Ghana Cybersecurity Act
Evidence request list. 12 controls, 12 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Ghana CSA: Child Online Protection, Awareness, Education and International Cooperation
Ghana CSA Child Online Protection + Awareness + International Cooperation (Parts IX-X of Act 1038). CHILD ONLINE PROTECTION (Sec.131-145): (a) CRIMINAL OFFENCES against children online - CSAM (child sexual abuse material) production + distribution + possession + grooming + cyberbullying + sextortion + commercial sexual exploitation; (b) REPORTING OBLIGATIONS - online service providers + hosting providers + cybersecurity professionals must report suspected child-online-offences to CSA + Ghana Police Service + Department of Social Welfare; (c) BLOCKING + REMOVAL of CSAM + takedown procedures + working with Internet Watch Foundation (IWF) + INHOPE + Interpol Crimes Against Children Working Group; (d) PARENTAL CONTROL + age verification + child-safe internet initiatives + education programs in schools; (e) COOPERATION with the Children's Department + Cyber Safety Foundation + civil society.
- Child online protection compliance + reporting
- Awareness campaigns + workforce development
- International cooperation + 24/7 contact
- MLA + capacity building participation
- Child online protection gaps + reporting failures
- Awareness + workforce development thin
- International cooperation absent
Ghana CSA: Critical Information Infrastructure (CII) Designation, Plan, Audit and Risk Assessment
Ghana CSA Critical Information Infrastructure (CII) regime (Part III of Act 1038). CII DESIGNATION: CSA Ghana designates CII owners across 13 SECTORS: (1) BANKING + FINANCE; (2) ENERGY (electricity + oil + gas); (3) WATER; (4) TELECOMMUNICATIONS; (5) TRANSPORT (aviation + maritime + rail + road); (6) HEALTH SERVICES; (7) GOVERNMENT SERVICES (including national security + military communications); (8) FOOD + AGRICULTURE supply chains; (9) EMERGENCY SERVICES; (10) MEDIA + INFORMATION services; (11) EDUCATION; (12) JUDICIARY + LEGAL SERVICES; (13) OTHER systems designated by CSA based on national-security + economic + societal significance. CII REGISTRATION + NOTIFICATION (Sec.20-21): designated entities must register with CSA + notify changes + provide ownership + control + technical contacts + system descriptions + dependencies. CII CYBERSECURITY PLAN (Sec.22): mandatory written plan cove
- CII registration + notification
- Cybersecurity Plan document + reviews
- Risk Assessment records
- Annual audit reports + CSA submission
- CII designation status unclear
- Plan not maintained
- Risk Assessment skipped
- Audit not conducted
Ghana CSA: Cybercrime Offences, Lawful Access and Preservation
Ghana CSA Cybercrime + Lawful Access + Preservation (Parts VII + VIII of Act 1038). CYBERCRIME OFFENCES (Sec.80-104): coordinated with Budapest Cybercrime Convention (which Ghana acceded to 2018) + Malabo Convention; criminalises: (a) UNAUTHORISED ACCESS to computer systems + data + bypass-of-access-controls; (b) ILLEGAL INTERCEPTION of transmissions + private communications; (c) DATA INTERFERENCE - damaging + altering + deleting + suppressing data without authorisation; (d) SYSTEM INTERFERENCE - serious hindering of system operation; (e) MISUSE OF DEVICES - production + sale + procurement for use + import + distribution + making available of devices/programs designed for offences + computer passwords + access codes; (f) COMPUTER-RELATED FORGERY + FRAUD; (g) CONTENT-RELATED OFFENCES - child sexual abuse material + cyberbullying + hate speech + terrorist content + revenge porn + sextortio
- Compliance with lawful access + production orders
- Preservation procedure + 7-30 day response
- International cooperation procedures
- Lawful access cooperation refused or slow
- Preservation orders not responded
- International cooperation inconsistent
Ghana CSA: Cybersecurity Incident Reporting (24-Hour to CSA) and National CERT-GH
Ghana CSA Incident Reporting + National CERT-GH (Part IV of Act 1038). 24-HOUR INCIDENT REPORTING REQUIREMENT (Sec.41): CII owners must report cybersecurity incidents to CSA Ghana within 24 HOURS of incident DISCOVERY; the threshold is incidents affecting CII confidentiality + integrity + availability + with significant risk of harm to public safety + national security + economic stability + public health + critical operations. INITIAL REPORT contents: incident type + scope + affected systems + initial impact assessment + immediate response actions; FOLLOW-UP REPORTS at significant milestones + final report within 30 days of incident closure including root cause + remediation + lessons learned. INCIDENT TYPES requiring reporting: ransomware + data breach + DDoS + unauthorized access + malicious code + insider threats + supply chain compromise + nation-state activity + critical-infrastruc
- Incident reporting procedure + 24-hour SLA
- CERT-GH contact + cooperation records
- Threat-intelligence subscriptions + exercises
- 24-hour SLA missed
- Follow-up reports incomplete
- CERT-GH engagement absent
- Exercises not participated
Ghana CSA: Cybersecurity Service Provider Licensing and Professional Accreditation
Ghana CSA Service Provider Licensing + Professional Accreditation (Parts V + VI of Act 1038). CYBERSECURITY SERVICE PROVIDER LICENSING (Sec.49-58): MANDATORY LICENSING for entities providing cybersecurity services in Ghana including: (a) MANAGED SECURITY SERVICE PROVIDERS (MSSPs); (b) PENETRATION TESTING + vulnerability assessment + red-teaming firms; (c) CYBERSECURITY CONSULTANCY; (d) FORENSIC INVESTIGATION; (e) THREAT INTELLIGENCE services; (f) INCIDENT RESPONSE + DFIR services; (g) CYBERSECURITY TRAINING + CERTIFICATION. LICENCE REQUIREMENTS: company registration + competency demonstration + insurance + ethics + Code of Conduct + financial standing + responsible person designation; licences typically valid 3 YEARS + renewable. CYBERSECURITY PROFESSIONAL ACCREDITATION (Sec.59-68): MANDATORY ACCREDITATION for individuals practising as cybersecurity professionals in Ghana including penet
- Licensed MSSP + contracted-firm verification
- Professional accreditation records + CPD
- Cross-border licensing arrangements
- Unlicensed MSSP engagement (CRIMINAL OFFENCE)
- Professional accreditation lapsed
- Cross-border arrangements not documented
Ghana CSA: Scope, Cyber Security Authority (CSA Ghana) and Definitions
Ghana Cybersecurity Act 2020 (Act 1038) Scope + CSA Ghana + Definitions. PURPOSE: regulate cybersecurity activities in Ghana + promote cybersecurity development + protect critical information infrastructure + prevent + detect + respond to cybersecurity incidents + cybercrime + protect children online. SCOPE: applies to (a) all persons in Ghana; (b) Ghanaian nationals + persons habitually resident in Ghana wherever located; (c) acts committed outside Ghana where the act has an effect in Ghana OR where the act is committed by a Ghanaian national; (d) cybersecurity activities including service provision + use + research. CYBER SECURITY AUTHORITY (CSA Ghana, Part II): an independent statutory body established under the Ministry of Communications + Digitalisation + with: (a) DIRECTOR-GENERAL appointed by the President; (b) GOVERNING BOARD with public + private + technical expertise; (c) FUNCT
- Ghana-applicability assessment + cross-border
- CSA-contact-point + cooperation procedure
- Cybersecurity Fund levy compliance if applicable
- Scope misunderstood
- CSA engagement reactive
- Cybersecurity Fund levies missed
Ghana CSA: Sectoral Coordination, Budapest Convention, Malabo Convention and 2024-2025 Status
Ghana CSA international framework + 2024-2025 status. BUDAPEST CYBERCRIME CONVENTION (Council of Europe Convention No. 185, 2001 + 2nd Additional Protocol 2022): Ghana acceded 2018 + actively participates in Cybercrime Convention Committee (T-CY) + 24/7 contact point + capacity-building programs; Ghana hosted regional Budapest Convention workshops + serves as African champion of accession. MALABO CONVENTION (African Union Convention on Cyber Security and Personal Data Protection 2014): Ghana SIGNATORY + has not yet RATIFIED but referenced in domestic law + cybersecurity strategy; ratification process ongoing; the Malabo Convention entered into force 2023 with required 15 ratifications. AFRICACERT (African Computer Emergency Response Teams Forum) + AfricaCERT-Members: Ghana CERT-GH active member; coordinates incident response + threat intelligence + cyber-exercises with peer African CERTs
- International cooperation engagement
- Cybersecurity Strategy 2024-2028 alignment
- Sectoral priorities tracking
- Workforce development participation
- International engagement absent
- Strategy 2024-2028 not aligned
- Workforce + capacity gaps
Ghana CSA coordination with adjacent Ghana legal frameworks. GHANA DATA PROTECTION ACT 2012 (Act 843) - separately tracked in corpus: established Data Protection Commission Ghana; covers personal data processing in Ghana; cybersecurity incidents involving personal data trigger BOTH Ghana DPA breach notification (to DPC) AND Ghana CSA 24-hour incident reporting (to CSA Ghana); 2024-2025 Ghana DPA review may align further with GDPR + EU adequacy aspirations + Ghana CSA. ELECTRONIC TRANSACTIONS ACT 2008 (Act 772): foundational e-commerce + electronic-evidence + electronic-records + electronic-signatures regime + complemented by Ghana CSA cybercrime provisions. CRIMINAL OFFENCES ACT 1960 (Act 29): general criminal law + computer-related offences + cybercrime provisions integrated with Ghana CSA Part VII. BANKING ACT 2004 + BANK OF GHANA DIRECTIVES: financial-sector cybersecurity + BoG Cyber
- Dual-reporting procedure DPA + CSA
- Sectoral compliance integration
- Civil society + judiciary engagement
- Dual reporting overlooked
- Sectoral compliance siloed
- Civil society engagement weak
Ghana CSA crosswalk to international standards. NIST CSF 2.0 (February 2024): mapping GOVERN (CSA Ghana engagement + Cybersecurity Plan) + IDENTIFY (CII designation + asset + risk + supplier) + PROTECT (access controls + segmentation + encryption + training) + DETECT (logging + monitoring + threat intelligence) + RESPOND (24-hour CSA notification + IR plan + CERT-GH coordination) + RECOVER (BCP + DRP). NIST SP 800-53 + 800-37 RMF: detailed control catalog + risk management framework + supports Ghana CSA Cybersecurity Plan content. ISO/IEC 27001:2022 + ISO/IEC 27002:2022 + ISO/IEC 27005:2022: ISMS + risk management structure aligned with Ghana CSA Cybersecurity Plan + annual audit; many Ghana CII organisations pursue ISO 27001 certification for international acceptance. ISO/IEC 22301:2019 BUSINESS CONTINUITY: aligns with Ghana CSA business continuity + disaster recovery requirements. ISO
- Crosswalk document
- International standards adoption
- Sector standards compliance
- Crosswalks not maintained
- ISO/NIST alignment ad-hoc
- Sector standards inconsistent
Ghana CSA compliance program implementation roadmap. ORGANIZATIONAL ROLES: (a) CHIEF INFORMATION SECURITY OFFICER (CISO) - CII Cybersecurity Plan ownership + CSA Ghana liaison; (b) CSA-CONTACT POINT for incident reporting + audit + cooperation; (c) NATIONAL CERT-GH COORDINATOR - threat intelligence + exercises + incident response coordination; (d) LICENCE/ACCREDITATION OWNER - MSSP licensing + cybersecurity professional accreditation tracking; (e) CHILD ONLINE PROTECTION LEAD - reporting + cooperation with Ghana Police + Department of Social Welfare; (f) LAWFUL ACCESS COMPLIANCE LEAD - preservation + production orders + Budapest cooperation; (g) SECTORAL LIAISON - DPC + NCA + BoG + NITA + sector regulators. OPERATIONAL CONTROLS: (a) CII designation + registration; (b) Cybersecurity Plan + annual review; (c) annual independent audit; (d) 24-hour incident reporting procedure + CSA online p
- Role inventory + RACI
- Operational controls + tooling investment
- Metrics + management review
- Sectoral + international engagement
- Roles undefined
- Tooling fragmented
- Metrics not tracked
- Sectoral + international engagement absent
Ghana CSA sectoral coordination. DATA PROTECTION COMMISSION GHANA (DPC, established by Data Protection Act 2012 Act 843): personal data + privacy + GDPR-adjacent regime; cybersecurity-incident-personal-data overlap coordination; the 2024-2025 review of Ghana DPA 2012 amendments may further align with the Ghana CSA cybersecurity regime. NATIONAL COMMUNICATIONS AUTHORITY (NCA): telecommunications regulator overseeing telecommunications operators + ISPs + ICT sector; cybersecurity provisions in NCA Code of Practice + Service Provider Licensing align with Ghana CSA. BANK OF GHANA (BoG): financial-sector cybersecurity directives including 2018 Cyber Risk Management Directive + 2021 Cybersecurity & Information Technology Risk Management Directive + 2024 amendments; coordinates with CSA on banking-sector CII. GHANA REVENUE AUTHORITY (GRA): tax-administration cybersecurity + payment-systems cybe
- DPC + NCA + BoG engagement records
- Sectoral compliance program
- Multi-regulator coordination playbook
- Multi-regulator coordination ad-hoc
- DPC + CSA overlap unaddressed
- Sectoral regulators not engaged
Ghana CSA implementation status + Cybersecurity Strategy 2024-2028 + 2024-2025 pipeline. STATUS: Act 1038 in force since 6 January 2021; CSA Ghana operational with growing capacity; first CII designations 2021-2023 across all 13 sectors; first MSSP licensing rounds + cybersecurity professional accreditation underway 2022-2024; 24-hour incident reporting system operational; CERT-GH active. CYBERSECURITY STRATEGY 2024-2028: Ghana's National Cybersecurity Strategy (NCS) refresh covering: (a) STRATEGIC OBJECTIVES - secure + resilient cyberspace + trusted online environment + cybersecurity workforce + secure digital transformation; (b) FIVE PILLARS - Governance + Cooperation + Capacity Building + Critical Infrastructure Protection + Resilience; (c) KEY INITIATIVES - critical infrastructure resilience + workforce development + child online safety + cybercrime response + international cooperati
- Strategy 2024-2028 implementation
- Priority area readiness
- Exercise participation
- International cooperation
- Strategy alignment ad-hoc
- Priority areas unaddressed
- Exercise non-participation
- International engagement low
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Ghana Cybersecurity Act framework page.