50% of Ghana Cybersecurity Act you already have
ISO 27043 already covers about 50% of Ghana Cybersecurity Act, leaving
6 of 12 controls as genuinely new work.
Already covered 0
Likely covered 6
New work 6
No control in ISO 27043
maps directly to one in Ghana Cybersecurity Act. Everything counted as covered is covered because both
map to the same third standard, which is what a crosswalk is, but it is an inference rather
than a lookup.
What is genuinely new work
Nothing in ISO 27043 reaches these. This is the list to scope.
GhCSA-Budapest-Malabo-AfricaCERT-2024-2025Budapest Convention, Malabo Convention, AfricaCERT and 2024-2025 Status
GhCSA-Child-OnlineProtection-Awareness-Intl-CoopChild Online Protection, Awareness, Education and International Cooperation
GhCSA-Coord-Ghana-DPA-Cybercrime-SectoralCoordination with Ghana DPA 2012, Cybercrime Definitions and Cross-Sectoral Frameworks
GhCSA-Crosswalk-NIST-ISO-27001-SectoralCrosswalk to NIST CSF 2.0, ISO 27001, ISO 22301 and Sector Standards
GhCSA-Sectoral-Coordination-DPC-NCA-BoGSectoral Coordination - Data Protection Commission, NCA, Bank of Ghana and Other Regulators
GhCSA-Status-2024-2025-Strategy-AIImplementation Status, Cybersecurity Strategy 2024-2028 and 2024-2025 Pipeline
Show the 6 you already have
GhCSA-CII-Designation-Plan-Audit-RiskCII Designation, Registration, Cybersecurity Plan, Audit and Risk Assessment
GhCSA-Cybercrime-Lawful-Access-PreservationCybercrime Offences, Lawful Access and Electronic Evidence Preservation
GhCSA-Implementation-RoadmapImplementation Roadmap - Organizational Roles, Tooling and Metrics
GhCSA-Incident-Reporting-CERT-GHCybersecurity Incident Reporting (24-Hour to CSA) and National CERT-GH Engagement
GhCSA-Scope-CSAGhana-DefsScope, Cyber Security Authority (CSA Ghana) and Key Definitions
GhCSA-Service-Provider-Licensing-ProfessionalCybersecurity Service Provider Licensing and Professional Accreditation
How this is calculated
Already covered means a mapping runs from a control in ISO 27043 to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition