📖 ABSTRACT/OVERVIEW
State government agencies in Nigeria manage extensive citizen data and public service delivery systems, yet most operate without formal cybersecurity governance frameworks that align with national and international standards. This study developed a cybersecurity governance framework for Nigerian state government agencies, drawing on case contexts from Kano, Rivers, and Plateau State agencies representing the North West, South South, and North Central geopolitical zones. A professional framework development methodology was applied, incorporating a gap analysis of current state agency cybersecurity governance against NIST CSF, ISO/IEC 27001, and NITDA Cybersecurity Framework standards through structured interviews with 18 state IT officers and 6 cybersecurity policy specialists, and review of existing state ICT policies. The gap analysis confirmed that 72.2 percent of interviewed state agencies lacked a cybersecurity policy document, risk assessment had not been conducted in any agency within the preceding 24 months, and no agency maintained a documented asset inventory. The framework developed encompasses four governance pillars: policy and risk management, technical security standards, personnel security management, and incident management. Each pillar includes specific controls, responsible officer designations, and performance indicators. Expert review by eight cybersecurity governance specialists confirmed the framework's alignment with Nigerian regulatory requirements and practical state-level resource constraints. The study recommends adoption of the framework by NITDA as a state government cybersecurity governance baseline standard and piloting in three state agencies across different geopolitical zones.
Keywords: cybersecurity governance framework, state government agencies, NIST CSF, Nigeria, security policy
Need Complete Chapters of the Above Topic?
Get high-quality, Zero-AI research materials with current citations.
Request via WhatsApp 💬