📖 ABSTRACT/OVERVIEW
Nigerian software houses develop applications used by millions of Nigerians in banking, health, and government, yet the state of secure software development practices in this sector has received minimal research attention, creating a gap with significant implications for national cybersecurity posture. This study analytically examined this research gap through systematic review and original primary research. A scoping review of ten databases identified only 6 publications from 2018 to 2024 specifically addressing SSDLC practices in Nigerian software development companies. Original survey research was conducted with 80 software developers from 20 companies in Lagos and Abuja. Results showed that threat modelling was practised in only 22.5 percent of companies. Security code review was conducted in 37.5 percent. Penetration testing before release was performed by 31.3 percent. Security requirements were formally specified in only 27.5 percent of development projects. Developer security training had been received by only 33.8 percent. Companies with fintech or banking clients showed better SSDLC practices than those without regulated clients (p < 0.05). The study identifies four critical research gaps including absence of Nigerian SSDLC benchmark data, absent regulatory requirements for software security in non-financial sectors, and inadequate academic security engineering education. A national secure software development standard sponsored by NITDA is recommended. Keywords: secure software development, SSDLC, Nigerian software industry, developer security, research gap
Need Complete Chapters of the Above Topic?
Get high-quality, Zero-AI research materials with current citations.
Request via WhatsApp 💬