UAE Information Assurance Regulation 1.1 Background The adoption of Information Technology (IT) and electronic communication have greatly improved the efficiency and productivity of businesses and governments within the UAE, and facilitated collaboration of individuals within the nation and across the globe. Undoubtedly, IT and electronic communication have and will continue to play a pivotal role in the economic development of the UAE and the daily life of its citizens. Therefore, the UAE stands committed to the further development of its national IT and electronic communication infrastructure, as well as its cyberspace, to support economic development and provide an environment where the interests of its governments, businesses, and citizens can thrive. The benefits of this technology adoption, however, come with a rapidly evolving set of cyber threats. These threats stem from a wide range of sources – including hacktivists, issue-motivated groups, and organized cybercrime syndicates – and represent national security concerns that can potentially disrupt critical national services and compromise critical information assets. Mitigating cyber threats, and ensuring the development of a secure national information and communications infrastructure, and cyberspace, is a strategic priority for the UAE. To this end, TRATRA developed the UAE IA Regulation as a critical element of the National Information Assurance Framework (NIAF) to provide requirements for elevating the level of IA across all implementing entities in the UAE. The development of the UAE IA Regulation is based on regional and global best practices including: • • • • • • 6 ISO/IEC 27001:2005 “Information technology — Security techniques — Information security management systems — Requirements”, ISO/IEC 27002:2005 “Information technology — Security techniques — Code of practice for Information security management”, ISO/IEC 27005:2005 “Information technology — Security techniques —Information security risk management” ISO/IEC 27010:2012 “Information technology — Security techniques — Information security management for inter-sector and inter-organizational communications” ISO/IEC 27032:2012 “Information technology — Security techniques — Guidelines for cybersecurity” NIST 800-53 Revision 4 “Security and Privacy Controls for Federal Information Systems and Organizations”

Select target paragraph3