Skip to content

Gulf — United Arab Emirates

UAE Information Assurance and Dubai ISR

Compliance assessment for organisations operating in the Emirates, against the federal Information Assurance Standards and, for Dubai government-linked entities, the Information Security Regulation.

The regulatory picture

Information security obligations in the UAE come from several directions and the applicable set depends on where you operate and who you serve. Federal Information Assurance Standards apply to entities in defined critical sectors. Dubai government entities and organisations working with them face the Dubai Information Security Regulation administered by the Dubai Electronic Security Center. Financial free zones operate their own regimes. Federal data protection legislation applies alongside these.

Determine which regime binds your entity before scoping any assessment. Organisations frequently assume one framework applies when in fact two or three do, or assume a free zone regime exempts them from federal obligations when it does not. We establish applicability formally, and where the answer turns on a legal question we say so and recommend you take advice.

Typical scope

  • Applicability determination across the federal, emirate-level and free zone regimes that may apply.
  • Information security governance, policy and organisational structure.
  • Asset management and information classification, which most frameworks in the region treat as foundational.
  • Access control, identity management and privileged access.
  • Operations security, logging, monitoring and incident management.
  • Third-party and cloud service governance.
  • Business continuity and resilience.
  • Personal data handling, assessed against the applicable data protection obligations.

Assess once, report several times

ISO 27001 SAMA CSF NCA ECC Shared evidence Assess once, reportseparately Usually the largest savingavailable on a multi-frameworkengagement.
Federal, emirate and free zone regimes overlap substantially.

Efficiency across overlapping regimes

Where several frameworks apply, we assess once and report several times. A single evidence collection exercise is mapped to each applicable control set, so you are not running three sequential assessments that ask the same people the same questions. This is usually the largest cost saving available on a multi-framework engagement.

How the engagement runs

  1. 1

    Applicability determination

    Establish which regimes bind the entity, based on sector, emirate, free zone and client base.

  2. 2

    Control set consolidation

    Build a unified control set that satisfies every applicable framework without duplication.

  3. 3

    Evidence collection

    Single collection exercise mapped across all applicable frameworks.

  4. 4

    Assessment

    Assess each control with evidence and record the position per framework.

  5. 5

    Gap analysis

    Identify gaps, flagging where one remediation closes requirements in multiple frameworks.

  6. 6

    Reporting

    Separate report per framework, in each framework's own structure.

What you receive

Applicability analysis across federal, emirate and free zone regimes
Consolidated control set mapped to every applicable framework
Assessment results reported separately per framework
Cross-framework gap analysis showing shared remediation opportunities
Prioritised roadmap sequenced by regulatory deadline
Evidence pack retained for supervisory or client inspection

Frequently asked questions

It depends on the free zone, your sector and your client base — and it is a legal question as much as a technical one. Some free zones operate independent regimes; being inside one does not automatically exempt an entity from every federal obligation. We determine applicability at scoping and recommend legal confirmation where the position is not clear-cut.

Yes, and it is usually worth doing. The control overlap with the regional frameworks is substantial, so a combined assessment costs materially less than running them separately, and ISO 27001 certification is often what your commercial clients ask for even when the regulator asks for something else.

Related services

Not sure this is the framework that binds you?

Six questions, ninety seconds, runs in your browser. It will tell you which frameworks apply and why.

Request a proposal
Top