📖 ABSTRACT/OVERVIEW
Smart city initiatives in Abuja, Federal Capital Territory, incorporating IoT sensors for traffic management, waste monitoring, and environmental sensing, introduce a large attack surface of internet-connected devices that existing municipal cybersecurity policies do not adequately address. This study designed a comprehensive IoT security framework for smart city IoT deployments in Abuja. A professional security architecture methodology was applied, drawing on threat modelling of the Abuja Smart City initiative's publicly documented sensor and connectivity architecture, interviews with six FCDA digital infrastructure officers, and review of ENISA IoT Security Guidelines and NIST IR 8259 IoT cybersecurity core baseline. Threat modelling using STRIDE identified 38 threat scenarios across six IoT subsystem categories. The security framework developed encompasses five security layers: device identity and authentication, encrypted communication, network segmentation, over-the-air firmware update security, and security monitoring. For each layer, specific implementation standards are defined, including certificate-based mutual TLS authentication for device-to-gateway communication, DTLS encryption for constrained devices, and mandatory code signing for firmware updates. A risk-prioritised implementation roadmap over 36 months is provided with estimated budget requirements per phase. Security control effectiveness was validated through expert review by eight IoT security specialists. The study recommends the FCDA establish an IoT Security Operations Centre co-located with the existing National Computer Emergency Response Team (ngCERT) facility for coordinated smart city security monitoring.
Keywords: IoT security, smart city, Abuja, threat modelling, cybersecurity framework
Need Complete Chapters of the Above Topic?
Get high-quality, Zero-AI research materials with current citations.
Request via WhatsApp 💬