Laws & RegulationsNESA IAS (UAE)
In ForceCritical national infrastructure, Government, Energy, Finance, Telecommunications
NESA Information Assurance Standards (IAS)
Also known as: NESA IAS (UAE)
UAE's National Electronic Security Authority information assurance standards for critical national infrastructure. Establishes mandatory security controls across 18 domains for CNI operators, requiring annual compliance assessments and incident reporting.
Jurisdiction
United Arab Emirates
Regulator
—
Effective
1/1/2014
Sector
Critical national infrastructure, Government, Energy, Finance, Telecommunications
Full Text / Summary
The UAE's National Electronic Security Authority (NESA) Information Assurance Standards (IAS) establish the cybersecurity framework for UAE government entities and critical infrastructure operators. NESA IAS consists of two tiers: Tier 1 (mandatory controls for all entities) and Tier 2 (enhanced controls for critical entities). The standards cover 18 domains including: information security governance; risk management; asset management; human resources security; physical and environmental security; communications and operations management; access control; information systems acquisition, development, and maintenance; information security incident management; business continuity management; and compliance. UAE entities must achieve compliance with NESA IAS as a condition of operating in regulated sectors. The UAE Cybersecurity Council, established in 2020, has expanded the national cybersecurity framework and introduced the UAE Cybersecurity Strategy 2021-2026. NESA has been restructured under the Cybersecurity Council, which now coordinates cybersecurity policy across all federal entities.