state ICT directors and security officers, a gap analysis of existing cybersecurity policies against ISO/IEC 27001 and NIST CSF requirements, and review of the NITDA National Cybersecurity Policy 2021. The gap analysis revealed that 72 percent of assessed state ICT units lacked documented incident response plans, 83 percent had not conducted formal risk assessments within the preceding 24 months, and 89 percent had no security awareness training programme for civil servants. The developed framework encompasses five governance domains: risk management, access control, incident response, security awareness, and third-party vendor management. Each domain includes policy templates, implementation checklists, key performance indicators, and responsible officer designations appropriate for state government organisational structures. Expert validation was conducted with 12 cybersecurity professionals and two NITDA representatives, confirming the framework's alignment with current Nigerian regulatory requirements. The study recommends adoption of the framework as a minimum cybersecurity baseline for all 36 state governments and mandates NUC-linked federal university capacity building for state government cybersecurity personnel training.
Keywords: cybersecurity governance, state government ICT, Nigeria, ISO 27001, NIST CSF
Need Complete Chapters of the Above Topic?
Get high-quality, Zero-AI research materials with current citations.
Request via WhatsApp 💬