Article

Cybersecurity Governance in the Ministry of Communications and Information Technology in Yemen: Empirical Evidence and a Context-Sensitive Framework

Public sector institutions in developing countries increasingly adopt cybersecurity governance frameworks, yet a persistent gap remains between formal adoption and strategic cybersecurity effectiveness. This study investigates this gap through a case study of the Ministry of Communications and Information Technology in Yemen, guided by ISO/IEC 27014. Using a descriptive-analytical approach, data were collected from 30 cybersecurity decision-makers across six governance dimensions and analyzed using PLS-SEM. The findings reveal a cybersecurity governance maturity gap, as none of the governance dimensions showed a significant impact on strategic effectiveness despite moderate to high implementation levels. Risk assessment and management exhibited a negative, non-significant relationship, indicating symbolic practices. The study proposes a context-sensitive framework to enhance strategic alignment and effectiveness. The findings offer practical guidance for policymakers in developing countries seeking to transition from compliance-oriented cybersecurity governance toward strategically integrated governance frameworks.

Riam Abdulbaset AL-Hakimi Corresponding

  • Department of Information Technology, Faculty of Computer Science and IT, Sana’a University, Sana’a, Yemen

Nagi Ali AL-Shaibany

  • Department of Information Technology, Faculty of Computer Science and IT, Sana’a University, Sana’a, Yemen
Download data is not yet available.

Metrics

0
Views
0
Downloads
0
Citations

How to Cite

Cybersecurity Governance in the Ministry of Communications and Information Technology in Yemen: Empirical Evidence and a Context-Sensitive Framework. (2026). Sana’a University Journal of Applied Sciences and Technology, 4(7), 2306-2317. https://doi.org/10.59628/jast.v4i7.2763