Scope
The Central Bank of the UAE Information Security Regulation applies to all Licensed Financial Institutions (LFIs) — banks, exchange houses, finance companies, payment service providers and stored-value facilities. The Standards expand the regulation into specific, auditable controls.
What the regulator is asking for
- A documented information security strategy approved by the board
- A risk-based security programme with a named CISO reporting independently of IT
- Continuous monitoring with reporting to the CBUAE on material incidents
- Third-party risk oversight for every outsourced critical function
Cross-walk to ISO 27001 and PCI DSS
| CBUAE control area | ISO 27001:2022 | PCI DSS v4 |
|---|---|---|
| Governance and CISO mandate | 5.1, 5.3, A.5.2 | 12.1, 12.4 |
| Risk management | 6.1.2, 6.1.3 | 12.3 |
| Access control | A.5.15 – A.5.18 | 7.x, 8.x |
| Cryptography | A.8.24 | 3.x, 4.x |
| Logging and monitoring | A.8.15, A.8.16 | 10.x, 11.5 |
| Incident response | A.5.24 – A.5.28 | 12.10 |
| Third-party risk | A.5.19 – A.5.23 | 12.8, 12.9 |
90-day remediation plan
Days 1-30 — Stabilise governance
- Confirm CISO mandate and reporting line
- Refresh information security policy with board sign-off
- Stand up the incident-reporting channel to CBUAE
Days 31-60 — Close technical gaps
- Privileged-access management for all production systems
- Encryption inventory: data at rest, in transit, in backups
- 24x7 monitoring coverage for the critical-function estate
Days 61-90 — Evidence and assurance
- Internal audit against the CBUAE Standards
- Third-party risk review for the top 20 vendors
- Tabletop exercise on the regulator-notification pathway
Next step
MAST runs the CBUAE readiness diagnostic as a fixed-fee two-week engagement. Book a diagnostic.