GDN DESKTOP 1

Advertisement

‎Stakeholder seeks stronger vetting of government software testing firms ‎

Procurement specialist, Dr Ogechi Ibeh Obinna

As Nigeria moves to strengthen standards for testing government software, procurement specialist, Dr Ogechi Ibeh Obinna, has called for stricter scrutiny of organisations entrusted with testing critical digital systems.

‎Obinna, who is the Head of Procurement, National Assembly Library Trust Fund, said technical certification alone was insufficient to guarantee the security and reliability of government software, arguing that the competence, independence, integrity and security practices of testing firms must also be assessed.

‎Her position comes as the National Information Technology Development Agency (NITDA) develops a software quality-assurance regime covering software development, independent testing and licensing of software-testing organisations.

‎The framework adopts a risk-based approach, classifying software according to its complexity, impact and potential consequences of failure. Class A systems constitute the highest category, covering high-impact and high-risk platforms whose failure could have serious implications for national security, human safety or economic stability.

Advertisement

‎Obinna said the increasing dependence of government institutions on software for revenue administration, identity management, healthcare, public finance and other critical services made software assurance a matter of national interest.

‎She, however, warned that independent testing itself could create security risks because testing organisations may gain access to source code, system architecture, credentials, data flows and reports identifying vulnerabilities in government systems.

EFN Non Oil Export

‎“Independent testing is necessary, but independence cannot be assumed merely because an organisation did not develop the software.

‎“It must be supported by verified competence, institutional integrity, strong security controls and freedom from conflicting interests,” she said.

Advertisement

‎She urged procurement institutions to become more involved in technology projects from the beginning, rather than limiting their role to tendering, evaluation, contracting and payment.

‎According to her, procurement strategies should reflect the consequences of potential system failure, with more stringent due diligence and contractual safeguards applied to systems handling sensitive national information.

‎For Class A engagements, she recommended scrutiny of the ownership and control of testing firms, the personnel assigned to sensitive projects, subcontractors, security capabilities and possible conflicts of interest.

‎“A technically qualified organisation may still present an unacceptable governance risk. Capability answers whether the firm can perform the assignment. Due diligence answers whether it should be entrusted with the assignment,” Obinna said.

‎She also called for security requirements to be incorporated into procurement documents and contracts, including rules governing access to systems, subcontracting, protection of test data and credentials, vulnerability reporting, security incidents and the handling of sensitive information after an engagement.

‎Obinna said the requirements should complement NITDA’s existing testing and documentation provisions, as well as obligations under the Nigeria Data Protection Act and other relevant cybersecurity regulations.

‎She further cautioned against allowing testing organisations to certify systems they designed or developed, saying ownership, professional and commercial relationships between developers and testers should be disclosed and independently assessed.

‎While supporting periodic audits, licence renewal and sanctions, she said licensing should not mark the end of scrutiny, noting that ownership, personnel and security controls could change after accreditation.

‎Obinna also warned that excessively high barriers could lead to market concentration if only a few firms qualify to test critical systems. She advocated investment in training, certification and secure testing infrastructure to develop more credible Nigerian firms without lowering standards.

Advertisement

‎She said the broader lesson was that value for money in technology procurement should not be determined by price alone.

‎“Procurement is no longer merely the process through which government buys technology. In a digital state, it is one of the principal ways through which government protects its institutions, its information and the citizens it serves,” she said.

 

Join Our Channels

Taboola Recommendation Widget