Compliance Guide

NESA & ISR Compliance in the UAE

A practical, control-led walkthrough of UAE Information Assurance Standards (IAS) and Dubai ISR — scope, priority levels, control families, evidence expectations and audit readiness for enterprise buyers and Critical Information Infrastructure operators.

By Jiva Technologies12 min read
NESA and ISR compliance in the UAE — enterprise guide

The UAE Information Assurance Standards (IAS), historically associated with NESA and now maintained under the UAE Cybersecurity Council, define the control baseline for government entities and operators of Critical Information Infrastructure. Dubai ISR layers Emirate-level expectations on top for entities operating under the Dubai Electronic Security Center. This guide summarises what enterprise buyers, CIOs and CISOs need to understand before commissioning a gap assessment, remediation programme or audit response.

Scope and applicability

UAE IAS applies to federal government entities, semi-government bodies and operators of Critical Information Infrastructure across sectors such as energy, transport, finance, health and telecommunications. Suppliers processing data on behalf of in-scope entities inherit obligations through contract. Private-sector organisations frequently adopt the framework where they interact with government, hold regulated data, or fall under a sector regulator — CBUAE, DoH, MOHAP, TDRA, ADGM or DIFC — that references IAS in its own directives.

Priority levels (P1–P4)

IAS uses a four-tier priority system to calibrate control depth to national-interest risk. The tier is assigned per information asset or service, signed off by the accountable executive, and revisited whenever asset value, threat landscape or regulator expectation changes.

P1

Critical

Highest impact on national interests. Deepest control implementation and evidence expected.

P2

High

Significant impact on entity or sector operations. Strong technical and management controls required.

P3

Medium

Moderate impact. Baseline controls with targeted uplift where risk assessment indicates.

P4

Low

Limited impact. Baseline hygiene and monitoring, with proportional evidence.

Control families

IAS controls are grouped into Management (M) and Technical (T) families. The summary below captures the intent of each family; the authoritative wording, sub-controls and priority-level expectations live in the published standard.

M1 — Strategy & Planning

Information security strategy, governance charter, roles and responsibilities, and alignment of the security programme with entity-level risk appetite and sector obligations.

M2 — Information Security Risk Management

Asset inventory, threat modelling, risk assessment methodology, treatment plans, and risk register maintenance mapped to UAE IAS priority levels.

M3 — Awareness & Training

Role-based awareness curricula for general staff, privileged users, developers and executives, with phishing simulation cadence and completion evidence.

M4 — Human Resource Security

Screening, onboarding, transfer and offboarding controls, acceptable-use, and third-party personnel obligations tied to access reviews.

M5 — Compliance

Legal, regulatory and contractual register, sector-overlay mapping (CBUAE, DoH, MOHAP, TDRA), and internal audit programme against IAS controls.

M6 — Performance Evaluation & Improvement

KPIs, KRIs, management review, corrective action tracking, and continual improvement of the information assurance management system.

T1 — Asset Management

Authoritative CMDB, information classification and labelling, media handling and secure disposal, aligned to residency and sovereignty obligations.

T2 — Physical & Environmental Security

Secure areas, delivery and loading, equipment siting and protection, cabling security, and environmental monitoring for regulated facilities.

T3 — Operations Management

Change, capacity, patch, malware, backup, logging and monitoring controls with segregation of duties across production environments.

T4 — Communications

Network segmentation, secure gateways, cryptographic controls in transit, remote access, and email security aligned to IAS technical baselines.

T5 — Access Control

Identity lifecycle, MFA, privileged access management, joiner-mover-leaver, session recording and periodic access recertification.

T6 — Third-Party Security

Supplier due diligence, contractual security clauses, ongoing monitoring, and offboarding of third parties with access to entity data.

T7 — Information Systems Acquisition & Development

Secure SDLC, threat modelling, secrets management, code review, SAST/DAST/SCA gates, and secure-configuration baselines for build pipelines.

T8 — Incident Management

Detection, triage, containment, eradication, recovery and lessons-learned aligned to national CERT reporting timelines where applicable.

T9 — Business Continuity Management

BIA, RTO/RPO targets, tested recovery plans, cyber-recovery isolation and coordination with sector regulator continuity expectations.

How Dubai ISR differs

The Dubai Information Security Regulation (ISR) is issued by the Dubai Electronic Security Center (DESC) and applies to Dubai Government entities and their contracted suppliers. Objectives align with UAE IAS, but ISR carries Emirate-specific requirements, an audit and certification programme, and governance mechanics led by DESC.

Entities operating in Dubai typically merge IAS and ISR into a single control library so that evidence is collected once and mapped to both. Common differences to expect: ISR certification cycles, DESC-directed audit scope, incident-reporting channels through DESC in addition to national CERT, and specific expectations around Dubai Government data hosted inside the Emirate.

Compliance checklist

Use the list below to sanity-check readiness before commissioning an internal audit or responding to a regulator-driven review. Missing evidence for any item usually indicates the control is planned rather than implemented.

  • Entity scoping decision confirmed — Critical Information Infrastructure (CII), government, semi-government or private sector overlay
  • IAS priority level assigned (P1–P4) with justification recorded and signed by the accountable executive
  • Asset inventory reconciled to CMDB with classification tags and data-residency flags
  • Risk register updated in the last quarter with treatment owners and target dates
  • IAS control-mapping matrix populated with implemented, partial, planned and not-applicable states
  • Dubai ISR gap analysis completed where the entity has operations in the Emirate of Dubai
  • Sector overlay mapped (CBUAE, DoH, MOHAP, TDRA, ADGM, DIFC) with regulator-specific evidence
  • Internal audit programme scheduled against IAS with independent reviewer named
  • Incident response plan tested in the last twelve months with a documented tabletop or live exercise
  • Business continuity and cyber-recovery plans exercised with the outcome logged and gaps closed
  • Third-party register reconciled with contractual security clauses and last review dates
  • Evidence pack indexed and stored in a tamper-evident repository for auditor access

How Jiva GRC services facilitate NESA and ISR audits

Governance, Risk & Compliance services from Jiva Technologies package IAS and ISR work into four coordinated stages: scoping and tiering, gap assessment against the control library, remediation delivered through the wider cybersecurity practice, and audit-ready evidence packs maintained on a defined cadence.

Scoping confirms whether the entity is a Critical Information Infrastructure operator, government body or private-sector supplier, and assigns priority levels to each in-scope asset. Gap assessment records implemented, partial, planned and not-applicable states against every M and T family, with justifications for exclusions. Remediation is coordinated across identity, network, endpoint, cloud, monitoring and business continuity teams rather than handed off. Evidence packs are indexed and versioned so that auditor requests are answered from a single source of record.

Frequently asked questions

What is NESA / UAE Information Assurance Standards?
The UAE Information Assurance (IA) Standards, historically issued by the National Electronic Security Authority (NESA) and now maintained under the UAE Cybersecurity Council and Signals Intelligence Agency, define a control framework for entities that operate Critical Information Infrastructure or handle sensitive information in the UAE. The framework groups management (M) and technical (T) controls, applied at priority levels P1 to P4 based on risk to national interests.
Who is in scope for UAE IAS and Dubai ISR?
IAS applies to federal government entities, semi-government bodies and operators of Critical Information Infrastructure across sectors such as energy, transport, finance, health and telecommunications. Dubai ISR applies to Dubai Government entities and their contracted suppliers. Private-sector organisations often adopt IAS controls where they contract with government or fall under a sector regulator that references the framework.
How do NESA IAS and ISO 27001 relate?
ISO 27001 defines a management system for information security; UAE IAS defines a prescriptive control set with priority levels tuned to UAE national risk. Many controls overlap, and an ISO 27001-certified ISMS accelerates IAS adoption, but IAS mandates specific implementations (for example around residency, cryptography and incident reporting) that ISO alone does not require. A mapping matrix, not a substitution, is the correct approach.
What is a NESA IAS priority level and how is it assigned?
Priority levels P1 to P4 indicate the criticality of an information asset or service to national interests, with P1 the highest. Assignment is based on impact of compromise across confidentiality, integrity and availability, and drives the depth of control implementation expected. The rating is recorded, justified and signed off by the accountable executive, and revisited when the asset, threat landscape or regulatory expectation changes.
How does Dubai ISR differ from UAE IAS?
Dubai ISR (Information Security Regulation) is issued by the Dubai Electronic Security Center and applies to Dubai Government entities and their suppliers. It shares many objectives with UAE IAS but carries Emirate-specific requirements, an audit and certification programme, and a governance structure led by DESC. Entities operating in Dubai typically map IAS and ISR into a single control library to avoid duplicate evidence collection.
What incident reporting timelines apply under UAE IAS?
Reportable incidents are notified to the national CERT (aeCERT) and, where relevant, to the sector regulator within the timelines defined in the entity's incident response plan and regulator directives. Timelines tighten for incidents affecting Critical Information Infrastructure. The incident response plan should list contact points, escalation triggers, communication templates and evidence-preservation steps in advance.
How does Jiva Technologies support NESA and ISR compliance?
Governance, Risk & Compliance services from Jiva Technologies cover scoping, gap assessment, IAS and ISR control mapping, remediation design across identity, network, endpoint, cloud and monitoring domains, evidence-pack build and audit support. Delivery is integrated with the wider cybersecurity practice so that identified gaps translate into implemented controls rather than a report on a shelf.

Preparing for a NESA or ISR audit?

Jiva Technologies delivers scoping, gap assessment, remediation and audit support for UAE IAS and Dubai ISR, integrated with the cybersecurity, cloud and managed services practices.