Cloud Security for Nigerian Critical Infrastructure: A Five-Pillar Implementation Framework and Synthetic-Data Demonstration
DOI:
https://doi.org/10.33003/fjs-2026-1017-6050Keywords:
Cloud Security, Critical Infrastructure, Nigeria, Synthetic Data, Cybersecurity Governance, Sensitivity Analysis, Shared ResponsibilityAbstract
Cloud-supported critical services require coordinated technical controls, accountable governance, and demonstrable recovery arrangements. This article proposes a Nigeria-focused cloud-security implementation framework and evaluates the behaviour of an accompanying implementation-gap index using synthetic data. The framework organises existing practices into five pillars: technical and operational controls, policy and governance, capacity building, collaboration, and threat intelligence. It links these pillars to control ownership and auditable evidence, with reference to international guidance and Nigerian policy instruments. The computational demonstration uses 100 fictional organisational profiles per replication, nine indicators with fixed marginal distributions, and 1,000 replications at each of three latent dependence settings. No professionals were surveyed, no experts were interviewed, and no incident records were analysed. Although the equal-pillar mean index remains 58.625 under every setting by construction, the simulated mean number of profiles with co-existing unsupported-software and authentication gaps increases from 32.42 to 47.99 as latent dependence increases. The corresponding number with an index of at least 75 increases from 20.67 to 48.02. Median overlap between alternative weighting schemes and the equal-pillar top-20 selection ranges from 13 to 20 profiles. These results demonstrate that fixed headline percentages do not identify the concentration of implementation gaps, and that review priorities depend on joint structure and weighting choices. The contribution is a transparent implementation and evaluation approach, not evidence of Nigerian incident prevalence, terrorist attribution, regulatory non-compliance, or intervention effectiveness. Independent field evaluation is required before operational adoption.
References
Cloud Security Alliance. (2026). Cloud Controls Matrix and CAIQ v4.1. https://cloudsecurityalliance.org/artifacts/cloud-controls-matrix-v4-1
Federal Ministry of Communications, Innovation and Digital Economy (FMCIDE). (2026, August 17). Federal Government unveils National Digital Cloud Policy to drive investment, digital sovereignty and government transformation [Policy announcement]. Official ministry policy announcement
Federal Republic of Nigeria. (2023). Nigeria Data Protection Act, 2023. Federal Republic of Nigeria Official Gazette. https://cert.gov.ng/ngcert/resources/Nigeria_Data_Protection_Act_2023.pdf
Federal Republic of Nigeria. (2024a). Cybercrimes (Prohibition, Prevention, etc.) Act, 2015 with Amendment Act 2024. Consolidated publication hosted by the Office of the National Security Adviser/ngCERT. https://cert.gov.ng/ngcert/resources/CyberCrime__Prohibition_Prevention_etc__Act__2024.pdf
Federal Republic of Nigeria. (2024b). Designation and Protection of Critical National Information Infrastructure Order, 2024. Federal Republic of Nigeria Official Gazette, 111(107). https://cert.gov.ng/ngcert/resources/cnii-gazette.pdf
Hashizume, K., Rosado, D. G., Fernández-Medina, E., & Fernandez, E. B. (2013). An analysis of security issues for cloud computing. Journal of Internet Services and Applications, 4, Article 5. https://doi.org/10.1186/1869-0238-4-5
International Organization for Standardization/International Electrotechnical Commission (ISO/IEC). (2022). ISO/IEC 27001:2022: Information security, cybersecurity and privacy protection—Information security management systems—Requirements. https://www.iso.org/standard/27001
Mell, P., & Grance, T. (2011). The NIST definition of cloud computing (NIST SP 800-145). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-145
Morris, T. P., White, I. R., & Crowther, M. J. (2019). Using simulation studies to evaluate statistical methods. Statistics in Medicine, 38(11), 2074–2102. https://doi.org/10.1002/sim.8086
National Institute of Standards and Technology (NIST). (2024). The NIST Cybersecurity Framework (CSF) 2.0 (NIST CSWP 29). https://doi.org/10.6028/NIST.CSWP.29
Nelson, A., Rekhi, S., Souppaya, M., & Scarfone, K. (2025). Incident response recommendations and considerations for cybersecurity risk management: A CSF 2.0 Community Profile (NIST SP 800-61 Rev. 3). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-61r3
Nigeria Data Protection Commission (NDPC). (2025). Nigeria Data Protection Act (NDP Act) 2023: General Application and Implementation Directive (GAID) 2025 (NDPC/NDP ACT-GAID/01/2025). https://ndpc.gov.ng/wp-content/uploads/2025/07/NDP-ACT-GAID-2025-MARCH-20TH.pdf
Office of the National Security Adviser. (2021). National cybersecurity policy and strategy. https://cert.gov.ng/ngcert/resources/NATIONAL_CYBERSECURITY_POLICY_AND_STRATEGY_2021.pdf
Peffers, K., Tuunanen, T., Rothenberger, M. A., & Chatterjee, S. (2007). A design science research methodology for information systems research. Journal of Management Information Systems, 24(3), 45–77. https://doi.org/10.2753/MIS0742-1222240302
Stouffer, K., Pease, M., Tang, C., Zimmerman, T., Pillitteri, V., Lightman, S., Hahn, A., Saravia, S., Sherule, A., & Thompson, M. (2023). Guide to operational technology (OT) security (NIST SP 800-82 Rev. 3). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-82r3
Downloads
Published
Issue
Section
Categories
License
Copyright (c) 2026 Olawale Olalekan Onalaja, Sulaiman Adesegun Kukoyi, Oluwaseun Ayodeji Odusanya, Abayomi Opeoluwa Kehinde, Olugbenga G. Obadina

This work is licensed under a Creative Commons Attribution 4.0 International License.