← Frameworks / Financial Regulation

Bank of Ghana Cyber and Information Security Directive

Comprehensive 131-page directive mandating cybersecurity requirements for all banks, specialised deposit-taking institutions, payment systems, and fintech companies in Ghana. 20 sections covering governance, risk management, audit, asset management, cyber defence, incident response, access control, electronic banking, cyber exercises, external connections, cloud services, physical security, HR management, contractual requirements, ISMS/ISO 27001 certification, business continuity, compliance, and secure development. Requires mandatory ISO 27001 certification.

Clause Title SP 800-53 Controls
CISD-BCM Business Continuity Management
CISD-COMP Compliance, Reporting and Regulatory Obligations
CISD-I Overview, Scope and Applicability
CISD-II Governance
CISD-III Risk Management
CISD-ISMS ISMS and ISO 27001 Certification
CISD-IV Internal Audit
CISD-IX Electronic Banking Services
CISD-SDLC System Acquisition, Development and Maintenance
CISD-V Asset Management
CISD-VI Cyber Defence
CISD-VII Cyber Response
CISD-VIII Employee Access to ICT Systems
CISD-X Cyber Exercises
CISD-XI External Connections
CISD-XII Cloud Services
CISD-XIII Banks with International Affiliation
CISD-XIV Physical Security
CISD-XV Human Resource Management
CISD-XVI Contractual Aspects