40% of PCI PIN Security you already have
Ghana Cybersecurity Act already covers about 40% of PCI PIN Security, leaving
26 of 43 controls as genuinely new work.
Already covered 0
Likely covered 17
New work 26
No control in Ghana Cybersecurity Act
maps directly to one in PCI PIN Security. Everything counted as covered is covered because both
map to the same third standard, which is what a crosswalk is, but it is an inference rather
than a lookup.
What is genuinely new work
Nothing in Ghana Cybersecurity Act reaches these. This is the list to scope.
CO-1PINs Used for Cardholder Authentication Are Processed in Approved Devices
CO-10Equipment Used to Process PINs and Keys Is Managed in a Secure Manner
CO-11Secret and Private Keys and Key Components Are Generated, Conveyed, and Used in a Manner That Prevents or Detects Their Unauthorized Disclosure, Modification, or Substitution
CO-12Keys Are Used in a Manner That Prevents or Detects Their Unauthorized Usage
CO-13Keys Are Administered Throughout Their Lifecycle in a Secure Manner
CO-14Materials Used to Generate or Transport Keys Are Treated With the Same Security as the Keys They Protect
CO-15Cryptographic Keys Are Replaced With New Keys When Knowledge of Or Access to a Key Is No Longer Required
CO-16Keys No Longer Used or Replaced Are Securely Destroyed
CO-17Access to Secret and Private Cryptographic Keys and Key Material Is Restricted
CO-18Logging Is in Place to Enable Audit and Investigation of Key Management Activities
CO-19Organizations Implement and Document Risk-Mitigation Practices
CO-2Devices Approved Under PCI PTS POI Have SRED Functionality
CO-3POIs and HSMs Are Protected From Unauthorized Access
CO-4Procedures Exist to Protect Devices From Tampering and Substitution
CO-5Cryptographic Keys Are Generated Using Approved Methods
CO-6Cryptographic Keys Are Conveyed or Transmitted Securely
CO-7Key Loading Is Handled in a Secure Manner
CO-8Keys Are Used Only for Their Designated Purpose
CO-9Keys Are Administered in a Secure Manner
CO-Annex-ASymmetric Key Distribution Using Asymmetric Techniques
CO-Annex-BKey-Injection Facility Requirements
PCI-PIN-04Security policy framework
PCI-PIN-17Contractual security requirements
PCI-PIN-20Exit strategy and transition planning
PCI-PIN-21Incident detection and classification
PCI-PIN-22Incident response and containment
Show the 17 you already have
PCI-PIN-05Roles and responsibilities definition
PCI-PIN-06Network security and segmentation
PCI-PIN-07Endpoint protection and detection
PCI-PIN-08Application security controls
PCI-PIN-09Encryption and key management
PCI-PIN-10Secure configuration standards
PCI-PIN-11Business continuity planning and testing
PCI-PIN-12Disaster recovery procedures
PCI-PIN-13Third-party dependency management
PCI-PIN-14Critical service identification
PCI-PIN-15Communication and escalation procedures
PCI-PIN-16Due diligence and onboarding
PCI-PIN-18Ongoing monitoring and assessment
PCI-PIN-19Concentration risk management
PCI-PIN-23Regulatory reporting requirements
PCI-PIN-24Customer notification procedures
PCI-PIN-25Post-incident review and improvement
How this is calculated
Already covered means a mapping runs from a control in Ghana Cybersecurity Act to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition