Discover your OT Blind spots today! Get your free Executive Readiness Heatmap.

Contact Us
Close
Chat
Get In Touch

Get Immediate Help

Get in Touch!

Tell us what you need and we’ll connect you with the right specialist within 10 minutes.

  • Yes, I agree with the storage and handling of my data by this website, to receive periodic emails from microminder cybersecurity related to products and services and can unsubscribe at any time. By proceeding, you consent to allow microminder cybersecurity to store and process the personal information submitted above to provide you the content requested. I accept microminder's Privacy Policy.*

  • This site is protected by reCAPTCHA.

Thank You

Thank you

We appreciate your interest in our cybersecurity services! Our team will review your submission and reach out to you soon to discuss next steps.

UK: +44 (0)20 3336 7200
UAE: +971 454 01252
KSA: +966 1351 81844

4.9 Microminder Cybersecurity

310 reviews on

Trusted by 2600+ Enterprises & Governments

Trusted by 2600+ Enterprises & Governments

Contact the Microminder Team

Need a quote or have a question? Fill out the form below, and our team will respond to you as soon as we can.

What are you looking for today?

Managed security Services

Managed security Services

Cyber Risk Management

Cyber Risk Management

Compliance & Consulting Services

Compliance & Consulting Services

Cyber Technology Solutions

Cyber Technology Solutions

Selected Services:

Request for

  • Yes, I agree with the storage and handling of my data by this website, to receive periodic emails from microminder cybersecurity related to products and services and can unsubscribe at any time. By proceeding, you consent to allow microminder cybersecurity to store and process the personal information submitted above to provide you the content requested. I accept microminder's Privacy Policy.*

  • This site is protected by reCAPTCHA.

Thank You

Thank you

In the meantime, please help our team scope your requirement better and to get the right expert on the call by completing the below section. It should take 30 seconds!

30 seconds!

Untick the solutions you don’t need

  • Untick All
  • Untick All
  • Untick All
  • Untick All
Thank You

What happens next?

Thanks for considering us for your cybersecurity needs! Our team will review your submission and contact you shortly to discuss how we can assist you.

01

Our cyber technology team team will contact you after analysing your requirements

02

We sign NDAs for complete confidentiality during engagements if required

03

Post a scoping call, a detailed proposal is shared which consists of scope of work, costs, timelines and methodology

04

Once signed off and pre-requisites provided, the assembled team can commence the delivery within 48 hours

05

Post delivery, A management presentation is offered to discuss project findings and remediation advice

Home  Resources  Blogs  ADHICS Control Checklist for Abu Dhabi Health Entities

ADHICS Control Checklist for Abu Dhabi Health Entities

 
Lorna Jones

Lorna Jones, Senior Cyber Security Consultant
Sep 15, 2026

  • LinkedIn

This page provides a working, domain-by-domain control checklist for ADHICS compliance, covering the five domains confirmed directly against the current published standard: Human Resources Security, Asset Management, Physical and Environmental Security, Access Control, and Communications and Operations Management. Use it to self-assess before commissioning a formal gap assessment. It summarises the standard rather than replacing it, and the published standard itself remains the authoritative source.

Key Takeaways

Before working through the checklist, a few points shape how to use it.

  • This checklist covers five of ADHICS's domains in full detail, drawn directly from the current published standard text, not from third-party summaries.
  • Auditors fail entities on evidence far more often than on missing controls, so the evidence column matters as much as the control itself.
  • A five-point maturity scale, from not implemented through to operating and reviewed, gives a practical way to score each control area honestly.
  • Several controls in the Communications and Operation Management domain, including annual vulnerability assessment and penetration testing, are among the most commonly missed in practice.
  • Self-assessment is a starting point, not a substitute for a formal gap assessment once genuine implementation work begins.


Working through the checklist domain by domain, rather than control by control, tends to produce a more usable picture of where an entity actually stands.

Using This ADHICS Control Checklist

ADHICS compliance work usually starts with good intentions and a vague sense of where the gaps are. A structured checklist replaces that vague sense with a domain-by-domain view, letting a compliance lead or CISO score current practice honestly before committing budget to a formal engagement. For background on what ADHICS is, who it binds, and how the audit and submission process works, our ADHICS compliance guide covers that ground; this page assumes that context and moves straight to the practical checklist.

This checklist is not exhaustive. It summarises the confirmed control requirements across five domains rather than replicating the full standard, and it does not replace the judgement of a qualified compliance professional or the authority of the published standard itself.

How to Score Each Control

A consistent scoring approach turns a checklist from a read-once document into something a compliance team can revisit and track progress against over time.

  • Not implemented — the control does not exist in any form.
  • Partially implemented — some elements are in place, but the control is incomplete against the standard's stated demands.
  • Implemented but not evidenced — the control operates in practice, but no record proves it.
  • Implemented and evidenced — the control operates and produces a documented record an auditor could review.
  • Operating and reviewed — the control operates, is evidenced, and is periodically reviewed for continued effectiveness.


"Implemented but not evidenced" is the rating that causes most audit findings in practice. A password policy that genuinely exists and is genuinely enforced still fails an audit if nobody can produce the record showing when it was last reviewed or who approved it. Treating evidence as part of the control, not an afterthought once the control exists, is the single habit that prevents the most audit friction later. Our business security audits guide covers this evidence-gathering discipline in more general terms, beyond ADHICS specifically.

The Control Checklist by Domain

The checklist below follows the domain structure of the current standard for the five domains confirmed directly against the published text. Entities should filter by their own classification tier, since not every control in every domain applies at Basic level.

Human Resources Security

This domain covers the security aspects of hiring, employing, and exiting staff, contractors, and third-party users, treating people as both an asset and a risk surface that needs the same deliberate control as any technical system.


Control areaWhat you must have in placeEvidence auditors expectYour rating
HR security policyA documented policy covering recruitment, employment, and termination security requirementsSigned, version-controlled policy document
Background verificationBackground checks for all employees, contractors, and third-party users before access is grantedVerification records for every in-scope individual
Terms of employmentContracts including security responsibilities, NDA, and disciplinary termsSigned contracts and NDAs on file
Security awareness trainingOnboarding and periodic awareness training for all staffTraining completion records and attendance logs
Role-based trainingTraining specific to elevated-risk roles before system access is grantedRole-specific training records tied to access grants
Disciplinary processA defined process for security breaches by staffDocumented disciplinary actions where breaches occurred
Exit and access revocationAccess removed within 24 hours of termination, assets recoveredExit clearance forms and access revocation logs

The most common gap in this domain is not the policy itself but the exit process: many entities can show a hiring checklist but cannot produce evidence that access was actually revoked within the required 24-hour window for every departure in the past year.

Asset Management

This domain covers how an entity identifies, classifies, handles, and eventually disposes of its information assets, including the medical devices and equipment that carry particular weight under ADHICS specifically.

Control areaWhat you must have in placeEvidence auditors expectYour rating
Asset management policyA documented policy covering ownership, classification, and retentionSigned policy referencing the standard's classification scheme
Asset inventoryA complete, current inventory of all information assets, including medical devicesAn up-to-date, centrally accessible inventory
Asset ownershipA named owner assigned to every identified assetOwnership records mapped to the inventory
Classification and labellingEvery asset classified per the standard's four-tier scheme (Public, Restricted, Confidential, Secret)Classification records aligned to the inventory
BYOD controlsAn authorisation process for personal devices accessing entity dataBYOD usage agreements signed by users
Secure disposalControls ensuring disposed assets cannot be recoveredDisposal records naming owner, method, and authorisation

Medical device inventory is where this domain most often falls short in practice. General IT asset inventories tend to be reasonably mature; a linked inventory that also covers medical devices and equipment, redacted of patient information, is far less commonly in place.

Physical and Environmental Security

This domain covers protecting the facilities, secure areas, and equipment that support information processing, from access control at the door to environmental protections like fire suppression and power backup.

Control areaWhat you must have in placeEvidence auditors expectYour rating
Physical security policyA documented policy addressing secure storage and physical protectionSigned policy covering internal and external threats
Secure area accessDefined security perimeters with authorised-only accessAccess logs and authorised personnel lists

Visitor and CCTV controlsVisitor logs and CCTV coverage at vantage points in secure areasRetained CCTV footage and visitor logs
Equipment siting and protectionMedical devices and equipment positioned and protected appropriatelyDocumented equipment placement guidelines
Environmental controlsFire suppression, detection, and temperature/humidity monitoring for data centresMaintenance and testing records for environmental systems
Off-site equipment protectionAuthorisation and chain-of-custody controls for equipment taken off-siteMovement and possession logs

Access records and CCTV footage retention are the two evidence types most often missing here, even where the physical controls themselves, locks, badges, cameras, are genuinely in place.

Access Control

This domain governs who can reach entity systems, applications, and medical devices, and under what conditions, spanning password policy through to network-level access restrictions.
Control areaWhat you must have in placeEvidence auditors expectYour rating
Access control policyA documented policy covering granting, review, and revocation of accessSigned policy addressing role-based access principles

Password complexityMinimum 12 characters, mixed case, number, and special character; 5-attempt lockout; 3-password historyTechnical configuration evidence from system settings
User access managementFormal registration and de-registration process with unique accounts per userUser account creation and deactivation records
Privileged access controlsMulti-factor authentication for privileged, administrative, and remote accessMFA configuration evidence and privileged account inventory
Access reviewsAccess and privileges reviewed at least annuallyAnnual access review records
Network access controlControlled, authenticated access to network services and remote channels
Network access logs and authentication configuration
Wireless securityInternal wireless not broadcast, trusted-device-only accessWireless configuration and authorisation records

Annual access review is the control most often found "implemented but not evidenced": the review happens informally, but no dated record exists showing who was reviewed, by whom, and when.

Communications and Operation Management

This is the largest of the five confirmed domains, covering the day-to-day technical operation of systems: change management, malware protection, backup, logging, patch management, and technical security testing.

Control areaWhat you must have in placeEvidence auditors expectYour rating
Change managementA Change Advisory Board and documented change approval processChange records with approval, testing, and rollback evidence
Malware protectionAnti-malware deployed and current across servers, workstations, and mobile devicesDeployment coverage reports and update logs
Backup and restorationRegular backups with periodically tested restorationBackup logs and documented restoration test results
Logging and monitoringCentralised, protected logging with defined alerting and escalation criteriaLog retention records and alert response evidence
Annual VAPTYearly vulnerability assessment and penetration testing of systems, web/mobile applications, and connected medical devicesTesting reports, remediation tracking, and revalidation results
Patch managementFormal, prioritised patching with critical patches applied promptlyPatch deployment and validation records
Data leakage preventionDLP controls to prevent unauthorised loss of health informationDLP deployment and incident records
Information exchange controlsSecure exchange procedures, with health information not leaving the UAE without DoH exemptionData flow documentation and cross-border exemption records, where applicable

The annual VAPT requirement is worth flagging on its own: it is stated directly and unambiguously in the standard, yet it is one of the controls most commonly found missing entirely rather than simply under-evidenced, since organisations without an established testing programme often have not commissioned any structured penetration test at all. Our enterprise penetration testing guide and vulnerability assessment service cover how to scope this specific obligation.

Where Health Entities Most Often Fall Short

Across the five domains above, certain gap patterns recur consistently enough to call out directly rather than leave scattered through the checklist.

  1. Evidence retention, not control existence, is the single biggest audit risk. A control that operates informally without a dated record is functionally the same as a control that does not exist, from an auditor's perspective.
  2. Medical device coverage lags general IT coverage across asset management, access control, and testing alike, since device inventories and patching regimes often grew up separately from the main IT estate.
  3. Third-party and supplier evidence tends to be the thinnest area across every domain that touches vendors, since entities often assume a supplier's own security posture is "good enough" without documenting why.
  4. Annual cadence controls, access reviews and VAPT specifically are easy to let slip past their due date without a formal tracking mechanism.
  5. Staff awareness records exist for onboarding far more consistently than for the ongoing, periodic campaigns the standard also requires.


Sequencing remediation against these patterns, rather than working alphabetically through the checklist, tends to close the highest-risk gaps first.

Moving From Self-Assessment to a Formal Gap Assessment

Self-assessment against this checklist gives an honest internal picture, but it is not the same as a formal gap assessment. A formal assessment brings independent judgement to bear on ratings an internal team might score generously, tests evidence against actual audit expectations rather than internal assumptions, and produces a prioritised remediation plan with realistic timelines rather than a simple pass or fail per control.
The right moment to commission one is once self-assessment surfaces enough "not implemented" or "partially implemented" ratings that a structured remediation programme, rather than ad hoc fixes, becomes the more efficient path forward. Our enterprise cyber risk management service covers this kind of structured assessment work in more depth. This checklist offers general guidance and does not replace the published ADHICS standard, which remains the authoritative source for any specific compliance decision.

Don’t Let Cyber Attacks Ruin Your Business

  • Certified Security Experts: Our CREST and ISO27001 accredited experts have a proven track record of implementing modern security solutions
  • 41 years of experience: We have served 2600+ customers across 20 countries to secure 7M+ users
  • One Stop Security Shop: You name the service, we’ve got it — a comprehensive suite of security solutions designed to keep your organization safe

To keep up with innovation in IT & OT security, subscribe to our newsletter

FAQs

How many controls does ADHICS contain?

692 controls across 11 domains, per the Department of Health's own published guidance.

Do all ADHICS controls apply to every health entity?

No. Applicability depends on entity type and, for hospitals, bed capacity, across four control categories.

What evidence do ADHICS auditors ask for?

Dated, verifiable records: policies, logs, training completions, and test results tied to each control.

What is an ADHICS gap assessment?

An independent review identifying where current practice falls short of the standard. See our enterprise cyber risk management service.

How often should we review ADHICS controls?

At least annually for access reviews and VAPT specifically; more often where the risk environment changes.

What is the difference between ADHICS V1 and V2?

V2 consolidated three earlier standards into one framework. See our ADHICS compliance guide.

Can we self-assess ADHICS compliance?

Yes, as a starting point. See our vulnerability assessment service for the technical testing that a self-assessment cannot replace.
692 controls across 11 domains, per the Department of Health's own published guidance.
No. Applicability depends on entity type and, for hospitals, bed capacity, across four control categories.
Dated, verifiable records: policies, logs, training completions, and test results tied to each control.
An independent review identifying where current practice falls short of the standard. See our enterprise cyber risk management service.
At least annually for access reviews and VAPT specifically; more often where the risk environment changes.
V2 consolidated three earlier standards into one framework. See our ADHICS compliance guide.
Yes, as a starting point. See our vulnerability assessment service for the technical testing that a self-assessment cannot replace.