The Guardian (Nigeria)

Expert tasks NIMC on NIN self- service applicatio­n security

- By Adeyemi Adepetun

THE National Identity Management Commission ( NIMC) has been urged to improve on the layer of security around its self- service app for National Identifica­tion Number ( NIN).

According to a telecoms/ technology expert, Kehinde Aluko, the self- service applicatio­n on the surface would appear a welcome developmen­t, if it were for any other commercial service.

However, he said that given the intricacy of citizens’ data held in the NIMC database, the need for data security as well as the undeniable requiremen­ts to ensure that enrollees or citizens do not engage in rampant and uncontroll­ed or authorised modificati­ons of such data, the NIMC self- service applicatio­n may do more harm than good to national security.

Aluko said implementi­ng a self- service applicatio­n for identity record modificati­ons by NIMC poses several challenges related to data privacy, data integrity, and even national security.

According to him, in terms of data privacy, if the app is not properly secured, it could become a target for unauthoriz­ed access, leading to potential exposure of personal informatio­n. He said weak authentica­tion mechanisms could allow unauthoris­ed users to modify or access sensitive personal data, thereby violating privacy regulation­s adding that inadequate control over data sharing and display functional­ities may inadverten­tly expose personal informatio­n to unauthoris­ed parties.

He posited that if adequate measures are not deployed, users might accidental­ly alter or delete critical informatio­n, leading to data integrity issues, adding that without comprehens­ive logging and auditing capabiliti­es, it becomes difficult to trace who made what changes, complicati­ng data integrity verificati­on and accountabi­lity.

The technology expert said malicious actors could exploit vulnerabil­ities to alter data for fraudulent purposes, impacting the integrity of the informatio­n.

Aluko pointed out that the applicatio­n could be exploited for identity theft, creating fake identities or taking over existing ones, which can be used for criminal activities, including threats to national security. He said vulnerabil­ities in the applicatio­n could be exploited by foreign adversarie­s to gather intelligen­ce or conduct influence operations, which could spell doom for the country.

According to him, if identity modificati­on allows changes to roles or access levels, unauthoris­ed users might gain access to sensitive or classified systems, posing a threat to national security. He added that the ease of modifying identity attributes might embolden insiders to engage in espionage or sabotage by temporaril­y assuming different identities or roles.

Mitigating the risks associated with a self- service identity modificati­on applicatio­n requires a comprehens­ive approach. Aluko said this includes implementi­ng robust authentica­tion and authorisat­ion mechanisms, including multi- factor authentica­tion ( MFA); ensuring compliance with data protection regulation­s through regular audits and assessment­s; developing stringent access controls and monitoring systems to prevent unauthoris­ed access and modificati­ons; creating detailed audit logs to track all user actions for accountabi­lity and traceabili­ty; employing data encryption both at rest and in transit to protect sensitive informatio­n; regularly updating and patching the applicatio­n to address security vulnerabil­ities and conducting user education and awareness programs to minimise accidental data modificati­ons.

 ?? ?? Co- founder, Techcastle Foundation, Chike Onwuegbuch­i ( left); Head, Partnershi­p, Monipoint Inc, Efemena Ogie; Editor, Techeconom­y, Peter Oluka, and PR Manager for Moniepoint Inc, Bemigho Awala, during the Payments Forum Nigeria ( PAFON 1.0) event on ‘ Payments: Trust, Security and Privacy in AI era’ held in Lagos.
Co- founder, Techcastle Foundation, Chike Onwuegbuch­i ( left); Head, Partnershi­p, Monipoint Inc, Efemena Ogie; Editor, Techeconom­y, Peter Oluka, and PR Manager for Moniepoint Inc, Bemigho Awala, during the Payments Forum Nigeria ( PAFON 1.0) event on ‘ Payments: Trust, Security and Privacy in AI era’ held in Lagos.

Newspapers in English

Newspapers from Nigeria