📖 ABSTRACT/OVERVIEW
Government websites in North East Nigeria serve as public-facing digital infrastructure for service delivery and information dissemination, yet their security configurations are rarely systematically evaluated, leaving citizens and government data at risk. This study assessed the security posture of 25 government ministry and agency websites in Borno, Yobe, and Adamawa States, North East Nigeria. A technical website security audit methodology was employed, using automated scanning tools (OWASP ZAP, SSL Labs, and Hardenize) to assess HTTPS deployment, SSL/TLS certificate validity, HTTP security headers, content security policy, mixed content issues, and open port exposure. Results showed that HTTPS was deployed by 80.0 percent of assessed sites but SSL/TLS configurations were inadequately hardened in 60.0 percent. Content Security Policy headers were absent from 84.0 percent. X-Frame-Options headers protecting against clickjacking were missing in 76.0 percent. Subresource integrity for external scripts was implemented in only 8.0 percent. Common open port vulnerabilities were identified on hosting servers in 44.0 percent. Adaptive to the conflict environment, 20.0 percent of sites had not been updated in more than 18 months. The study concludes that North East zone government web security is significantly below minimum standards and recommends a NITDA-facilitated government website security remediation programme, centralised secure hosting infrastructure, and mandatory bi-annual web security audits for all state and LGA government digital assets.
Keywords: government website security, HTTPS, security headers, North East Nigeria, web application security
Need Complete Chapters of the Above Topic?
Get high-quality, Zero-AI research materials with current citations.
Request via WhatsApp 💬