UAE Information Assurance Regulation
1.1 Background
The adoption of Information Technology (IT) and electronic communication have greatly
improved the efficiency and productivity of businesses and governments within the UAE, and
facilitated collaboration of individuals within the nation and across the globe. Undoubtedly,
IT and electronic communication have and will continue to play a pivotal role in the economic
development of the UAE and the daily life of its citizens. Therefore, the UAE stands committed
to the further development of its national IT and electronic communication infrastructure, as
well as its cyberspace, to support economic development and provide an environment where
the interests of its governments, businesses, and citizens can thrive.
The benefits of this technology adoption, however, come with a rapidly evolving set of cyber
threats. These threats stem from a wide range of sources – including hacktivists, issue-motivated
groups, and organized cybercrime syndicates – and represent national security concerns that
can potentially disrupt critical national services and compromise critical information assets.
Mitigating cyber threats, and ensuring the development of a secure national information and
communications infrastructure, and cyberspace, is a strategic priority for the UAE. To this end,
TRATRA developed the UAE IA Regulation as a critical element of the National Information
Assurance Framework (NIAF) to provide requirements for elevating the level of IA across all
implementing entities in the UAE.
The development of the UAE IA Regulation
is based on regional and global best practices including:
•
•
•
•
•
•
6
ISO/IEC 27001:2005 “Information technology — Security techniques — Information
security management systems — Requirements”,
ISO/IEC 27002:2005 “Information technology — Security techniques — Code of practice
for Information security management”,
ISO/IEC 27005:2005 “Information technology — Security techniques —Information
security risk management”
ISO/IEC 27010:2012 “Information technology — Security techniques — Information
security management for inter-sector and inter-organizational communications”
ISO/IEC 27032:2012 “Information technology — Security techniques — Guidelines for
cybersecurity”
NIST 800-53 Revision 4 “Security and Privacy Controls for Federal Information Systems
and Organizations”