📖 ABSTRACT/OVERVIEW
The Nigerian government's increasing migration of public services to cloud infrastructure creates an urgent requirement for integrated security practices within software development and operations pipelines, yet DevSecOps adoption in Nigerian public sector cloud environments remains nascent and empirically uncharacterised. This study empirically assesses DevSecOps integration in Nigerian government cloud infrastructure deployments, with data drawn from Galaxy Backbone operations supporting Federal Ministry of Communications projects in Abuja. A mixed-methods design combines a technical security audit of five government cloud workloads with interviews conducted with 18 government IT security officers and cloud administrators. The security audit evaluates Infrastructure-as-Code security scanning, container image vulnerability management, secrets management practices, and network micro-segmentation adherence against the Cloud Security Alliance framework. Findings identify critical gaps in secrets management, with plaintext credentials found in 3 of 5 audited workloads, absent container runtime security monitoring, and no automated IaC security scanning in any evaluated pipeline. Interview data reveals that budget constraints, skills shortages in cloud security, and slow procurement cycles for security tooling are the primary systemic barriers. A phased DevSecOps maturity roadmap adapted to Nigerian government IT governance constraints is proposed. Keywords: DevSecOps, government cloud, Nigeria, cloud security, Infrastructure-as-Code
Need Complete Chapters of the Above Topic?
Get high-quality, Zero-AI research materials with current citations.
Request via WhatsApp 💬