UAE Information Assurance Regulation
1.2 Purpose of the UAE IA Regulation
The purpose of the UAE IA Regulation is to provide requirements to raise the minimum level
of protection of information assets and supporting systems across all implementing entities
in the UAE, as outlined in Section 2.1.
In particular, the UAE IA Regulation provides:
•
•
•
•
•
•
•
•
Description of how information assurance is achieved at the national, sector, and entity
levels
Enable a risk-based approach for the implementation of these
Outline of the roles and responsibilities of key stakeholders for the planning, development,
implementation, and ongoing monitoring and improvement of these
Reference catalog of common information security controls to defend against common
threats that exploit known cyber security vulnerabilities
Realization for sectorial requirements through the provision of specialized controls to
address sector-specific information assurance requirements
Phased implementation approach to address the most common threats, facilitate the
incremental adoption of these , and optimize the value realized through implementation
Definition of compliance from the perspective of these and describe the approach that
will be adopted by TRA to assess compliance
Enabler for inter-entity and cross-sector communication to support information sharing
and build national situational awareness
In summary, the implementation of these will serve to improve the IA protection level of the
UAE critical information infrastructure. As such, this document serves as the national UAE IA
Regulation that implementing entities have to demonstrate compliance with.
8