UAE Information Assurance Regulation • • Abu Dhabi Information Security Standards Version 1 and Version 2, developed by Abu Dhabi Systems and Information Centre (ADSIC). SANS 20 Critical Security Controls for Effective Cyber Defense Version 4.1 Moreover the development was guided by key principles including: • • • Applicability of the common IA requirements across industries , and applicability of the sector-specific IA requirements across entities within each CIIP sector Support for the development of the entity, sector, and national-level views of cyber security, to address potential IA risks that emerge from the interconnectivity of entities and sectors Support the performance management and the evolution of the controls in these based on measuring and sharing effective performance indicators, as well as contributions from key stakeholders to support the ongoing development and refinement of these . Compliance with these will raise the level of national IA and help the UAE progress towards a more resilient national information and communication infrastructure, and cyberspace. All UAE government entities and other entities identified as critical by TRA are obligated to implement these . However, TRA highly recommends all entities in the UAE to adopt these on a voluntary basis, as applicable, in order to participate in raising the nation minimumsecurity levels. 7

Select target paragraph3