Governance. Risk. Compliance. Cybersecurity.
Scope & Applicability

Scope & Applicability — UAE IAF

Defining the right scope is the single biggest determinant of UAE IAF success. Too narrow and the certificate is meaningless; too broad and the programme stalls under its own weight.

  • ISO/IEC 27001 Certified
  • ISO/IEC 27701 Certified
  • ISO 9001 Certified

Delivered by an ISO/IEC 27001, 27701 & 9001 certified organisation

Who the standard applies to

  • UAE-licensed entities under the relevant federal or emirate regulator
  • Service providers processing in-scope data for UAE entities
  • Branches of foreign entities operating in the UAE
  • Critical-infrastructure operators designated by the authority

Typical in-scope boundaries

  • Legal entities and business units in scope
  • Geographies and data residency boundaries
  • Cloud accounts, data centres and end-user computing estates
  • Third parties processing in-scope data on your behalf
  • Products, services or customer segments included
Scope dimensions

Icon grid titled "Scope dimensions" with 5 categories: Legal entities and business units in scope, Geographies and data residency boundaries, Cloud accounts, data centres and end-user computing estates, Third parties processing in-scope data on your behalf, Products, services or customer segments included.

  • Legal entities and business units in scope
  • Geographies and data residency boundaries
  • Cloud accounts, data centres and end-user computing estates
  • Third parties processing in-scope data on your behalf
  • Products, services or customer segments included

Common scoping mistakes

  • Excluding shared services (HR, payroll, identity) that handle in-scope data.
  • Treating SaaS platforms as out-of-scope when they process production data.
  • Omitting DR, backup and recovery sites from the boundary.
  • Forgetting to include the security operations function itself.
Scoping pitfalls to avoid

Checklist titled "Scoping pitfalls to avoid" with 4 items, every item marked complete: Excluding shared services (HR, payroll, identity) that handle in-scope data.; Treating SaaS platforms as out-of-scope when they process production data.; Omitting DR, backup and recovery sites from the boundary.; Forgetting to include the security operations function itself..

  • Excluding shared services (HR, payroll, identity) that handle in-scope data.
  • Treating SaaS platforms as out-of-scope when they process production data.
  • Omitting DR, backup and recovery sites from the boundary.
  • Forgetting to include the security operations function itself.

How we run the scoping exercise

A two-week scoping sprint with your sponsor, IT, security, legal and audit produces a written scope statement, an asset and data-flow map, and a signed-off boundary diagram. This becomes the anchor for the entire UAE IAF programme.