The national information assurance standard applying to entities within the United Arab Emirates critical information infrastructure.
Entities designated as critical information infrastructure, and organisations in sectors where the standard is applied by a sector regulator. Suppliers to those entities are frequently required to demonstrate alignment as a contractual condition.
The control set overlaps substantially with ISO 27001, which is why organisations holding ISO 27001 usually start from a strong position. The overlap is not equivalence: NESA carries national assurance expectations that ISO 27001 does not address, and those obligations must be met on their own terms.
Compliance assessed against the national standard, evidenced to the relevant authority or sector regulator.
SecureEdge Advisory prepares you and facilitates the process. The affirmation is made by an external auditor, a certification body or the regulator, never by us.
Control mappings exist between this framework and others in the library, so evidence gathered here may support work elsewhere. Mappings are published as draft, and a mapping shows a relationship rather than satisfied coverage. An auditor decides whether the evidence answers the requirement.