BoG Cyber Directive
Market regime · Bank of Ghana Cyber & Information Security Directive (2018)
Bank of Ghana
Ghana
2018, phased implementation
Bank of Ghana, with the financial-industry CSIRT
Banks and payment service providers under Bank of Ghana supervision
Curated, versioned & cross-mapped
The obligation, plainly.
The Bank of Ghana's Cyber & Information Security Directive sets the supervisory bar for Ghanaian banking: governance with a designated CISO, a documented security programme, protective controls, security-operations capability, incident reporting through the BoG and the financial-industry CERT, resilience and independent assurance.
It is one of the region's most prescriptive directives, and it lands on the same control substance as the CBN and CBK regimes, which is why the catalog maps all three onto one technical and governance control set.
Where programmes are tested.
Governance and the CISO
Board-approved strategy and a CISO with the standing to execute it.
The security programme
A documented, risk-driven programme covering protection, awareness and third parties.
SOC and monitoring
Security-operations capability: monitoring, detection and response the supervisor can inspect.
Reporting and assurance
Incidents reported to the BoG and sector CERT, with periodic independent assurance of the programme.
Curated once, evidenced continuously.
- The directive cross-walks to the same controls as the CBN framework, CBK guidance and ISO 27001, one estate, evidenced once, reported to each supervisor in its own language.
- Requirements resolve to shared controls: implement a control once and it counts toward every framework it maps to.
- Status is evidence-gated: a requirement can't be marked implemented without valid, in-date evidence behind it.
- Every attestation carries maker/checker, and every action lands in an append-only audit trail.
BoG Cyber Directive, asked plainly.
The questions compliance teams actually ask before an adoption decision or an audit.
Who does the BoG directive apply to?
Banks, and through subsequent guidelines the payment service providers and other institutions the Bank of Ghana licenses. Its expectations scale with the institution, but the core, governance, programme, monitoring, reporting, applies across the sector.
Does the directive really require a SOC?
It requires security-operations capability, monitoring, detection and response that actually run. Larger institutions typically evidence this with an in-house or outsourced SOC; what the supervisor tests is the capability and its logs, not the org chart.
Where do incidents get reported?
To the Bank of Ghana and through the financial-industry CSIRT arrangements the directive established, within the mandated timelines. The dual channel is the point: supervisory notification and sector-wide threat sharing, both fed from one incident workflow.
How does it compare to the CBN's cybersecurity framework?
Same species: board accountability, CISO, risk-based controls, reporting on a clock. An institution operating in both markets should run one control set and let the cross-mapping produce each supervisor's evidence, which is exactly how the catalog structures it.
Where it connects.
The full catalogCompliance you can prove.
Walk into your next audit ready.
Book a working demo. We'll map your obligations to the standards you're audited against and the regulators you actually answer to.
The platform, modules, catalog, audit trail and security architecture are live today; the continuous live-evidence engine is in active development, shown in a working demo. Reach us at hello@cardinalgrc.com.