Developing and evaluating a zero trust cyber risk governance maturity model for digital government platforms
Abstract
This paper develops and evaluates a cyber risk engineering framework for multi-agency digital government platforms, employing a design science research (DSR) methodology to construct, operationalise, and preliminarily validate the Cyber Risk Governance Maturity Model (CRGMM) as a reusable computing artefact. Following Hevner et al.’s [18] DSR cycle, the CRGMM is constructed through threat modelling (STRIDE + MITRE ATT&CK v14), framework benchmarking (NIST CSF 2.0, ISO 27001/27701, CISA ZTA Maturity Model), and GQM-derived indicator design. Initial validation is conducted through a structured expert panel (n = 15), with ordinal Krippendorff’s alpha = 0.7644 (10,000-resample bootstrap 95% CI [0.6700, 0.9248]), and a single pilot case application to Kuwait’s Sahel platform — a systemically important government platform (SIGP) consolidating 433 + services for nine million users. The CRGMM comprises six governance dimensions, five maturity levels, and fourteen quantitative scoring indicators. Applied to Sahel, it reveals a structural governance-technology disjunction: operationally capable controls — biometric authentication, anti-fraud reporting, cloud-first infrastructure — coexist with critical legislative and accountability deficits. A quantitative threat severity matrix identifies platform identity fraud and cross-agency data breach as critical-band risks (score = 20). International benchmarking against UAE PASS, Estonia X-Road, Singapore SingPass/NDI, and Saudi Absher identifies the enacted-PDPL + independent-DPA combination as the single highest-priority reform. Ten sequenced policy propositions constitute a three-phase reform engineering roadmap. To the best of my knowledge, the CRGMM is among the first cyber risk engineering frameworks purpose-designed for multi-agency platform e-government, explicitly integrating zero trust architecture, privacy engineering, biometric identity governance, and citizen enablement as measurable dimensions. It addresses gaps in CMMI, NIST CSF tiers, CISA ZTA MM, CMMC, and C2M2 — none of which accommodate the governance challenges of cross-agency digital government platforms in regulatory-transition contexts.