ECG ISCSMS Policy

Information Security, Continuity and Service Management Policy Statement

The Electricity Company of Ghana (ECG), classified as a Critical Information Infrastructure (CII) under the Cybersecurity Act, 2020 (Act 1038), recognizes that secure information, resilient operations and reliable technology services are essential to the safe and reliable delivery of electricity services. ECG is committed to protecting information, sustaining critical services, managing risk and strengthening operational resilience for the benefit of customers, staff, suppliers, regulators and other stakeholders.

This statement summarizes ECG’s public commitment to its Information Security, Continuity and Service Management System (ISCSMS). Detailed procedures, technical controls, response arrangements and operational requirements are maintained internally and applied through ECG’s governance framework.

Through the ISCSMS, ECG promotes the confidentiality, integrity and availability of information, the continuity of critical services, effective IT service management and continual improvement of operational resilience.

 

Our Commitment

ECG is undergoing an ISCSMS implementation aligned with internationally recognized standards and guidelines, including ISO/IEC 27001 for information security, ISO 22301 for business continuity, ISO/IEC 20000-1 for IT service management and ISO 31000 for risk management guidance.

ECG will apply this system to protect information and assets, reduce the likelihood and impact of disruptions, meet applicable legal and regulatory obligations, and sustain stakeholder confidence in the reliability and resilience of ECG’s operations.

ECG’s management will provide leadership, resources and oversight for the implementation, maintenance and continual improvement of the ISCSMS. Employees, contractors, suppliers and other authorized users are expected to observe applicable ISCSMS requirements.

 

Scope

This statement applies to ECG’s information, systems, services, people and processes. It covers board members, directors, employees, contractors, suppliers and other third parties who access, process or support ECG’s information, systems or services.

  

ISCSMS Objectives

  • ECG establishes, monitors and reviews Information Security, Continuity and Service Management System objectives to support:
  • Protection of information and critical assets.
  • Improvement of operational resilience and service continuity.
  • Effective management of information security, business continuity and service-related risks.
  • Compliance with legal, regulatory and contractual obligations.
  • Improvement of service quality and customer confidence.
  • Enhancement of employee awareness and capability.
  • Continual improvement of ISCSMS performance and effectiveness.

 

Continual Improvement

ECG will continually improve the ISCSMS by monitoring performance, assessing risks, learning from incidents and exercises, strengthening awareness, and updating processes to reflect business needs, stakeholder expectations and applicable requirements.

This statement will be reviewed periodically to ensure it remains suitable, relevant and effective in supporting ECG’s mandate, regulatory obligations and commitment to resilient electricity service delivery.

 

 

 


Print   Email