Bank of Ghana Cyber and Information Security Directive
Comprehensive 131-page directive mandating cybersecurity requirements for all banks, specialised deposit-taking institutions, payment systems, and fintech companies in Ghana. 20 sections covering governance, risk management, audit, asset management, cyber defence, incident response, access control, electronic banking, cyber exercises, external connections, cloud services, physical security, HR management, contractual requirements, ISMS/ISO 27001 certification, business continuity, compliance, and secure development. Requires mandatory ISO 27001 certification.
| Clause | Title | SP 800-53 Controls |
|---|---|---|
| CISD-BCM | Business Continuity Management | |
| CISD-COMP | Compliance, Reporting and Regulatory Obligations | |
| CISD-I | Overview, Scope and Applicability | |
| CISD-II | Governance | |
| CISD-III | Risk Management | |
| CISD-ISMS | ISMS and ISO 27001 Certification | |
| CISD-IV | Internal Audit | |
| CISD-IX | Electronic Banking Services | |
| CISD-SDLC | System Acquisition, Development and Maintenance | |
| CISD-V | Asset Management | |
| CISD-VI | Cyber Defence | |
| CISD-VII | Cyber Response | |
| CISD-VIII | Employee Access to ICT Systems | |
| CISD-X | Cyber Exercises | |
| CISD-XI | External Connections | |
| CISD-XII | Cloud Services | |
| CISD-XIII | Banks with International Affiliation | |
| CISD-XIV | Physical Security | |
| CISD-XV | Human Resource Management | |
| CISD-XVI | Contractual Aspects |