Framework overlap

Does AWS Well-Architected Security Pillar cover Ghana Cybersecurity Act?

You hold AWS Well-Architected Security Pillar and have been told to do Ghana Cybersecurity Act. Here is how much overlaps, control by control.

50% of Ghana Cybersecurity Act you already have

AWS Well-Architected Security Pillar already covers about 50% of Ghana Cybersecurity Act, leaving 6 of 12 controls as genuinely new work.

Already covered 6 Likely covered 0 New work 6

What is genuinely new work

Nothing in AWS Well-Architected Security Pillar reaches these. This is the list to scope.

GhCSA-Budapest-Malabo-AfricaCERT-2024-2025
Budapest Convention, Malabo Convention, AfricaCERT and 2024-2025 Status
GhCSA-Child-OnlineProtection-Awareness-Intl-Coop
Child Online Protection, Awareness, Education and International Cooperation
GhCSA-Coord-Ghana-DPA-Cybercrime-Sectoral
Coordination with Ghana DPA 2012, Cybercrime Definitions and Cross-Sectoral Frameworks
GhCSA-Crosswalk-NIST-ISO-27001-Sectoral
Crosswalk to NIST CSF 2.0, ISO 27001, ISO 22301 and Sector Standards
GhCSA-Sectoral-Coordination-DPC-NCA-BoG
Sectoral Coordination - Data Protection Commission, NCA, Bank of Ghana and Other Regulators
GhCSA-Status-2024-2025-Strategy-AI
Implementation Status, Cybersecurity Strategy 2024-2028 and 2024-2025 Pipeline
Show the 6 you already have
GhCSA-CII-Designation-Plan-Audit-Risk
CII Designation, Registration, Cybersecurity Plan, Audit and Risk Assessment
GhCSA-Cybercrime-Lawful-Access-Preservation
Cybercrime Offences, Lawful Access and Electronic Evidence Preservation
GhCSA-Implementation-Roadmap
Implementation Roadmap - Organizational Roles, Tooling and Metrics
GhCSA-Incident-Reporting-CERT-GH
Cybersecurity Incident Reporting (24-Hour to CSA) and National CERT-GH Engagement
GhCSA-Scope-CSAGhana-Defs
Scope, Cyber Security Authority (CSA Ghana) and Key Definitions
GhCSA-Service-Provider-Licensing-Professional
Cybersecurity Service Provider Licensing and Professional Accreditation

How this is calculated

Already covered means a mapping runs from a control in AWS Well-Architected Security Pillar to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition