Background
The UAE Information Assurance (IA) Standards, originally issued by NESA and now maintained by the UAE Cyber Security Council, apply to entities operating Critical Information Infrastructure across government, energy, telecom, finance, and transport.
Structure of the standards
- 188 controls across 4 management and 11 technical security families
- 4 priority tiers (P1 – P4) — P1 controls are mandatory for every CII operator
- Three sector profiles — Government, Critical Sector, Other
The control map
Management families
- M1 — Strategy and planning
- M2 — Information security risk management
- M3 — Awareness and training
- M4 — Human resources security
Technical families
- T1 — Asset management
- T2 — Physical and environmental security
- T3 — Operations management
- T4 — Communications
- T5 — Access control
- T6 — Third-party security
- T7 — Information systems acquisition, development and maintenance
- T8 — Information security incident management
- T9 — Information security continuity management
- T10 — Compliance
- T11 — Sector-specific requirements
P1 controls every CII operator must close first
- Documented information security strategy with executive sponsorship
- Risk-management methodology covering all CII assets
- Asset inventory with classification
- Privileged-access management
- 24x7 monitoring with incident triage
- Vulnerability management with monthly cadence
- Backup with quarterly restore test
- Annual independent security audit
Mapping to other frameworks
The IA Standards align closely with ISO 27001 and NIST CSF. MAST maintains a one-to-one mapping that lets clients reuse evidence across CBUAE, ADHICS, ISO 27001 and IA audits.
Next step
For a P1 gap assessment scoped to your sector, contact the UAE practice lead.