21% of IEC 62443 you already have
Ghana Cybersecurity Act already covers about 21% of IEC 62443, leaving
64 of 81 controls as genuinely new work.
Already covered 0
Likely covered 17
New work 64
No control in Ghana Cybersecurity Act
maps directly to one in IEC 62443. Everything counted as covered is covered because both
map to the same third standard, which is what a crosswalk is, but it is an inference rather
than a lookup.
What is genuinely new work
Nothing in Ghana Cybersecurity Act reaches these. This is the list to scope.
62443-2-1-ACAccount Management and Access Control for IACS
62443-2-1-BCPBusiness Continuity and Disaster Recovery for IACS
62443-2-1-CSMSCyber Security Management System (CSMS) for IACS
62443-2-1-IRIncident Planning and Response for IACS
62443-2-1-MOCManagement of Change for IACS Security
62443-2-1-NSEGNetwork Segmentation and Zone/Conduit Implementation
62443-2-1-PHYPhysical and Environmental Security of IACS Assets
62443-2-1-PMPatch Management and System Update for IACS
62443-2-1-RAIACS Risk Identification, Classification and Assessment
62443-2-1-TRNPersonnel Security Awareness and Training for IACS
62443-2-4-SP-01Service Provider Security Program
62443-2-4-SP-02Service Provider Solution Staffing and Assurance
62443-2-4-SP-03Service Provider Architecture and Design Practices
62443-2-4-SP-04Service Provider Wireless and Remote Access Practices
62443-2-4-SP-05Service Provider Malware Protection Practices
62443-2-4-SP-06Service Provider Backup and Restore Practices
62443-3-2-CRSDocument Cybersecurity Requirements Specification (CRS)
62443-3-2-ZCR-1Identify System Under Consideration
62443-3-2-ZCR-2High-Level Risk Assessment
62443-3-2-ZCR-3Partition the SUC into Zones and Conduits
62443-3-2-ZCR-4Detailed Cybersecurity Risk Assessment per Zone and Conduit
62443-3-3-FR1-SR-1-1Human User Identification and Authentication (FR1)
62443-3-3-FR1-SR-1-11Unsuccessful Login Attempts
62443-3-3-FR1-SR-1-2Software Process and Device Identification and Authentication
62443-3-3-FR1-SR-1-5Authenticator Management
62443-3-3-FR1-SR-1-7Strength of Password-Based Authentication
62443-3-3-FR2-SR-2-1Authorisation Enforcement (FR2 Use Control)
62443-3-3-FR2-SR-2-4Mobile Code Restriction
62443-3-3-FR2-SR-2-5Session Lock and Termination
62443-3-3-FR2-SR-2-8Auditable Events
62443-3-3-FR3-SR-3-1Communication Integrity (FR3 System Integrity)
62443-3-3-FR3-SR-3-2Protection from Malicious Code
62443-3-3-FR3-SR-3-3Security Functionality Verification
62443-3-3-FR3-SR-3-4Software and Information Integrity
62443-3-3-FR3-SR-3-8Session Integrity
62443-3-3-FR4-SR-4-1Information Confidentiality (FR4 Data Confidentiality)
62443-3-3-FR4-SR-4-2Information Persistence and Sanitisation
62443-3-3-FR5-SR-5-1Network Segmentation (FR5 Restricted Data Flow)
62443-3-3-FR5-SR-5-2Zone Boundary Protection
62443-3-3-FR5-SR-5-3General-Purpose Person-to-Person Communication Restrictions
62443-3-3-FR6-SR-6-1Audit Log Accessibility (FR6 Timely Response to Events)
62443-3-3-FR6-SR-6-2Continuous Monitoring
62443-3-3-FR7-SR-7-1Denial-of-Service Protection (FR7 Resource Availability)
62443-3-3-FR7-SR-7-3Control System Backup
62443-3-3-FR7-SR-7-6Network and Security Configurations
62443-4-1-DMDefect Management and Vulnerability Handling
62443-4-1-SDSecure by Design
62443-4-1-SGSecurity Guidelines for Asset Owner
62443-4-1-SISecure Implementation
62443-4-1-SMSecurity Management (Product Development)
62443-4-1-SRSpecification of Security Requirements
62443-4-1-SUMSecurity Update Management
62443-4-1-SVVSecurity Verification and Validation
62443-4-2-CR-1-1Component Identification and Authentication of Users
62443-4-2-CR-3-1Component Communication Integrity
62443-4-2-CR-7-1Component Denial-of-Service Protection
62443-4-2-EDR-3-10Embedded Device Support for Updates
IEC62443-01Critical asset identification and inventory
IEC62443-03Security governance structure
IEC62443-04Roles and responsibilities for critical systems
IEC62443-06Physical and logical access controls
IEC62443-09Interactive remote access security
IEC62443-15Ports and services management
IEC62443-19Coordination with sector-specific agencies
Show the 17 you already have
IEC62443-02System security categorization
IEC62443-05Security policy for operational technology
IEC62443-07Personnel risk assessment
IEC62443-08Electronic access perimeter management
IEC62443-10Revocation of access procedures
IEC62443-11Security patch management for OT
IEC62443-12Malware prevention for operational systems
IEC62443-13Network security monitoring
IEC62443-14System security hardening
IEC62443-16Incident response plan for operational disruptions
IEC62443-17Recovery plan for critical systems
IEC62443-18Reporting obligations to authorities
IEC62443-20Exercises and drills for OT incidents
IEC62443-21Supply chain risk management for critical components
IEC62443-22Configuration management for OT systems
IEC62443-23Change management procedures
IEC62443-24Vulnerability assessment for critical systems
How this is calculated
Already covered means a mapping runs from a control in Ghana Cybersecurity Act to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition