The country of Nigeria has launched a national cloud framework. It is hoped this will support digital infrastructure and provide a basis for cloud adoption.
The National Sovereign Cloud Regulatory Instrument has been approved in Nigeria. It has established the country’s guidelines and governance framework, which will oversee cloud services and adoption. The signing was held at the National Information Technology Development Agency (NITDA) in Abuja. Requirements will also be set out for data classification, data sovereignty, cloud security, investment promotion and risk management. This will provide a more robust and cohesive approach to governance of the cloud across the country.
National Cloud Security
Preventing unwanted data access has been something companies have worked hard to combat for some time, or at least the biggest. The average cost of a data breach is estimated to be $4.88M. Cloud security tools have long been essential for safeguarding this. This list of 10 types explained for teams includes methods like Cloud Access Security Broker (CASB), Cloud Detection and Response, and Cloud Vulnerability Management. Yet with all these methods used, countries have been struggling to catch up.
Galaxy Backbone, the shared service provider of digital systems of the Nigerian Government, has said the move will increase trust and help sustain a drive toward a secure and resilient digital economy. They added that “As the Federal Government’s trusted digital infrastructure and shared services provider, Galaxy Backbone remains committed to supporting the implementation of policies and technologies that strengthen digital trust, protect national data assets, and accelerate Nigeria’s digital transformation agenda.”
Several key stakeholders were at the signing ceremony. They included Chief Executive Officer of Galaxy Backbone Prof. Ibrahim Adeyanju, the Permanent Secretary of the Federal Ministry of Communications, Innovation and Digital Economy, Engr. Nadungu Gagare, and NITDA Director General Kashifu Inuwa.
What is Data Sovereignty?
Data sovereignty refers to the process of data being subject to the laws and regulations of the location it currently exists in. It covers data that is in transmission, storage, or processing, regardless of the location of the organization from which it came. Often referred to as data residency, it can help protect sensitive information from cyber attacks and data theft.
There are three main terms, often used interchangeably, when it comes to data sovereignty. However, each of them works slightly differently and describes a different aspect.
- Sovereignty – Data stored and processed in the place it was created
- Residency – Data that is held in a different place to that from which it was created
- Localization – The process of compliance regarding the local laws related to residency.
Thus, data sovereignty is determined using these three criteria. Consider a European company that stores data in Ireland using a US-based cloud service provider. Thus, even though it resides in the European Union, it may still have to comply with data sovereignty rules under US law. This is despite the fact that its data originated and exists in Europe, making it an extremely complex challenge.
Why Is Data Sovereignty Important?
Data sovereignty is vital for several reasons. Firstly, it is a way in which control can be given over access to data. Some data, as mentioned in the example above, may be subject to foreign oversight. This can pose several risks for companies, as data may come under surveillance without the owner’s consent.
There are also certain compliance risks. Laws like the GDPR can give huge penalties and fines if breached. Thus, strict controls on data and how it can travel must be adhered to.
By having a national data sovereignty plan, it also helps protect against threats to the state. Risks exist from geopolitical tensions, with many cyber attacks stemming from rogue states like North Korea. Keeping data in areas that are open to attack and not protected by data sovereignty can increase the risk of espionage.
Lastly, the safe storing of data and sovereignty builds trust. Customers want to know their data is safe when it is held by a business. This works no differently for sovereign nations. Countries like Nigeria can implement these strategies and, with safeguards in place, begin to attract business and companies from across the globe.
The Main Challenges
By no means will these improvements in data sovereignty clear up all of Nigeria’s issues. The country remains vulnerable to attacks, and this is often cited as being down to high levels of corruption coming from within. Poor monitoring, bribery and fraud have long hindered the government, taking the form of procurement fraud, insider threats and weak accountability.
To really thrive, these issues must be addressed alongside data sovereignty and security. Only then will the systems work together, creating a robust framework on which future digital endeavours can be built. To do so, transparency and accountability must become cornerstones. This is hurting Nigeria’s reputation on a global stage, and will be crucial if it wants to attract international business.
