Ghana: Implemented Cybersecurity Act 2020 (Act 1038) including security measures for critical information infrastructure providers

Description

Implemented Cybersecurity Act 2020 (Act 1038) including security measures for critical information infrastructure providers

On 29 December 2020, the Cybersecurity Act 2020 (Act 1038) entered into force following its signing and publication in the official gazette. The Act outlines measures for the designation, registration, and management of critical information infrastructure (CII). The Minister, advised by the Authority, can designate computer systems or networks as CII if they are essential for national security, economic and social well-being, or public safety. Designated CII must be registered with the Authority, and any changes in ownership must be reported within seven days. The Authority can conduct periodic audits to ensure compliance with the Act's provisions. Owners of CII must report cybersecurity incidents within 24 hours and submit audit reports to the Authority. Unauthorised access to CII is prohibited, with penalties including fines and imprisonment. The Act also establishes the National Computer Emergency Response Team (CERT) and Sectoral CERTs to respond to cybersecurity incidents. These teams coordinate responses, collect incident data, and submit monthly reports to the Authority. The Authority may establish a cybersecurity incident monitoring and response system, including an early warning system for public advisories. Institutions must report cybersecurity incidents to the relevant CERT within 24 hours, with non-compliance resulting in administrative penalties.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Cybersecurity regulation
Regulated Economic Activity
infrastructure provider: internet and telecom services, platform intermediary: other, infrastructure provider: cloud computing, storage and databases
Implementation Level
national
Government Branch
executive
Government Body
central government

Complete timeline of this policy change

Hide details
2020-11-06
adopted

On 6 November 2020, the Cybersecurity Act 2020 (Act 1038) was adopted by the Parliament of the Repu…

2020-12-29
in force

On 29 December 2020, the Cybersecurity Act 2020 (Act 1038) entered into force following its signin…

We use cookies and other technologies to perform analytics on our website. By opting in, you consent to the use by us and our third-party partners of cookies and data gathered from your use of our platform. See our Privacy Policy to learn more about the use of data and your rights.