BoG Cyber Directive

Ghana's supervisory cyber regime: CISO, programme, SOC capability and reporting into the BoG.

Market regime · Bank of Ghana Cyber & Information Security Directive (2018)

Issued by

Bank of Ghana

Region

Ghana

Effective

2018, phased implementation

Oversight

Bank of Ghana, with the financial-industry CSIRT

Applies when

Banks and payment service providers under Bank of Ghana supervision

In the catalog

Curated, versioned & cross-mapped

The obligation, plainly.

The Bank of Ghana's Cyber & Information Security Directive sets the supervisory bar for Ghanaian banking: governance with a designated CISO, a documented security programme, protective controls, security-operations capability, incident reporting through the BoG and the financial-industry CERT, resilience and independent assurance.

It is one of the region's most prescriptive directives, and it lands on the same control substance as the CBN and CBK regimes, which is why the catalog maps all three onto one technical and governance control set.

Where programmes are tested.

01

Governance and the CISO

Board-approved strategy and a CISO with the standing to execute it.

02

The security programme

A documented, risk-driven programme covering protection, awareness and third parties.

03

SOC and monitoring

Security-operations capability: monitoring, detection and response the supervisor can inspect.

04

Reporting and assurance

Incidents reported to the BoG and sector CERT, with periodic independent assurance of the programme.

Curated once, evidenced continuously.

  • The directive cross-walks to the same controls as the CBN framework, CBK guidance and ISO 27001, one estate, evidenced once, reported to each supervisor in its own language.
  • Requirements resolve to shared controls: implement a control once and it counts toward every framework it maps to.
  • Status is evidence-gated: a requirement can't be marked implemented without valid, in-date evidence behind it.
  • Every attestation carries maker/checker, and every action lands in an append-only audit trail.

BoG Cyber Directive, asked plainly.

The questions compliance teams actually ask before an adoption decision or an audit.

Who does the BoG directive apply to?

Banks, and through subsequent guidelines the payment service providers and other institutions the Bank of Ghana licenses. Its expectations scale with the institution, but the core, governance, programme, monitoring, reporting, applies across the sector.

Does the directive really require a SOC?

It requires security-operations capability, monitoring, detection and response that actually run. Larger institutions typically evidence this with an in-house or outsourced SOC; what the supervisor tests is the capability and its logs, not the org chart.

Where do incidents get reported?

To the Bank of Ghana and through the financial-industry CSIRT arrangements the directive established, within the mandated timelines. The dual channel is the point: supervisory notification and sector-wide threat sharing, both fed from one incident workflow.

How does it compare to the CBN's cybersecurity framework?

Same species: board accountability, CISO, risk-based controls, reporting on a clock. An institution operating in both markets should run one control set and let the cross-mapping produce each supervisor's evidence, which is exactly how the catalog structures it.

Compliance you can prove.
Walk into your next audit ready.

Book a working demo. We'll map your obligations to the standards you're audited against and the regulators you actually answer to.

The platform, modules, catalog, audit trail and security architecture are live today; the continuous live-evidence engine is in active development, shown in a working demo. Reach us at hello@cardinalgrc.com.