UAE Information Assurance Regulation 1.3 Layout of the UAE IA Regulation This section provides an overview of the layout of the UAE IA Regulation to guide the readability of this document. Overall, the UAE IA Regulation is composed of seven chapters: • Chapter 1: Introduction: This chapter outlines TRA’s rationale for developing the UAE IA Regulation and provides an overview of the document layout. • Chapter 2: UAE IA Regulation Overview: This chapter outlines the scope of the document and describes the relationship of the UAE IA Regulation with other national cyber security program documents published by TRA (e.g. UAE CIIP Policy). This chapter also describes how information assurance requirements are addressed at the national, sector, and entity levels following a lifecycle approach to progress the adoption and evolution of information assurance in the UAE. • Chapter 3: UAE IA Regulation Implementation: This chapter outlines the implementation guidance for entities applying the UAE IA Regulation. To help guide the implementation of these , this chapter also provides an overview of the risk-based approach for the identification of applicable controls to be implemented in order to address risks in a manner commensurate with their potential impact. Moreover, this chapter outlines the roles and responsibilities of key stakeholders to provide clarity on how to plan, develop, implement, monitor, improve, and report on the implementation of these . Lastly, this chapter concludes by outlining critical success factors for the effective implementation of these . • Chapter 4: Compliance with the UAE IA Regulation: This chapter provides a definition of compliance with respect to the requirements of these , and outlines the approach that TRA will follow when evaluating compliance. 9

Select target paragraph3