Location via proxy:   [ UP ]  
[Report a bug]   [Manage cookies]                

What Is NESA Compliance - ValueMentor

Download as pdf or txt
Download as pdf or txt
You are on page 1of 5

2/9/2021 What is NESA Compliance - ValueMentor

U a

What is NESA Compliance

Home » What is NESA Compliance

NESA Compliance is mandated by Signals Intellegence Agency (SIA), earlier


known as NESA, on all critical information infrastructure operators in UAE

What does NESA Stands for?


NESA stands for National Electronic Security Authority. It is a federal authority in
United Arab emirates responsible for cyber security strategy of UAE.

Who must be NESA compliant?


NESA Compliance is mandated to all government organizations, semi-government 2
organizations and business organizations that are identi ed as critical
infrastructure to UAE.

What are the standards to follow to become NESA Compliant?

https://valuementor.com/blogs/nesa-compliance/what-is-nesa-compliance/ 1/5
2/9/2021 What is NESA Compliance - ValueMentor

The UAE National Cyber Security Strategy (NCSS), developed and governed by


NESA, de nes the protection requirements of UAE Cyberspace. The primary
standard to follow for NESA compliance is UAE Information Assurance Standards
(UAE IAS). Additionally, the NESA National Cyber Risk Management Framework
de nes the NESA Risk Assessment process.

What are the NESA Security Control Implementation timelines?

UAE IAS lists 188 security


controls in a prioritized approach. There are 4 priorities de ned and the controls
are grouped into these 4 priorities. NESA expects the entities to implement the
Priority 1 controls at the earliest. Controls from P2 to P4 to follow. Even though
there are no xed dates listed in the NESA documents, our experience indicates
that the P1 dates are nearby.

P1 Controls are mostly the management controls, with some technical security
requirements. From the 188 controls, NESA mandates 35 controls which help
entities in building the information security foundation. These controls are
required to be implemented by all the relevant entities, irrespective of the
outcome of the NESA Risk Assessment results.

How does NESA evaluate the compliance status?


According to the standards and based on the information, we receive from the
public domain, NESA would get involved through different approaches based on
the implementation level at the operator. 2
(a) Reporting: NESA would collect and consolidate the reports from entities to
generate sector and national risk contexts. These are based on the self-assessment
reports prepared by the critical national infrastructure entities

https://valuementor.com/blogs/nesa-compliance/what-is-nesa-compliance/ 2/5
2/9/2021 What is NESA Compliance - ValueMentor

(b) Auditing: One of our customers had retained us until the NESA audits are over.
This indicates that the NESA may audit, by means of requesting evidence, the
operator to validate some or all of the reported status of an entity.

(c) Testing:  The audits may be extended by testing speci c control


implementations at the operator.

Follow the service page to know more about our NESA Compliance service

Categories
Penetration Testing

PCI DSS Compliance

SWIFT CSP Assessment

NESA Compliance

ISO 27001 Consulting

Cloud Security

GDPR Compliance

Healthcare Cyber Security

ICS / SCADA / IOT

Managed Security

Incident Response

Case Studies

Contact us to know more about our


services
Full Name
2

Phone Number

https://valuementor.com/blogs/nesa-compliance/what-is-nesa-compliance/ 3/5
2/9/2021 What is NESA Compliance - ValueMentor

Company Name

Email Address

Message

Submit

COMPANY SERVICES

Company Overview PCI Certi cation


Leadership ISO 27001 Consulting
Careers GDPR Compliance
Blog SWIFT CSP Services
News & Events Penetration Testing
Case Studies Mobile App Security Testing

GLOBAL SERVICES STAY CONNECTED

Security Testing    
Payment Security
Cyber Risk Management REACH US

Managed Security
E-Mail: sales [at] valuementor.com
Cyber Engineering UAE: +971 – 567 24 5454
2
Managed Services USA: +1 409 210 2900
India : +91-974 5767 949

https://valuementor.com/blogs/nesa-compliance/what-is-nesa-compliance/ 4/5
2/9/2021 What is NESA Compliance - ValueMentor

ValueMentor © 2020 Terms of Services, Privacy Policy, Cookie Policy and Binding


Corporate Rules 

https://valuementor.com/blogs/nesa-compliance/what-is-nesa-compliance/ 5/5

You might also like