Discover your OT Blind spots today! Get your free Executive Readiness Heatmap.

Contact Us
Close
Chat
Get In Touch

Get Immediate Help

Get in Touch!

Tell us what you need and we’ll connect you with the right specialist within 10 minutes.

  • Yes, I agree with the storage and handling of my data by this website, to receive periodic emails from microminder cybersecurity related to products and services and can unsubscribe at any time. By proceeding, you consent to allow microminder cybersecurity to store and process the personal information submitted above to provide you the content requested. I accept microminder's Privacy Policy.*

  • This site is protected by reCAPTCHA.

Thank You

Thank you

We appreciate your interest in our cybersecurity services! Our team will review your submission and reach out to you soon to discuss next steps.

UK: +44 (0)20 3336 7200
UAE: +971 454 01252
KSA: +966 1351 81844

4.9 Microminder Cybersecurity

310 reviews on

Trusted by 2600+ Enterprises & Governments

Trusted by 2600+ Enterprises & Governments

Contact the Microminder Team

Need a quote or have a question? Fill out the form below, and our team will respond to you as soon as we can.

What are you looking for today?

Managed security Services

Managed security Services

Cyber Risk Management

Cyber Risk Management

Compliance & Consulting Services

Compliance & Consulting Services

Cyber Technology Solutions

Cyber Technology Solutions

Selected Services:

Request for

  • Yes, I agree with the storage and handling of my data by this website, to receive periodic emails from microminder cybersecurity related to products and services and can unsubscribe at any time. By proceeding, you consent to allow microminder cybersecurity to store and process the personal information submitted above to provide you the content requested. I accept microminder's Privacy Policy.*

  • This site is protected by reCAPTCHA.

Thank You

Thank you

In the meantime, please help our team scope your requirement better and to get the right expert on the call by completing the below section. It should take 30 seconds!

30 seconds!

Untick the solutions you don’t need

  • Untick All
  • Untick All
  • Untick All
  • Untick All
Thank You

What happens next?

Thanks for considering us for your cybersecurity needs! Our team will review your submission and contact you shortly to discuss how we can assist you.

01

Our cyber technology team team will contact you after analysing your requirements

02

We sign NDAs for complete confidentiality during engagements if required

03

Post a scoping call, a detailed proposal is shared which consists of scope of work, costs, timelines and methodology

04

Once signed off and pre-requisites provided, the assembled team can commence the delivery within 48 hours

05

Post delivery, A management presentation is offered to discuss project findings and remediation advice

Home  Resources  Blogs  NESA IAR Checklist: Mapping Controls to the UAE Information Assurance Standard

NESA IAR Checklist: Mapping Controls to the UAE Information Assurance Standard

 
Sanjiv Cherian

Sanjiv Cherian, Chief Commercial Officer
Sep 16, 2026

  • LinkedIn

The UAE Information Assurance Regulation, administered through the UAE Information Assurance Standard, organises its requirements into 15 control families: six Management families and nine Technical families. Version 2, effective from September 2025, rebased the standard onto ISO 27001:2022 and introduced explicit priority tagging for every control. This checklist works through the confirmed family structure and gives a practical starting point for self-assessment before a formal gap assessment.

Key Takeaways

Before working through the checklist, these points shape how to use it.

  • The standard organises 15 control families: six Management (M1–M6) and nine Technical (T1–T9).
  • Every control carries a priority tag, from P1 (mandatory) through P4 (risk-based), which determines implementation sequencing.
  • Version 2, effective September 2025, rebased the framework onto ISO 27001:2022 and added seven new National Security Policy annexes covering areas like cloud, AI/ML, and IoT.
  • P1 controls across access control, patch management, and incident management are among the most commonly found gaps in practice.
  • This checklist summarises the family structure rather than replicating every control; the published standard remains the authoritative source.


Working through the checklist family by family gives a more usable picture than treating individual controls in isolation.

Using This UAE Information Assurance Regulation Checklist

The UAE Information Assurance Regulation is administered through the UAE Information Assurance Standard, and organisations pursuing NESA alignment work from that standard's control structure directly. For background on what the regulation is, who it binds, and how NESA relates to other UAE frameworks, our NESA compliance guide covers that ground; this page moves straight to the practical checklist rather than re-explaining the regulation itself.

This checklist works through the standard's 15 control families, giving a practitioner a structured way to self-assess before committing budget to a formal engagement. It is not exhaustive, and it does not replace the judgement of a qualified compliance professional or the authority of the published standard.

How the Control Families Are Organised

The standard splits its requirements into two categories: Management controls, addressing governance, strategy, and organisational accountability, and Technical controls, addressing the operational and technical measures that implement that governance in practice.

  • M1: Strategy and Planning — the organisation's information security strategy and its alignment with business objectives.
  • M2: Information Security Risk Management — the risk identification, assessment, and treatment framework.
  • M3: Awareness and Training — security awareness programmes across the organisation.
  • M4: Human Resource Security — security requirements across the employment lifecycle.
  • M5: Compliance — legal, regulatory, and internal policy compliance management.
  • M6: Performance Evaluation and Improvement — measuring and improving the security programme over time.
  • T1: Information Asset Management — asset inventory and classification.
  • T2 through T4 — network security, cryptography, and physical security controls.
  • T5: Patch Management — timely patching of systems and applications.
  • T6: Incident Management — detection, response, and reporting of security incidents.
  • T7 and T8 — secure system development and third-party security.
  • T9: Information Systems Continuity Management — business continuity and disaster recovery.


Every control within these 15 families carries a priority tag, P1 through P4, with P1 controls mandatory regardless of risk assessment outcome and P2 through P4 applied based on an entity's specific risk profile. This priority tiering, not the family structure alone, is what actually determines implementation order for most organisations.

The Control Checklist by Family

The checklist below covers six of the fifteen families in working detail, drawn from confirmed control examples within the current standard. The remaining nine families are named accurately above but are not expanded into full checklist tables here, since doing so responsibly requires the full published standard rather than secondary description.

M1: Strategy and Planning

This family establishes the organisational strategy that everything else in the standard builds on, requiring visible senior leadership commitment rather than a standalone IT document.


Control areaWhat you must have in placeEvidence auditors expectYour rating
Information Security Strategy (M1-P1)A senior-leadership-approved strategy aligning security investment with business objectivesSigned, dated strategy document with leadership sign-off
Strategic alignment reviewPeriodic review confirming the strategy still reflects current business prioritiesReview records showing update cadence

A strategy document that exists but was never formally approved by senior leadership is a common gap: the content may be sound, but the accountability chain the standard requires is missing.

M2: Information Security Risk Management

This family requires a repeatable, documented process for identifying and treating risk, not a one-time exercise completed and then left unrevised.
Control areaWhat you must have in placeEvidence auditors expectYour rating
Risk Management Framework (M2-P1)A documented, repeatable process for identifying, analysing, and treating riskFramework document plus evidence of actual application
Live risk registerA risk register updated as the environment changes, not a static annual documentDated risk register entries showing periodic reassessment

Treating the risk register as a document produced once for an audit, rather than a living record updated after infrastructure changes or new deployments, is the most common gap in this family in practice.

M3: Awareness and Training

This family requires documented, mandatory security awareness training across the organisation, with evidence that staff actually understand their role in protecting information assets.


Control areaWhat you must have in placeEvidence auditors expectYour rating
Security Awareness Training (M3-P1)Mandatory training for all personnel, documented and trackedTraining completion records and attendance logs
Role-specific awarenessAdditional awareness content for higher-risk rolesRole-mapped training records

Generic, one-size-fits-all training that satisfies the letter of the requirement but does not reflect actual role-based risk tends to draw scrutiny during assessment. Our vulnerability assessment service covers the technical side of the risk picture this training is meant to support.

T1: Information Asset Management

This family requires a comprehensive, current inventory of hardware and software assets, plus classification of data according to its criticality.

Control areaWhat you must have in placeEvidence auditors expectYour rating
Asset inventory (T1-P1)A comprehensive hardware and software asset inventoryCurrent, centrally accessible inventory
Data classification (T1.2)Data classified according to criticality, with appropriate rigour for higher classificationsClassification records and labelling evidence
Access control hygieneNo orphaned accounts, privileged access reviewed regularly, MFA enforced for remote accessAccess review records and MFA configuration evidence

Orphaned accounts belonging to former staff or contractors, and privileged accounts reviewed only annually rather than quarterly, are consistently among the most frequently identified gaps in this family across UAE assessments.

T5: Patch Management

A P1 family, meaning every organisation implements it regardless of risk profile, and the standard expects a documented, evidenced process rather than ad hoc patching.

Control areaWhat you must have in placeEvidence auditors expect
Your rating
Critical patch SLA (T5-P1)A documented service level for applying critical patchesPatch deployment records against the stated SLA
Patch completion trackingRecorded completion dates and documented exceptions where patches are delayedPatch logs showing dates and exception justifications

The absence of a documented SLA for critical patches, with patches applied ad hoc and no recorded completion evidence, is one of the most consistently identified P1 gaps in practice.

T6: Incident Management

Also a P1 family, requiring a genuinely exercised incident response capability rather than a plan that exists only on paper.

Control areaWhat you must have in placeEvidence auditors expectYour rating
Incident response plan (T6-P1)A documented, exercised incident response planRecords of tabletop exercises or live incident drills
Incident logA maintained log of security incidents, however minorA current, dated incident log

An incident response plan that exists but has never been exercised, alongside no maintained incident log, is a recurring finding at exactly the family the standard treats as mandatory. Our enterprise penetration testing guide and incident response guide both cover the technical work that typically feeds this family's evidence base.

Sequencing Implementation by Priority

Priority tiering exists specifically to stop organisations from working through the standard alphabetically or by whichever family feels easiest, which tends to leave the mandatory P1 controls under-resourced while effort goes toward lower-priority items first. Entities that sequence by priority, closing every P1 gap across both Management and Technical families before addressing P2 through P4 items, generally reach a defensible compliance position faster and with less wasted effort than those working family by family in document order.
Budget is the practical reason this matters. Organisations that spread implementation evenly across all 15 families often run out of budget or momentum before reaching the controls that actually carry mandatory weight, leaving the highest-consequence gaps unresolved while lower-priority items are fully implemented.

Mapping NESA Controls to ISO 27001

Entities frequently pursue NESA alignment and ISO 27001 certification simultaneously, and Version 2's rebasing onto ISO 27001:2022 specifically increases the practical overlap between the two.
AreaISO 27001 Annex AUAE IAR
GovernanceOrganisational controlsM1: Strategy and Planning
Risk managementRisk assessment and treatmentM2: Information Security Risk Management
Asset managementAsset management controlsT1: Information Asset Management
Access controlDedicated Annex A domainEmbedded within T1 and related technical families
Incident managementIncident management controlsT6: Incident Management
Business continuityBusiness continuity controlsT9: Information Systems Continuity Management
Supplier securitySupplier relationship controlsAddressed within the Technical family set (T7/T8 area)

An organisation already holding ISO 27001 certification carries genuine efficiency into NESA alignment specifically because Version 2 deliberately rebased onto the current ISO 27001:2022 control structure, narrowing the gap between the two frameworks considerably compared to the earlier version of the standard.

Preparing for a NESA Assessment

Preparation follows a fairly predictable sequence once an organisation has confirmed its scope and criticality designation under the regulation.

  1. Confirm scope and criticality designation, establishing whether the organisation is mandated or voluntarily aligning.
  2. Complete a self-assessment against this checklist and the full published family structure.
  3. Close priority gaps first, working through P1 controls across both Management and Technical families before lower priorities.
  4. Assemble evidence for every control claimed as implemented, not just the control itself.
  5. Run an internal review before booking any external assessment.
  6. Book the assessment, allowing realistic time for evidence gathering rather than compressing it against a fixed deadline.


This article provides general guidance on the UAE Information Assurance Standard's structure and does not constitute legal or compliance advice; the current published standard remains the authoritative source for any specific compliance decision.

Don’t Let Cyber Attacks Ruin Your Business

  • Certified Security Experts: Our CREST and ISO27001 accredited experts have a proven track record of implementing modern security solutions
  • 41 years of experience: We have served 2600+ customers across 20 countries to secure 7M+ users
  • One Stop Security Shop: You name the service, we’ve got it — a comprehensive suite of security solutions designed to keep your organization safe

FAQs

What does NESA IAR stand for?

The UAE Information Assurance Regulation, historically associated with the National Electronic Security Authority (NESA).

Who must comply with the UAE Information Assurance Regulation?

Federal and local government entities, semi-government bodies, and critical information infrastructure operators. See NESA compliance.

How many controls does the IAR contain?

The prior version held 188 controls across 15 families; Version 2 restructured the framework with explicit priority tagging per control.

What is control prioritisation in the IAR?

Every control carries a P1 (mandatory) to P4 (risk-based) tag, determining implementation sequence.

Does ISO 27001 cover NESA requirements?

Substantial overlap exists, especially since Version 2 was rebased onto ISO 27001:2022. See ISO 27001 certification.

What evidence do NESA assessors ask for?

Dated, verifiable records tied to each control: policies, training logs, patch records, and incident documentation.

How often is a NESA assessment required?

Cadence varies by entity designation; P1 controls in particular expect ongoing, not one-time, evidence.
The UAE Information Assurance Regulation, historically associated with the National Electronic Security Authority (NESA).
Federal and local government entities, semi-government bodies, and critical information infrastructure operators. See NESA compliance.
The prior version held 188 controls across 15 families; Version 2 restructured the framework with explicit priority tagging per control.
Every control carries a P1 (mandatory) to P4 (risk-based) tag, determining implementation sequence.
Substantial overlap exists, especially since Version 2 was rebased onto ISO 27001:2022. See ISO 27001 certification.
Dated, verifiable records tied to each control: policies, training logs, patch records, and incident documentation.
Cadence varies by entity designation; P1 controls in particular expect ongoing, not one-time, evidence.