Two things fix the shape of a UAE IA programme. The first is designation: the authority decides which entities are critical, so scope is not something you assess your way out of. The second is the split between the always applicable core, implemented whatever the risk assessment finds, and the remaining controls, which that assessment selects and every exclusion must justify. Once the applicable set is known, the four priority levels give the order, P1 first. Cost follows the same structure, and because the authority monitors compliance over time, the recurring number matters more than the first year. An existing ISO 27001 ISMS reduces both the build and the recurring cost, because the standard already covers much of the control set.
4 pages on UAE IA, in the order the work happens. Jump to the stage you are at, or read straight through.
Know whether designation puts you in scope, which controls apply whatever your risk assessment finds, and track the rest as a checklist with an owner, a status and evidence on each.
Budget the programme year on year, then judge platforms on whether they carry the P1 set through to evidence.
These sit under another subject but bear directly on UAE IA.
The free compliance check runs the UAE IA gap assessment in about five minutes and gives you a scored report you can take to a board meeting.
14-day free trial · no credit card · unlimited users