← Latest papers
💻 computer science

A Design Science Approach to Zero Trust Cyber Risk Governance in Digital Government Platforms: Development and Evaluation of the CRGMM Framework

This paper presents the development and preliminary validation of the Cyber Risk Governance Maturity Model (CRGMM), a novel Design Science framework that integrates Zero Trust principles to assess and guide the cyber risk governance of multi-agency digital government platforms, as demonstrated through its application to Kuwait's Sahel system.

Original authors: Abdullah F. Alenezi

Published 2026-07-10
📖 7 min read🧠 Deep dive

Original authors: Abdullah F. Alenezi

Original paper licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

Imagine Kuwait's digital government, Sahel, as a massive, super-fast train station. Instead of having 433 separate ticket booths, each with its own security guard and waiting room, the government built one giant, high-tech terminal where everyone enters through a single gate. This is brilliant for speed and convenience: you can buy a train ticket, renew a passport, and pay a utility bill all in one place. But here's the catch: if a thief breaks into this one terminal, they don't just steal one person's ticket; they could potentially grab the keys to the entire city's transportation system.

This paper, written by Abdullah F. Alenezi, argues that while Kuwait has built a very fancy train station with some cool new locks (like fingerprint scanners), the blueprint for the security guards is missing. The station is running on "Zero Trust" principles (a fancy way of saying "never trust anyone, always check their ID"), but the rules for who gets to check the IDs and what happens if the locks are picked haven't been written down in law yet.

The Big Problem: The "Concentration Paradox"

The paper calls this the Concentration Paradox. It's like putting all your eggs in one basket because it's easier to carry, but then realizing that if the basket drops, you lose all your eggs at once.

  • The Good News: The station is operational. Over 122 million trips have been made, and the fingerprint scanners (called Hawyti) are working.
  • The Bad News: The station is a Systemically Important Government Platform (SIGP). This means it's so important that if it crashes, the whole country feels it. Yet, the paper finds that the station's "emergency exit plan" and "data protection laws" are still in the drafting phase.

The "CRGMM" Tool: A Report Card for Security

To fix this, the author invented a new tool called the Cyber Risk Governance Maturity Model (CRGMM). Think of this as a specialized report card designed specifically for giant digital train stations, not just regular offices.

Most existing report cards (like CMMI or NIST CSF) are like checking if a single car has a working brake. But Sahel is a whole fleet of 433 cars linked together. The old report cards don't know how to grade the connection between the cars.

The new CRGMM report card has six dimensions (like six different subjects in school) and five levels (from "Failing" to "A+"). The author tested this report card with a panel of 15 experts (a mix of university professors, government tech guys, and security pros). The experts agreed on the grades with a score of 0.76 (which is a solid "B+" level of agreement in the world of statistics).

What the Report Card Found

When the author used this new report card on Kuwait's Sahel platform, the results were a mix of "Great Hardware" and "Missing Rules":

  1. The "Critical" Risks: The paper identified two threats as Critical (the highest danger level, scoring 20 out of 25).

    • Platform Identity Fraud: Bad guys pretending to be the station (fake apps, phishing texts). The station has a "report fraud" button (called Aman), but it's like having a mailbox for complaints without a police force to actually catch the criminals.
    • Cross-Agency Data Breach: Since 38 different government agencies are linked, if one agency has a weak lock, the bad guys can walk right through to the others. The paper says there is no rule forcing these agencies to use a "Zero Trust" system (where you check ID at every single door, not just the front gate).
  2. The "Missing" Laws: The paper points out a huge gap: Kuwait does not yet have a Personal Data Protection Law (PDPL) or an independent Data Protection Authority (DPA).

    • Analogy: It's like building a bank vault with a state-of-the-art steel door, but the bank has no law saying the vault must be locked, and no police officer is assigned to watch it. The paper argues that without these laws, the fancy door is just decoration.
  3. The "Biometric" Trap: The station uses fingerprints and facial scans. The paper warns that unlike a password, you can't change your fingerprint if it gets stolen. If a hacker steals the fingerprint data, it's gone forever. The paper says there are no specific laws yet to protect this "irreversible" data.

What the Paper Rules Out

The author is very clear about what won't work:

  • Just "Checking the Box": You can't just say "We are ISO 27001 certified" (a standard for security) and call it a day. The paper argues that certification without a real law behind it is "surface compliance"—it looks good on paper but doesn't actually stop the thieves.
  • Waiting for Time to Fix It: The paper rejects the idea that the security problems will fix themselves as the platform grows. In fact, the more services you add, the worse the risk gets because the "governance gap" (the missing rules) gets wider.
  • Copying Enterprise Models: You can't just use security rules designed for a regular company (like a bank or a tech firm) because a government platform deals with citizens, not just employees. The rules need to be different.

The Proposed Roadmap: A Three-Phase Plan

The paper suggests a step-by-step plan to fix the station, but it insists on doing things in the right order. You can't build the roof before you pour the foundation.

  • Phase 1 (The Foundation - 0 to 18 months): Before adding more tech, you must write the laws.
    • Pass a Personal Data Protection Law.
    • Create an independent Data Protection Authority (a police force for data).
    • Make a public plan for what to do if a breach happens (including telling citizens within 72 hours).
  • Phase 2 (The Structure - 18 to 36 months): Now you build the tech rules.
    • Force all agencies to get certified and use Zero Trust (checking ID at every door).
    • Create a special shield for the fingerprint data.
  • Phase 3 (The Culture - 36 to 60 months): Teach the passengers.
    • Launch a program to teach citizens (in multiple languages) how to spot scams.

How Sure Are We?

The paper is very careful about what it knows and what it guesses.

  • Proven: The author measured the current state using public documents and a panel of experts. The score of 0.76 agreement among experts is a hard fact.
  • Simulated/Calculated: The "Risk Scores" (like the 20 for fraud) are calculated based on a formula (Likelihood × Impact) using known data. They are not guesses, but they are based on publicly available info, not secret internal tests.
  • Suggested: The "Three-Phase Plan" is a recommendation. The paper suggests this is the best way forward, but it hasn't been tested in the real world yet. The author admits they didn't get to run a "red team" (a group of hackers trying to break in) because that data isn't public.

The Bottom Line

The paper concludes that Kuwait's digital station is a marvel of engineering, but it's running on a legal vacuum. The CRGMM tool shows that the technology is ready, but the governance (the rules and laws) is lagging behind. The author argues that to keep the station safe, the government must stop building new services and start writing the laws that protect the ones they already have. It's a call to build the "rules of the road" before the "cars" get any faster.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →