UAE Information Assurance Regulation 1.2 Purpose of the UAE IA Regulation The purpose of the UAE IA Regulation is to provide requirements to raise the minimum level of protection of information assets and supporting systems across all implementing entities in the UAE, as outlined in Section 2.1. In particular, the UAE IA Regulation provides: • • • • • • • • Description of how information assurance is achieved at the national, sector, and entity levels Enable a risk-based approach for the implementation of these Outline of the roles and responsibilities of key stakeholders for the planning, development, implementation, and ongoing monitoring and improvement of these Reference catalog of common information security controls to defend against common threats that exploit known cyber security vulnerabilities Realization for sectorial requirements through the provision of specialized controls to address sector-specific information assurance requirements Phased implementation approach to address the most common threats, facilitate the incremental adoption of these , and optimize the value realized through implementation Definition of compliance from the perspective of these and describe the approach that will be adopted by TRA to assess compliance Enabler for inter-entity and cross-sector communication to support information sharing and build national situational awareness In summary, the implementation of these will serve to improve the IA protection level of the UAE critical information infrastructure. As such, this document serves as the national UAE IA Regulation that implementing entities have to demonstrate compliance with. 8

Select target paragraph3