Skip to content

Evidence request lists

Ghana Cybersecurity Act

Evidence request list. 12 controls, 12 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Ghana CSA: Child Online Protection, Awareness, Education and International Cooperation

GhCSA-Child-OnlineProtection-Awareness-Intl-Coop
Child Online Protection, Awareness, Education and International Cooperation

Ghana CSA Child Online Protection + Awareness + International Cooperation (Parts IX-X of Act 1038). CHILD ONLINE PROTECTION (Sec.131-145): (a) CRIMINAL OFFENCES against children online - CSAM (child sexual abuse material) production + distribution + possession + grooming + cyberbullying + sextortion + commercial sexual exploitation; (b) REPORTING OBLIGATIONS - online service providers + hosting providers + cybersecurity professionals must report suspected child-online-offences to CSA + Ghana Police Service + Department of Social Welfare; (c) BLOCKING + REMOVAL of CSAM + takedown procedures + working with Internet Watch Foundation (IWF) + INHOPE + Interpol Crimes Against Children Working Group; (d) PARENTAL CONTROL + age verification + child-safe internet initiatives + education programs in schools; (e) COOPERATION with the Children's Department + Cyber Safety Foundation + civil society.

Artefacts an auditor will ask for
  • Child online protection compliance + reporting
  • Awareness campaigns + workforce development
  • International cooperation + 24/7 contact
  • MLA + capacity building participation
Where this commonly fails
  • Child online protection gaps + reporting failures
  • Awareness + workforce development thin
  • International cooperation absent

Ghana CSA: Critical Information Infrastructure (CII) Designation, Plan, Audit and Risk Assessment

GhCSA-CII-Designation-Plan-Audit-Risk
CII Designation, Registration, Cybersecurity Plan, Audit and Risk Assessment

Ghana CSA Critical Information Infrastructure (CII) regime (Part III of Act 1038). CII DESIGNATION: CSA Ghana designates CII owners across 13 SECTORS: (1) BANKING + FINANCE; (2) ENERGY (electricity + oil + gas); (3) WATER; (4) TELECOMMUNICATIONS; (5) TRANSPORT (aviation + maritime + rail + road); (6) HEALTH SERVICES; (7) GOVERNMENT SERVICES (including national security + military communications); (8) FOOD + AGRICULTURE supply chains; (9) EMERGENCY SERVICES; (10) MEDIA + INFORMATION services; (11) EDUCATION; (12) JUDICIARY + LEGAL SERVICES; (13) OTHER systems designated by CSA based on national-security + economic + societal significance. CII REGISTRATION + NOTIFICATION (Sec.20-21): designated entities must register with CSA + notify changes + provide ownership + control + technical contacts + system descriptions + dependencies. CII CYBERSECURITY PLAN (Sec.22): mandatory written plan cove

Artefacts an auditor will ask for
  • CII registration + notification
  • Cybersecurity Plan document + reviews
  • Risk Assessment records
  • Annual audit reports + CSA submission
Where this commonly fails
  • CII designation status unclear
  • Plan not maintained
  • Risk Assessment skipped
  • Audit not conducted

Ghana CSA: Cybercrime Offences, Lawful Access and Preservation

GhCSA-Cybercrime-Lawful-Access-Preservation
Cybercrime Offences, Lawful Access and Electronic Evidence Preservation

Ghana CSA Cybercrime + Lawful Access + Preservation (Parts VII + VIII of Act 1038). CYBERCRIME OFFENCES (Sec.80-104): coordinated with Budapest Cybercrime Convention (which Ghana acceded to 2018) + Malabo Convention; criminalises: (a) UNAUTHORISED ACCESS to computer systems + data + bypass-of-access-controls; (b) ILLEGAL INTERCEPTION of transmissions + private communications; (c) DATA INTERFERENCE - damaging + altering + deleting + suppressing data without authorisation; (d) SYSTEM INTERFERENCE - serious hindering of system operation; (e) MISUSE OF DEVICES - production + sale + procurement for use + import + distribution + making available of devices/programs designed for offences + computer passwords + access codes; (f) COMPUTER-RELATED FORGERY + FRAUD; (g) CONTENT-RELATED OFFENCES - child sexual abuse material + cyberbullying + hate speech + terrorist content + revenge porn + sextortio

Artefacts an auditor will ask for
  • Compliance with lawful access + production orders
  • Preservation procedure + 7-30 day response
  • International cooperation procedures
Where this commonly fails
  • Lawful access cooperation refused or slow
  • Preservation orders not responded
  • International cooperation inconsistent

Ghana CSA: Cybersecurity Incident Reporting (24-Hour to CSA) and National CERT-GH

GhCSA-Incident-Reporting-CERT-GH
Cybersecurity Incident Reporting (24-Hour to CSA) and National CERT-GH Engagement

Ghana CSA Incident Reporting + National CERT-GH (Part IV of Act 1038). 24-HOUR INCIDENT REPORTING REQUIREMENT (Sec.41): CII owners must report cybersecurity incidents to CSA Ghana within 24 HOURS of incident DISCOVERY; the threshold is incidents affecting CII confidentiality + integrity + availability + with significant risk of harm to public safety + national security + economic stability + public health + critical operations. INITIAL REPORT contents: incident type + scope + affected systems + initial impact assessment + immediate response actions; FOLLOW-UP REPORTS at significant milestones + final report within 30 days of incident closure including root cause + remediation + lessons learned. INCIDENT TYPES requiring reporting: ransomware + data breach + DDoS + unauthorized access + malicious code + insider threats + supply chain compromise + nation-state activity + critical-infrastruc

Artefacts an auditor will ask for
  • Incident reporting procedure + 24-hour SLA
  • CERT-GH contact + cooperation records
  • Threat-intelligence subscriptions + exercises
Where this commonly fails
  • 24-hour SLA missed
  • Follow-up reports incomplete
  • CERT-GH engagement absent
  • Exercises not participated

Ghana CSA: Cybersecurity Service Provider Licensing and Professional Accreditation

GhCSA-Service-Provider-Licensing-Professional
Cybersecurity Service Provider Licensing and Professional Accreditation

Ghana CSA Service Provider Licensing + Professional Accreditation (Parts V + VI of Act 1038). CYBERSECURITY SERVICE PROVIDER LICENSING (Sec.49-58): MANDATORY LICENSING for entities providing cybersecurity services in Ghana including: (a) MANAGED SECURITY SERVICE PROVIDERS (MSSPs); (b) PENETRATION TESTING + vulnerability assessment + red-teaming firms; (c) CYBERSECURITY CONSULTANCY; (d) FORENSIC INVESTIGATION; (e) THREAT INTELLIGENCE services; (f) INCIDENT RESPONSE + DFIR services; (g) CYBERSECURITY TRAINING + CERTIFICATION. LICENCE REQUIREMENTS: company registration + competency demonstration + insurance + ethics + Code of Conduct + financial standing + responsible person designation; licences typically valid 3 YEARS + renewable. CYBERSECURITY PROFESSIONAL ACCREDITATION (Sec.59-68): MANDATORY ACCREDITATION for individuals practising as cybersecurity professionals in Ghana including penet

Artefacts an auditor will ask for
  • Licensed MSSP + contracted-firm verification
  • Professional accreditation records + CPD
  • Cross-border licensing arrangements
Where this commonly fails
  • Unlicensed MSSP engagement (CRIMINAL OFFENCE)
  • Professional accreditation lapsed
  • Cross-border arrangements not documented

Ghana CSA: Scope, Cyber Security Authority (CSA Ghana) and Definitions

GhCSA-Scope-CSAGhana-Defs
Scope, Cyber Security Authority (CSA Ghana) and Key Definitions

Ghana Cybersecurity Act 2020 (Act 1038) Scope + CSA Ghana + Definitions. PURPOSE: regulate cybersecurity activities in Ghana + promote cybersecurity development + protect critical information infrastructure + prevent + detect + respond to cybersecurity incidents + cybercrime + protect children online. SCOPE: applies to (a) all persons in Ghana; (b) Ghanaian nationals + persons habitually resident in Ghana wherever located; (c) acts committed outside Ghana where the act has an effect in Ghana OR where the act is committed by a Ghanaian national; (d) cybersecurity activities including service provision + use + research. CYBER SECURITY AUTHORITY (CSA Ghana, Part II): an independent statutory body established under the Ministry of Communications + Digitalisation + with: (a) DIRECTOR-GENERAL appointed by the President; (b) GOVERNING BOARD with public + private + technical expertise; (c) FUNCT

Artefacts an auditor will ask for
  • Ghana-applicability assessment + cross-border
  • CSA-contact-point + cooperation procedure
  • Cybersecurity Fund levy compliance if applicable
Where this commonly fails
  • Scope misunderstood
  • CSA engagement reactive
  • Cybersecurity Fund levies missed

Ghana CSA: Sectoral Coordination, Budapest Convention, Malabo Convention and 2024-2025 Status

GhCSA-Budapest-Malabo-AfricaCERT-2024-2025
Budapest Convention, Malabo Convention, AfricaCERT and 2024-2025 Status

Ghana CSA international framework + 2024-2025 status. BUDAPEST CYBERCRIME CONVENTION (Council of Europe Convention No. 185, 2001 + 2nd Additional Protocol 2022): Ghana acceded 2018 + actively participates in Cybercrime Convention Committee (T-CY) + 24/7 contact point + capacity-building programs; Ghana hosted regional Budapest Convention workshops + serves as African champion of accession. MALABO CONVENTION (African Union Convention on Cyber Security and Personal Data Protection 2014): Ghana SIGNATORY + has not yet RATIFIED but referenced in domestic law + cybersecurity strategy; ratification process ongoing; the Malabo Convention entered into force 2023 with required 15 ratifications. AFRICACERT (African Computer Emergency Response Teams Forum) + AfricaCERT-Members: Ghana CERT-GH active member; coordinates incident response + threat intelligence + cyber-exercises with peer African CERTs

Artefacts an auditor will ask for
  • International cooperation engagement
  • Cybersecurity Strategy 2024-2028 alignment
  • Sectoral priorities tracking
  • Workforce development participation
Where this commonly fails
  • International engagement absent
  • Strategy 2024-2028 not aligned
  • Workforce + capacity gaps
GhCSA-Coord-Ghana-DPA-Cybercrime-Sectoral
Coordination with Ghana DPA 2012, Cybercrime Definitions and Cross-Sectoral Frameworks

Ghana CSA coordination with adjacent Ghana legal frameworks. GHANA DATA PROTECTION ACT 2012 (Act 843) - separately tracked in corpus: established Data Protection Commission Ghana; covers personal data processing in Ghana; cybersecurity incidents involving personal data trigger BOTH Ghana DPA breach notification (to DPC) AND Ghana CSA 24-hour incident reporting (to CSA Ghana); 2024-2025 Ghana DPA review may align further with GDPR + EU adequacy aspirations + Ghana CSA. ELECTRONIC TRANSACTIONS ACT 2008 (Act 772): foundational e-commerce + electronic-evidence + electronic-records + electronic-signatures regime + complemented by Ghana CSA cybercrime provisions. CRIMINAL OFFENCES ACT 1960 (Act 29): general criminal law + computer-related offences + cybercrime provisions integrated with Ghana CSA Part VII. BANKING ACT 2004 + BANK OF GHANA DIRECTIVES: financial-sector cybersecurity + BoG Cyber

Artefacts an auditor will ask for
  • Dual-reporting procedure DPA + CSA
  • Sectoral compliance integration
  • Civil society + judiciary engagement
Where this commonly fails
  • Dual reporting overlooked
  • Sectoral compliance siloed
  • Civil society engagement weak
GhCSA-Crosswalk-NIST-ISO-27001-Sectoral
Crosswalk to NIST CSF 2.0, ISO 27001, ISO 22301 and Sector Standards

Ghana CSA crosswalk to international standards. NIST CSF 2.0 (February 2024): mapping GOVERN (CSA Ghana engagement + Cybersecurity Plan) + IDENTIFY (CII designation + asset + risk + supplier) + PROTECT (access controls + segmentation + encryption + training) + DETECT (logging + monitoring + threat intelligence) + RESPOND (24-hour CSA notification + IR plan + CERT-GH coordination) + RECOVER (BCP + DRP). NIST SP 800-53 + 800-37 RMF: detailed control catalog + risk management framework + supports Ghana CSA Cybersecurity Plan content. ISO/IEC 27001:2022 + ISO/IEC 27002:2022 + ISO/IEC 27005:2022: ISMS + risk management structure aligned with Ghana CSA Cybersecurity Plan + annual audit; many Ghana CII organisations pursue ISO 27001 certification for international acceptance. ISO/IEC 22301:2019 BUSINESS CONTINUITY: aligns with Ghana CSA business continuity + disaster recovery requirements. ISO

Artefacts an auditor will ask for
  • Crosswalk document
  • International standards adoption
  • Sector standards compliance
Where this commonly fails
  • Crosswalks not maintained
  • ISO/NIST alignment ad-hoc
  • Sector standards inconsistent
GhCSA-Implementation-Roadmap
Implementation Roadmap - Organizational Roles, Tooling and Metrics

Ghana CSA compliance program implementation roadmap. ORGANIZATIONAL ROLES: (a) CHIEF INFORMATION SECURITY OFFICER (CISO) - CII Cybersecurity Plan ownership + CSA Ghana liaison; (b) CSA-CONTACT POINT for incident reporting + audit + cooperation; (c) NATIONAL CERT-GH COORDINATOR - threat intelligence + exercises + incident response coordination; (d) LICENCE/ACCREDITATION OWNER - MSSP licensing + cybersecurity professional accreditation tracking; (e) CHILD ONLINE PROTECTION LEAD - reporting + cooperation with Ghana Police + Department of Social Welfare; (f) LAWFUL ACCESS COMPLIANCE LEAD - preservation + production orders + Budapest cooperation; (g) SECTORAL LIAISON - DPC + NCA + BoG + NITA + sector regulators. OPERATIONAL CONTROLS: (a) CII designation + registration; (b) Cybersecurity Plan + annual review; (c) annual independent audit; (d) 24-hour incident reporting procedure + CSA online p

Artefacts an auditor will ask for
  • Role inventory + RACI
  • Operational controls + tooling investment
  • Metrics + management review
  • Sectoral + international engagement
Where this commonly fails
  • Roles undefined
  • Tooling fragmented
  • Metrics not tracked
  • Sectoral + international engagement absent
GhCSA-Sectoral-Coordination-DPC-NCA-BoG
Sectoral Coordination - Data Protection Commission, NCA, Bank of Ghana and Other Regulators

Ghana CSA sectoral coordination. DATA PROTECTION COMMISSION GHANA (DPC, established by Data Protection Act 2012 Act 843): personal data + privacy + GDPR-adjacent regime; cybersecurity-incident-personal-data overlap coordination; the 2024-2025 review of Ghana DPA 2012 amendments may further align with the Ghana CSA cybersecurity regime. NATIONAL COMMUNICATIONS AUTHORITY (NCA): telecommunications regulator overseeing telecommunications operators + ISPs + ICT sector; cybersecurity provisions in NCA Code of Practice + Service Provider Licensing align with Ghana CSA. BANK OF GHANA (BoG): financial-sector cybersecurity directives including 2018 Cyber Risk Management Directive + 2021 Cybersecurity & Information Technology Risk Management Directive + 2024 amendments; coordinates with CSA on banking-sector CII. GHANA REVENUE AUTHORITY (GRA): tax-administration cybersecurity + payment-systems cybe

Artefacts an auditor will ask for
  • DPC + NCA + BoG engagement records
  • Sectoral compliance program
  • Multi-regulator coordination playbook
Where this commonly fails
  • Multi-regulator coordination ad-hoc
  • DPC + CSA overlap unaddressed
  • Sectoral regulators not engaged
GhCSA-Status-2024-2025-Strategy-AI
Implementation Status, Cybersecurity Strategy 2024-2028 and 2024-2025 Pipeline

Ghana CSA implementation status + Cybersecurity Strategy 2024-2028 + 2024-2025 pipeline. STATUS: Act 1038 in force since 6 January 2021; CSA Ghana operational with growing capacity; first CII designations 2021-2023 across all 13 sectors; first MSSP licensing rounds + cybersecurity professional accreditation underway 2022-2024; 24-hour incident reporting system operational; CERT-GH active. CYBERSECURITY STRATEGY 2024-2028: Ghana's National Cybersecurity Strategy (NCS) refresh covering: (a) STRATEGIC OBJECTIVES - secure + resilient cyberspace + trusted online environment + cybersecurity workforce + secure digital transformation; (b) FIVE PILLARS - Governance + Cooperation + Capacity Building + Critical Infrastructure Protection + Resilience; (c) KEY INITIATIVES - critical infrastructure resilience + workforce development + child online safety + cybercrime response + international cooperati

Artefacts an auditor will ask for
  • Strategy 2024-2028 implementation
  • Priority area readiness
  • Exercise participation
  • International cooperation
Where this commonly fails
  • Strategy alignment ad-hoc
  • Priority areas unaddressed
  • Exercise non-participation
  • International engagement low
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Ghana Cybersecurity Act framework page.