Gulf — United Arab Emirates
UAE Information Assurance and Dubai ISR
Compliance assessment for organisations operating in the Emirates, against the federal Information Assurance Standards and, for Dubai government-linked entities, the Information Security Regulation.
The regulatory picture
Information security obligations in the UAE come from several directions and the applicable set depends on where you operate and who you serve. Federal Information Assurance Standards apply to entities in defined critical sectors. Dubai government entities and organisations working with them face the Dubai Information Security Regulation administered by the Dubai Electronic Security Center. Financial free zones operate their own regimes. Federal data protection legislation applies alongside these.
Determine which regime binds your entity before scoping any assessment. Organisations frequently assume one framework applies when in fact two or three do, or assume a free zone regime exempts them from federal obligations when it does not. We establish applicability formally, and where the answer turns on a legal question we say so and recommend you take advice.
Typical scope
- Applicability determination across the federal, emirate-level and free zone regimes that may apply.
- Information security governance, policy and organisational structure.
- Asset management and information classification, which most frameworks in the region treat as foundational.
- Access control, identity management and privileged access.
- Operations security, logging, monitoring and incident management.
- Third-party and cloud service governance.
- Business continuity and resilience.
- Personal data handling, assessed against the applicable data protection obligations.
Assess once, report several times
Efficiency across overlapping regimes
Where several frameworks apply, we assess once and report several times. A single evidence collection exercise is mapped to each applicable control set, so you are not running three sequential assessments that ask the same people the same questions. This is usually the largest cost saving available on a multi-framework engagement.
How the engagement runs
-
1
Applicability determination
Establish which regimes bind the entity, based on sector, emirate, free zone and client base.
-
2
Control set consolidation
Build a unified control set that satisfies every applicable framework without duplication.
-
3
Evidence collection
Single collection exercise mapped across all applicable frameworks.
-
4
Assessment
Assess each control with evidence and record the position per framework.
-
5
Gap analysis
Identify gaps, flagging where one remediation closes requirements in multiple frameworks.
-
6
Reporting
Separate report per framework, in each framework's own structure.
What you receive
Frequently asked questions
Related services
Not sure this is the framework that binds you?
Six questions, ninety seconds, runs in your browser. It will tell you which frameworks apply and why.
Request a proposal