📖 ABSTRACT/OVERVIEW
Critical information infrastructure protection is a national security priority, and professional assessment of Nigeria's CIIP framework provides evidence for strengthening the country's resilience against attacks on essential services. This study professionally assessed Nigeria's Critical Information Infrastructure Protection framework against international CIIP standards and the current threat environment. A mixed assessment methodology was employed, combining documentary analysis of the Nigeria Cybercrime (Prohibition, Prevention) Act 2015, NITDA National Cybersecurity Policy 2021, and Presidential Executive Orders relating to CIIP, structured interviews with 12 government cybersecurity officials and 8 critical infrastructure operators from five sectors (energy, telecommunications, banking, health, and water), and benchmarking against US NIST SP 800-160, EU NIS2 Directive, and African Union CIIP guidelines. Assessment revealed that formal CIIP designation for specific entities was absent in three of five assessed sectors. Sector-specific cybersecurity requirements existed only for banking and telecommunications. Information sharing between government and critical infrastructure operators was rated as inadequate by 91.7 percent of operators. No Nigerian sector had undergone a formal nationally coordinated CIIP exercise in the preceding three years. The study concludes that Nigeria's CIIP framework is normatively established but operationally underdeveloped. Recommendations include formal sector-specific CIIP designation regulations, mandatory inter-sector threat intelligence sharing, annual national cyber exercise, and dedicated critical infrastructure cybersecurity technical assistance teams under NITDA.
Keywords: critical information infrastructure, CIIP, Nigeria, cybersecurity policy, national cyber resilience
Need Complete Chapters of the Above Topic?
Get high-quality, Zero-AI research materials with current citations.
Request via WhatsApp 💬