International Peer-Reviewed Journal•Open Access•ISSN 2456-8880
irejournals@gmail.com•+91-7433024337

Home / Current Issue / Paper 1702715

1702715 Vol 4 · Issue 11 Download Paper

Development of a Compliance-Driven Identity Governance Model for Enhancing Enterprise Information Security

Oluchukwu Modesta Oluoha Abisola Odeshina Oluwatosin Reis Friday Okpeke Verlinda Attipoe Omamode Henry Orieno

Subject area: Science,Engineering and Technology  ·  Area of research: Information Security

Abstract

In the contemporary digital landscape, organizations face increasing regulatory pressures and cybersecurity threats that demand robust identity and access management (IAM) frameworks. Traditional identity governance models often fall short in dynamically aligning with evolving compliance mandates, resulting in security vulnerabilities and audit deficiencies. This study proposes the development of a Compliance-Driven Identity Governance Model (CD-IGM) aimed at enhancing enterprise information security while ensuring regulatory alignment. The model integrates compliance requirements as a foundational design principle rather than a peripheral consideration, embedding regulatory frameworks such as GDPR, HIPAA, SOX, and ISO 27001 into the identity lifecycle management process. The CD-IGM framework is designed around three core pillars: Policy-Centric Access Control, Automated Compliance Monitoring, and Risk-Based Role Engineering. Policy-Centric Access Control ensures that access decisions are tightly coupled with compliance mandates and business rules. Automated Compliance Monitoring leverages artificial intelligence and machine learning to continuously audit user activities, detect anomalies, and generate compliance reports in real time. Risk-Based Role Engineering utilizes behavior analytics and contextual data to dynamically assign roles and permissions based on assessed risk levels. A prototype of the model was implemented and evaluated in a simulated enterprise environment to measure its effectiveness in improving security posture and compliance readiness. Results demonstrated a 35% reduction in unauthorized access incidents and a 50% improvement in audit response times compared to traditional models. Furthermore, stakeholders reported enhanced visibility and control over identity-related risks and improved confidence in compliance audits. The proposed model offers a scalable, proactive, and adaptive approach to identity governance that aligns organizational security objectives with compliance requirements. It represents a paradigm shift from reactive compliance fulfillment to strategic compliance integration, thereby fostering a culture of security by design. The model?s modular architecture also supports integration with existing IAM systems, cloud platforms, and emerging technologies such as Zero Trust and blockchain-based identity systems. This research contributes to the body of knowledge in information security governance by bridging the gap between compliance and identity management, offering practical and theoretical implications for enterprises, policymakers, and cybersecurity professionals seeking to enhance data protection and regulatory conformance.

Keywords

Identity Governance, Compliance, Information Security, Access Management, Risk-Based Role Engineering, Audit, Policy-Centric Control, Artificial Intelligence, Cybersecurity, Regulatory Frameworks.

References

[1] Abisoye, A., & Akerele, J. I. (2021): A High-Impact Data-Driven Decision-Making Model for Integrating Cutting-Edge Cybersecurity Strategies into Public Policy, Governance, and Organizational Frameworks.

[2] Adewale, T. T., Olorunyomi, T. D., & Odonkor, T. N. (2021). Advancing sustainability accounting: A unified model for ESG integration and auditing. International Journal of Science and Research Archive, 2(1), 169-185.

[3] Adewale, T. T., Olorunyomi, T. D., & Odonkor, T. N. (2021). AI-powered financial forensic systems: A conceptual framework for fraud detection and prevention. Magna Scientia Advanced Research and Reviews, 2(2), 119-136.

[4] Adewoyin, M. A. (2021). Developing frameworks for managing low-carbon energy transitions: overcoming barriers to implementation in the oil and gas industry.

[5] Agbede, O. O., Akhigbe, E. E., Ajayi, A. J., & Egbuhuzor, N. S. (2021). Assessing economic risks and returns of energy transitions with quantitative financial approaches. International Journal of Multidisciplinary Research and Growth Evaluation, 2(1), 552-566. https://doi.org/10.54660/.IJMRGE.2021.2.1.552-566

[6] Agho, G., Ezeh, M. O., Isong, M., Iwe, D., & Oluseyi, K. A. (2021). Sustainable pore pressure prediction and its impact on geo-mechanical modelling for enhanced drilling operations. World Journal of Advanced Research and Reviews, 12(1), 540–557. https://doi.org/10.30574/wjarr.2021.12.1.0536

[7] Ajayi, A. & Akerele, J. I. (2021). A High-Impact Data-Driven Decision-Making Model for Integrating Cutting-Edge Cybersecurity Strategies into Public Policy, Governance, and Organizational Frameworks. International Journal of Multidisciplinary Research and Growth Evaluation, 2(1), pp. 623-637. DOI: https://doi.org/10.54660/IJMRGE.2021.2.1.623-637.

[8] Ajayi, A. B., Folarin, T. E., Mustapha, H. A., Popoola, A. F., & Afolabi, S. O. (2020). Development of a low-cost polyurethane (foam) waste shredding machine. ABUAD Journal of Engineering Research and Development, 3(2), 105–114. http://ajerd.abuad.edu.ng/wp-content/uploads/2020/12/AJERD0302-12.pdf

[9] Ajayi, A. B., Mustapha, H. A., Popoola, A. F., Folarin, T. E., & Afolabi, S. O. (2021). Development of a rectangular mould with vertical screw press for polyurethane (foam) waste recycling machine. Polyurethane, 4(1). http://ajerd.abuad.edu.ng/wp-content/uploads/2021/07/AJERD0401-05.pdf

[10] Ajayi, A. B., Popoola, A. F., Mustapha, H. A., Folarin, T. E., & Afolabi, S. O. (2020). Development of a mixer for polyurethane (foam) waste recycling machine. ABUAD Journal of Engineering Research and Development, in-Press. http://ajerd.abuad.edu.ng/wp-content/uploads/2021/07/AJERD0401-03.pdf

[11] Ajayi, A. J., Akhigbe, E. E., Egbuhuzor, N. S., & Agbede, O. O. (2021). Bridging data and decision-making: AI-enabled analytics for project management in oil and gas infrastructure. International Journal of Multidisciplinary Research and Growth Evaluation, 2(1), 567-580. https://doi.org/10.54660/.IJMRGE.2021.2.1.567-580

[12] Ajonbadi, H. A., Lawal, A. A., Badmus, D. A., & Otokiti, B. O. (2014). Financial Control and Organisational Performance of the Nigerian Small and Medium Enterprises (SMEs): A Catalyst for Economic Growth. American Journal of Business, Economics and Management, 2(2), 135-143.

[13] Ajonbadi, H. A., Mojeed-Sanni, B. A., & Otokiti, B. O. (2015). Sustaining competitive advantage in medium-sized enterprises (MEs) through employee social interaction and helping behaviours. Journal of Small Business and Entrepreneurship, 3(2), 1–16.

[14] Ajonbadi, H.A, Lawal, A.A., and Badmus, D.A and Otokiti B.O (2014). Leadership and Organisational Performance in the Nigeria Small and Medium Enterprises (SMEs). American Journal of Business, Economics and Management, Vol. 36, Issue, 2.

[15] Ajonbadi, H.A, Mojeed-Sanni, B.A and Otokiti, B.O (2015). Sustaining Competitive Advantage in Medium-sized Enterprises (MEs) through Employee Social Interaction and Helping Behaviours. Business and Economic Research Journal, Vol. 36, Issue 4.

[16] Ajonbadi, H.A, Otokiti, B. O, and Adebayo, P. (2016). The Efficacy of Planning on Organisational Performance in the Nigeria SMEs. European Journal of Business and Management, Vol. 24, Issue 3.

[17] Akhigbe, E. E., Egbuhuzor, N. S., Ajayi, A. J., & Agbede, O. O. (2021). Financial valuation of green bonds for sustainability-focused energy investment portfolios and projects. Magna Scientia Advanced Research and Reviews, 2(1), 109-128. https://doi.org/10.30574/msarr.2021.2.1.0033

[18] Akinbola, O. A., & Otokiti, B. O. (2012). Effects of lease options as a source of finance on profitability performance of small and medium enterprises (SMEs) in Lagos State, Nigeria. International Journal of Economic Development Research and Investment Vol. 3 No3, Dec 2012.

[19] Akinbola, O. A., Otokiti, B. O., Akinbola, O. S., & Sanni, S. A. (2020). Nexus of Born Global Entrepreneurship Firms and Economic Development in Nigeria. Ekonomicko-manazerske spektrum, 14(1), 52-64.

[20] Akinbola, O.A., Otokiti, B.O, and Adegbuyi, O.A. (2014). Market Based Capabilities and Results: Inference for Telecommunication Service Businesses in Nigeria, The European Journal of Business and Social Sciences, Vol. 12, Issue 1.

[21] AlKalbani, A., Deng, H., Kam, B., & Zhang, X. (2017). Information security compliance in organizations: an institutional perspective. Data and Information Management, 1(2), 104-114. https://doi.org/10.1515/dim-2017-0006

[22] Al-Khouri, A. (2012). Biometrics technology and the new economy. International Journal of Innovation in the Digital Economy, 3(4), 1-28. https://doi.org/10.4018/jide.2012100101

[23] Al-Khouri, A. (2013). Privacy in the age of big data: exploring the role of modern identity management systems. World Journal of Social Science, 1(1). https://doi.org/10.5430/wjss.v1n1p37

[24] Alshammari, S., Albeshri, A., & Alsubhi, K. (2021). Integrating a high-reliability multicriteria trust evaluation model with task role-based access control for cloud services. Symmetry, 13(3), 492. https://doi.org/10.3390/sym13030492

[25] Backes, J., Berrueco, U., Bray, T., Brim, D., Cook, B., Gacek, A., … & Viswanathan, D. (2020). Stratified abstraction of access control policies., 165-176. https://doi.org/10.1007/978-3-030-53288-8_9

[26] Baldwin, A., Mont, M., Beres, Y., & Shiu, S. (2010). Assurance for federated identity management. Journal of Computer Security, 18(4), 541-572. https://doi.org/10.3233/jcs-2009-0380

[27] Berliner, D., Ingrams, A., & Piotrowski, S. (2021). Process effects of multistakeholder institutions: theory and evidence from the open government partnership. Regulation & Governance, 16(4), 1343-1361. https://doi.org/10.1111/rego.12430

[28] Butler, T. and O’Brien, L. (2018). Understanding regtech for digital regulatory compliance., 85-102. https://doi.org/10.1007/978-3-030-02330-0_6

[29] Cremonezi, B., Vieira, A., Nacif, J., & Nogueira, M. (2020). Survey on identity and access management for internet of things.. https://doi.org/10.21203/rs.3.rs-66793/v1

[30] Damiani, E., Vimercati, S., & Samarati, P. (2003). Managing multiple and dependable identities. Ieee Internet Computing, 7(6), 29-37. https://doi.org/10.1109/mic.2003.1250581

[31] Damon, F. and Coetzee, M. (2013). Towards a generic identity and access assurance model by component analysis - a conceptual review.. https://doi.org/10.1109/es.2013.6690086

[32] Daraghmi, E., Daraghmi, Y., & Yuan, S. (2019). Medchain: a design of blockchain-based system for medical records access and permissions management. Ieee Access, 7, 164595-164613. https://doi.org/10.1109/access.2019.2952942

[33] Egbuhuzor, N. S., Ajayi, A. J., Akhigbe, E. E., Agbede, O. O., Ewim, C. P.-M., & Ajiga, D. I. (2021). Cloud-based CRM systems: Revolutionizing customer engagement in the financial sector with artificial intelligence. International Journal of Science and Research Archive, 3(1), 215-234. https://doi.org/10.30574/ijsra.2021.3.1.0111

[34] Force, J. T. (2018). Risk management framework for information systems and organizations. NIST Special Publication, 800, 37.

[35] Ghaffari, F., Gilani, K., Bertin, E., & Crespi, N. (2021). Identity and access management using distributed ledger technology: a survey. International Journal of Network Management, 32(2). https://doi.org/10.1002/nem.2180

[36] Hamza, M., Abubakar, H., & Danlami, Y. (2018). Identity and access management system: a web-based approach for an enterprise. Path of Science, 4(11), 2001-2011. https://doi.org/10.22178/pos.40-1

[37] Hassan, Y. G., Collins, A., Babatunde, G. O., Alabi, A. A., & Mustapha, S. D. (2021). AI-driven intrusion detection and threat modeling to prevent unauthorized access in smart manufacturing networks. Artificial intelligence (AI), 16.

[38] Hoffmann, J., Weber, I., & Governatori, G. (2009). On compliance checking for clausal constraints in annotated process models. Information Systems Frontiers, 14(2), 155-177. https://doi.org/10.1007/s10796-009-9179-7

[39] Huang, J., Nicol, D., Bobba, R., & Huh, J. (2012). A framework integrating attribute-based policies into role-based access control.. https://doi.org/10.1145/2295136.2295170

[40] Ibitoye, B. A., AbdulWahab, R., & Mustapha, S. D. (2017): Estimation of Drivers’ Critical Gap Acceptance and Follow-up Time at Four–Legged Unsignalized Intersection.

[41] Indu, I., Anand, P., & Bhaskar, V. (2018). Identity and access management in cloud environment: mechanisms and challenges. Engineering Science and Technology an International Journal, 21(4), 574-588. https://doi.org/10.1016/j.jestch.2018.05.010

[42] Isa, A. M., Sharif, S. M., Ali, R. M., & Nordin, N. M. (2019). Managing evidence of public accountability: An information governance perspective. International Journal of Innovation, Creativity and Change, 10(7), 142-153.

[43] Jurkonis, L. and Petrusauskaitė, D. (2014). Effects of corporate governance on management efficiency of lithuanian state-owned enterprises. Ekonomika, 93(2), 77-97. https://doi.org/10.15388/ekon.2014.2.3545

[44] Kam, H. and Katerattanakul, P. (2014). Information security in higher education: a neo-institutional perspective. Journal of Information Privacy and Security, 10(1), 28-43. https://doi.org/10.1080/15536548.2014.912482

[45] Kioskli, K., Fotis, T., & Mouratidis, H. (2021, August). The landscape of cybersecurity vulnerabilities and challenges in healthcare: Security standards and paradigm shift recommendations. In Proceedings of the 16th International Conference on Availability, Reliability and Security (pp. 1-9).

[46] Kunz, M., Puchta, A., Groll, S., Fuchs, L., & Pernul, G. (2019). Attribute quality management for dynamic identity and access management. Journal of Information Security and Applications, 44, 64-79. https://doi.org/10.1016/j.jisa.2018.11.004

[47] Kure, H. (2021). An Integrated Cybersecurity Risk Management (I-CSRM) framework for critical infrastructure protection (Doctoral dissertation, University of East London).

[48] Kure, H. I., Islam, S., & Razzaque, M. A. (2018). An integrated cyber security risk management approach for a cyber-physical system. Applied Sciences, 8(6), 898.

[49] Landoll, D. (2021). The security risk assessment handbook: A complete guide for performing security risk assessments. CRC press.

[50] Lawal, A. A., Ajonbadi, H. A., & Otokiti, B. O. (2014). Leadership and organisational performance in the Nigeria small and medium enterprises (SMEs). American Journal of Business, Economics and Management, 2(5), 121.

[51] Lawal, A. A., Ajonbadi, H. A., & Otokiti, B. O. (2014). Strategic importance of the Nigerian small and medium enterprises (SMES): Myth or reality. American Journal of Business, Economics and Management, 2(4), 94-104.

[52] Lawal, A.A., and Ajonbadi, H.A and Otokiti B.O (2014). Leadership and Organisational Performance in the Nigeria Small and Medium Enterprises (SMEs), American Journal of Business, Economics and Management, Vol. 26, Issue 5.

[53] Lesavre, L. (2020). A taxonomic approach to understanding emerging blockchain identity management systems.. https://doi.org/10.6028/nist.cswp.01142020

[54] Li, N. and Rooij, B. (2021). Law lost, compliance found: a frontline understanding of the non-linear nature of business and employee responses to law. Journal of Business Ethics, 178(3), 715-734. https://doi.org/10.1007/s10551-021-04751-1

[55] Lips, A. (2013). Reconstructing, attributing and fixating citizen identities in digital-era government. Media Culture & Society, 35(1), 61-70. https://doi.org/10.1177/0163443712464559

[56] Lips, A., Taylor, J., & Organ, J. (2009). Identity management, administrative sorting and citizenship in new modes of government. Information Communication & Society, 12(5), 715-734. https://doi.org/10.1080/13691180802549508

[57] López, H., Debois, S., Slaats, T., & Hildebrandt, T. (2020). Business process compliance using reference models of law., 378-399. https://doi.org/10.1007/978-3-030-45234-6_19

[58] Luburić, R. (2017). Strengthening the three lines of defence in terms of more efficient operational risk management in central banks. Journal of Central Banking Theory and Practice, 6(1), 29-53.

[59] Masrek, M. N., Harun, Q. N., & Zaini, M. K. (2017, February). Information security culture for Malaysian public organization: a conceptual framework. In Proceedings of INTCESS 2017 4th international conference on education and social sciences (pp. 156-166).

[60] McSweeney, K. (2018). Motivating cybersecurity compliance in critical infrastructure industries: A grounded theory study (Doctoral dissertation, Capella University).

[61] Mustapha, S. D., Ibitoye, B. A., & AbdulWahab, R. (2017). Estimation of drivers’ critical gap acceptance and follow-up time at four-legged unsignalized intersection. CARD International Journal of Science and Advanced Innovative Research, 1(1), 98–107.

[62] Mutunga, C. (2015). Hospital Governance For The Counties In Kenya,‘Ephasis On Government-Run Institutions. EPH-International Journal of Medical and Health Science, 1(3), 1-5.

[63] Nuss, M., Puchta, A., & Kunz, M. (2018). Towards blockchain-based identity and access management for internet of things in enterprises., 167-181. https://doi.org/10.1007/978-3-319-98385-1_12

[64] Odio, P. E., Kokogho, E., Olorunfemi, T. A., Nwaozomudoh, M. O., Adeniji, I. E., & Sobowale, A. (2021). Innovative financial solutions: A conceptual framework for expanding SME portfolios in Nigeria's banking sector. International Journal of Multidisciplinary Research and Growth Evaluation, 2(1), 495-507.

[65] Ofodile, O. C., Toromade, A. S., Eyo-Udo, N. L., & Adewale, T. T. (2020). Optimizing FMCG supply chain management with IoT and cloud computing integration. International Journal of Management & Entrepreneurship Research, 6(11).

[66] Ogungbenle, H. N., & Omowole, B. M. (2012). Chemical, functional and amino acid composition of periwinkle (Tympanotonus fuscatus var radula) meat. Int J Pharm Sci Rev Res, 13(2), 128-132.

[67] Ogunnowo, E., Ogu, E., Egbumokei, P., Dienagha, I., & Digitemie, W. (2021). Theoretical framework for dynamic mechanical analysis in material selection for high-performance engineering applications. Open Access Research Journal of Multidisciplinary Studies, 1(2), 117-131.

[68] Oham, C., & Ejike, O. G. (2022). The evolution of branding in the performing arts: A comprehensive conceptual analysis.

[69] Okolie, C. I., Hamza, O., Eweje, A., Collins, A., & Babatunde, G. O. (2021). Leveraging Digital Transformation and Business Analysis to Improve Healthcare Provider Portal. IRE Journals, 4(10), 253-254. https://doi.org/10.54660/IJMRGE.2021.4.10.253-254​:contentReference[oaicite:0]{index=0}.

[70] Okolie, C.I., Hamza, O., Eweje, A., Collins, A., Babatunde, G.O., & Ubamadu, B.C., 2021. Leveraging Digital Transformation and Business Analysis to Improve Healthcare Provider Portal. ICONIC RESEARCH AND ENGINEERING JOURNALS, 4(10), pp.253-257.

[71] Olufemi-Phillips, A. Q., Ofodile, O. C., Toromade, A. S., Eyo-Udo, N. L., & Adewale, T. T. (2020). Optimizing FMCG supply chain management with IoT and cloud computing integration. International Journal of Management & Entrepreneurship Research, 6(11). Fair East Publishers.

[72] Olutimehin, D. O., Falaiye, T. O., Ewim, C. P. M., & Ibeh, A. I. (2021): Developing a Framework for Digital Transformation in Retail Banking Operations.

[73] Otokiti, B. O (2017). A study of management practices and organisational performance of selected MNCs in emerging market - A Case of Nigeria. International Journal of Business and Management Invention, Vol. 6, Issue 6, 1-7.

[74] Otokiti, B. O. (2012). Mode of Entry of Multinational Corporation and their Performance in the Nigeria Market (Doctoral dissertation, Covenant University).

[75] Otokiti, B. O. (2017). Social media and business growth of women entrepreneurs in Ilorin metropolis. International Journal of Entrepreneurship, Business and Management, 1(2), 50–65.

[76] Otokiti, B. O. (2018). Business regulation and control in Nigeria. Book of Readings in Honour of Professor S. O. Otokiti, 1(2), 201–215.

[77] Otokiti, B. O., & Akorede, A. F. (2018). Advancing sustainability through change and innovation: A co-evolutionary perspective. Innovation: Taking creativity to the market. Book of Readings in Honour of Professor S. O. Otokiti, 1(1), 161–167.

[78] Otokiti, B. O., & Onalaja, A. E. (2021). The role of strategic brand positioning in driving business growth and competitive advantage. Iconic Research and Engineering Journals, 4(9), 151–168.

[79] Otokiti, B. O., Igwe, A. N., Ewim, C. P. M., & Ibeh, A. I. (2021). Developing a framework for leveraging social media as a strategic tool for growth in Nigerian women entrepreneurs. Int J Multidiscip Res Growth Eval, 2(1), 597-607

[80] Otokiti, B.O. and Akinbola O.A (2013). Effects of Lease Options on the Organizational Growth of Small and Medium Enterprise (SME’s) in Lagos State, Nigeria, Asian Journal of Business and Management Sciences, Vol.3, Issue 4.

[81] Otokiti-ILORI, B.O (2018). Business Regulation and Control in Nigeria. Book of readings in honour of Professor S.O Otokiti, 1(1),

[82] Otokiti-ILORI, B.O and Akorede. A. F (2018). Advancing Sustainability through Change and Innovation: A co-evolutionanary perspective. Innovation: taking Creativity to the Market, book of readings in honour of Professor S.O Otokiti, 1(1), 161-167.

[83] Oyedokun, O. O. (2019). Green human resource management practices and its effect on the sustainable competitive edge in the Nigerian manufacturing industry (Dangote) (Doctoral dissertation, Dublin Business School).

[84] Oyeniyi, L. D., Igwe, A. N., Ofodile, O. C., & Paul-Mikki, C. (2021). Optimizing risk management frameworks in banking: Strategies to enhance compliance and profitability amid regulatory challenges.

[85] Park, J., Sandhu, R., & Ahn, G. (2001). Role-based access control on the web. Acm Transactions on Information and System Security, 4(1), 37-71. https://doi.org/10.1145/383775.383777

[86] Puchta, A., Böhm, F., & Pernul, G. (2019). Contributing to current challenges in identity and access management with visual analytics., 221-239. https://doi.org/10.1007/978-3-030-22479-0_12

[87] Putro, B., Surendro, K., & Siregar, H. (2016). Leadership and culture of data governance for the achievement of higher education goals (Case study: Indonesia University of Education). AIP Conference Proceedings, 1708, 050002. https://doi.org/10.1063/1.4941160

[88] Ramirez, R., & Choucri, N. (2016). Improving interdisciplinary communication with standardized cyber security terminology: a literature review. IEEE Access, 4, 2216-2243.

[89] Reagin, M. J., & Gentry, M. V. (2018). Enterprise cybersecurity: Building a successful defense program. Frontiers of health services management, 35(1), 13-22.

[90] Rossing, J., Johansen, T., & Pearson, T. (2019). Tax governance: the balance between tax regulatory requirements and societal expectations. International Journal of Corporate Governance, 10(3/4), 248. https://doi.org/10.1504/ijcg.2019.103227

[91] Samarati, P. and Vimercati, S. (2001). Access control: policies, models, and mechanisms., 137-196. https://doi.org/10.1007/3-540-45608-2_3

[92] Sharma, S., & Dutta, N. (2015). Cybersecurity Vulnerability Management using Novel Artificial Intelligence and Machine Learning Techniques. Sakshi, S.(2023). Development of a Project Risk Management System based on Industry, 4.

[93] Siponen, M., Mahmood, M., & Pahnila, S. (2009). Technical opinionare employees putting your company at risk by not following information security policies?. Communications of the Acm, 52(12), 145-147. https://doi.org/10.1145/1610252.1610289

[94] Skopik, F., Settanni, G., & Fiedler, R. (2016). A problem shared is a problem halved: A survey on the dimensions of collective cyber defense through security information sharing. Computers & Security, 60, 154-176.

[95] Sobowale, A., Nwaozomudoh, M. O., Odio, P. E., Kokogho, E., Olorunfemi, T. A., & Adeniji, I. E. (2021). Developing a conceptual framework for enhancing interbank currency operation accuracy in Nigeria's banking sector. International Journal of Multidisciplinary Research and Growth Evaluation, 2(1), 481–494. ANFO Publication House.

[96] Sobowale, A., Odio, P. E., Kokogho, E., Olorunfemi, T. A., Nwaozomudoh, M. O., & Adeniji, I. E. (2021). Innovative financial solutions: A conceptual framework for expanding SME portfolios in Nigeria's banking sector. International Journal of Multidisciplinary Research and Growth Evaluation, 2(1), 495–507. ANFO Publication House.

[97] Solms, J. (2020). Integrating regulatory technology (regtech) into the digital transformation of a bank treasury. Journal of Banking Regulation, 22(2), 152-168. https://doi.org/10.1057/s41261-020-00134-0

[98] Somanathan, S. (2021). A Study on Integrated Approaches in Cybersecurity Incident Response: A Project Management Perspective. Webology (ISSN: 1735-188X), 18(5).

[99] Tisdale, S. M. (2016). Architecting a cybersecurity management framework: Navigating and traversing complexity, ambiguity, and agility. Robert Morris University.

[100] Trim, P., & Lee, Y. I. (2016). Cyber security management: a governance, risk and compliance framework. Routledge.

[101] Tula, O. A., Adekoya, O. O., Isong, D., Daudu, C. D., Adefemi, A., & Okoli, C. E. (2004). Corporate advising strategies: A comprehensive review for aligning petroleum engineering with climate goals and CSR commitments in the United States and Africa. Corporate Sustainable Management Journal, 2(1), 32-38.

[102] Wæraas, A. (2015). Putting on the velvet glove: the paradox of “soft” core values in “hard” organizations. Administration & Society, 50(1), 53-77. https://doi.org/10.1177/0095399715581471

[103] Wang, S., & Wang, H. (2019). Knowledge management for cybersecurity in business organizations: a case study. Journal of Computer Information Systems.

How to cite this paper

Oluchukwu Modesta Oluoha, Abisola Odeshina, Oluwatosin Reis, Friday Okpeke, Verlinda Attipoe; Omamode Henry Orieno "Development of a Compliance-Driven Identity Governance Model for Enhancing Enterprise Information Security" Iconic Research And Engineering Journals Volume 4 Issue 11 2021 Page 310-324
Oluchukwu Modesta Oluoha, Abisola Odeshina, Oluwatosin Reis, Friday Okpeke, Verlinda Attipoe; Omamode Henry Orieno "Development of a Compliance-Driven Identity Governance Model for Enhancing Enterprise Information Security" Iconic Research And Engineering Journals, vol. 4, no. 11, May. 2021
Oluchukwu Modesta Oluoha, Abisola Odeshina, Oluwatosin Reis, Friday Okpeke, Verlinda Attipoe; Omamode Henry Orieno (2021). Development of a Compliance-Driven Identity Governance Model for Enhancing Enterprise Information Security. Iconic Research And Engineering Journals, 4(11).
Oluchukwu Modesta Oluoha, Abisola Odeshina, Oluwatosin Reis, Friday Okpeke, Verlinda Attipoe; Omamode Henry Orieno "Development of a Compliance-Driven Identity Governance Model for Enhancing Enterprise Information Security" Iconic Research And Engineering Journals, vol. 4, no. 11, May. 2021.
@article{1702715,
      author = {Oluchukwu Modesta Oluoha, Abisola Odeshina, Oluwatosin Reis, Friday Okpeke, Verlinda Attipoe; Omamode Henry Orieno},
      title = {Development of a Compliance-Driven Identity Governance Model for Enhancing Enterprise Information Security},
      journal = {Iconic Research And Engineering Journals},
      year = {2021},
      volume = {4},
      number = {11},
      pages = {310-324},
      issn = {2456-8880},
      url = {https://www.irejournals.com/formatedpaper/1702715.pdf},
      abstract = {In the contemporary digital landscape, organizations face increasing regulatory pressures and cybersecurity threats that demand robust identity and access management (IAM) frameworks. Traditional identity governance models often fall short in dynamically aligning with evolving compliance mandates, resulting in security vulnerabilities and audit deficiencies. This study proposes the development of a Compliance-Driven Identity Governance Model (CD-IGM) aimed at enhancing enterprise information security while ensuring regulatory alignment. The model integrates compliance requirements as a foundational design principle rather than a peripheral consideration, embedding regulatory frameworks such as GDPR, HIPAA, SOX, and ISO 27001 into the identity lifecycle management process. The CD-IGM framework is designed around three core pillars: Policy-Centric Access Control, Automated Compliance Monitoring, and Risk-Based Role Engineering. Policy-Centric Access Control ensures that access decisions are tightly coupled with compliance mandates and business rules. Automated Compliance Monitoring leverages artificial intelligence and machine learning to continuously audit user activities, detect anomalies, and generate compliance reports in real time. Risk-Based Role Engineering utilizes behavior analytics and contextual data to dynamically assign roles and permissions based on assessed risk levels. A prototype of the model was implemented and evaluated in a simulated enterprise environment to measure its effectiveness in improving security posture and compliance readiness. Results demonstrated a 35% reduction in unauthorized access incidents and a 50% improvement in audit response times compared to traditional models. Furthermore, stakeholders reported enhanced visibility and control over identity-related risks and improved confidence in compliance audits. The proposed model offers a scalable, proactive, and adaptive approach to identity governance that aligns organizational security objectives with compliance requirements. It represents a paradigm shift from reactive compliance fulfillment to strategic compliance integration, thereby fostering a culture of security by design. The model?s modular architecture also supports integration with existing IAM systems, cloud platforms, and emerging technologies such as Zero Trust and blockchain-based identity systems. This research contributes to the body of knowledge in information security governance by bridging the gap between compliance and identity management, offering practical and theoretical implications for enterprises, policymakers, and cybersecurity professionals seeking to enhance data protection and regulatory conformance.},
      keywords = {Identity Governance, Compliance, Information Security, Access Management, Risk-Based Role Engineering, Audit, Policy-Centric Control, Artificial Intelligence, Cybersecurity, Regulatory Frameworks.},
      month = {May},
  }