close
Friday, December 13, 2024

Oduyoye Omotoyosi: Gaps in new NIS technology innovation complex

Arise, O Compatriots! Nigeria Calls to Obey

• December 13, 2024
NIS OPERATIVES
NIS OPERATIVES(Credit: Premium Times Nigeria)

Arise, O Compatriots! Nigeria Calls to Obey. The first phrase of our former national anthem is etched in history, symboliSing a call to action for all Nigerians.

Recently, I came across a video online featuring the commissioning of the Bola Ahmed Tinubu Technology Innovation Complex at the Nigerian Immigration Service (NIS) Headquarters in Abuja, showcasing some of the technology facilities on ground including a newly built data center. The initiative is a commendable step toward addressing systemic lapses and reducing corruption, particularly in passport processing.

Nigerians can relate to how arduous obtaining or renewing a passport used to be. From excessive waiting periods to unofficial fees—popularly called “settle”—the system was challenging to navigate. Thanks to reforms introduced by Dr. Olubunmi Tunji-Ojo and the new NIS administration, these difficulties have improved significantly. Today, passport processing has become more efficient, transparent, and accessible.

However, with technological advancement comes a new level of responsibility, especially concerning information security. As an information security analyst, I observed a critical security gap in the video advertising the newly commissioned complex.

The complex was described as “A sophisticated, multibillion-naira project housing some of the most advanced technological security solutions, competing globally while serving as a blueprint for the rest of Africa.”

While this sounds ambitious, my professional analysis reveals significant security flaws that deviate from globally recognized security standards such as ISO/IEC 27001, NIST SP 800-53, and CIS Controls. Co-locating a data center in the same complex as a primary business or advertising its physical location introduces significant vulnerabilities making it as easy target for threat actors.

Let’s break it down against globally recognized security standards and frameworks like ISO/IEC 27001, NIST SP 800-53, and CIS Controls:

  • Data Center Location

Risk: Having a data center within the same facility increases exposure to both physical and cyber threats, including natural disasters, insider threats, and targeted attacks.

Framework Alignment:

ISO/IEC 27001 mandates that organizations consider location-specific risks (A.11.1 – Physical Security Perimeter).

NIST SP 800-53 (PE-18) specifies the need for “location diversification” to reduce the impact of a single failure.

Best Practice: Data centers should be in geographically separate, secure facilities to ensure redundancy and disaster recovery.

  • Advertising the Data Center

Risk: Publicly disclosing the location of a critical infrastructure makes it an easy target for threat actors.

Framework Alignment: ISO/IEC 27001 recommends maintaining confidentiality for sensitive infrastructure (A.18.1 – Compliance with Security Policies).

CIS Control 14 emphasizes minimizing the attack surface, including exposure to public information.

Best Practice: Limit information about the data center’s location to only authorized personnel with a need-to-know basis.

While the reforms and innovations introduced at the NIS are laudable, there is a pressing need to align the implementation with international best practices for information security. Addressing these critical vulnerabilities will not only enhance the security posture of the NIS but also serve as a true benchmark for Africa and beyond.

Omotoyosi Oduyoye is a Certified Information Systems Auditor (CISA) and Certified in Cyber Cybersecurity (CC) based in Edmonton, Canada.

We have recently deactivated our website's comment provider in favour of other channels of distribution and commentary. We encourage you to join the conversation on our stories via our Facebook, Twitter and other social media pages.

More from Peoples Gazette

Abubakar Kyari

Agriculture

FG tasks ECOWAS on leveraging financing strategies for agroecology

The federal government has urged stakeholders in the agriculture and finance sectors in the West Africa region to leverage financing strategies to enhance agroecology practices

Katsina State

Politics

Katsina youths pledge to deliver over 2 million votes to Atiku

“Katsina State is Atiku’s political base because it is his second home.”

Sport

Court jails China’s former football team coach 20 years for bribery

“I’m very sorry. I should have kept my head to the ground and followed the right path,” stated the ex-coach.

World

China, Egypt agree on need to promote peace in Middle East

Mr Al-Assad fled the country after the offensive, bringing a sudden end to decades of repressive rule by his clan.

Uncategorized

N80 Billion Fraud: Court grants Yahaya Bello N500 million bail

Justice Emeka Nwite, in a ruling, ordered that the two sureties must be landed property owners within the court’s jurisdiction.

Economy

Chinese investors waive right to respond to Nigeria’s petition to U.S. Supreme Court over assets seizure

Nigeria filed a writ of certiorari asking the top court to examine their immunity argument and review rulings from lower courts.

States

Ibadan: Ex-convict jailed for stealing church bell

Delivering judgment, the magistrate, O.O. Latunji, said that the sentence is based on evidence tendered before her by the police and his guilty plea.

Local courtroom

States

Ibadan man accuses wife of having affairs with his plumber

During cross-examination, the petitioner said that his wife did not catch him on their matrimonial bed with any woman.