← All frameworks
GCC GCC · 8 Policy & Process · UAE (Abu Dhabi)

ADHICS

Abu Dhabi Healthcare Information & Cyber Security Standard

v2 (2024)

47 controls · 11 domains · 131 sub-controls
Mandatory for: Abu Dhabi healthcare entities
Start assessment in platform →

About this framework

ADHICS v2 is Abu Dhabi's cybersecurity standard for healthcare, issued by the Department of Health. It sets the controls for protecting patient data and health information systems across governance, assets and operations. Version 2, effective from August 2024, significantly expands the 2019 original — adding domains for AI governance, IoMT (Internet of Medical Things) security, and cloud healthcare controls — and applies a tiered model so smaller clinics implement a proportionate subset.

Why it matters

Healthcare data is among the most sensitive an organisation can hold, and Abu Dhabi treats it accordingly: ADHICS compliance is a condition of operating as a DoH-regulated healthcare entity. But beyond licensing, the standard reflects a real duty of care — patients trust providers with information that cannot be un-leaked. ADHICS v2's new IoMT and cloud domains acknowledge how modern care actually runs. 786 Cyber maps the controls to your tier and keeps the evidence ready, so protecting patient data and keeping your licence are the same piece of work.

Who needs this

Mandatory for all DoH-regulated healthcare entities in Abu Dhabi — facilities, professionals, diagnostic labs, pharmacies, payers and insurers, and any party handling patient health data.

The control structure

  1. Governance Security strategy, roles, risk management and compliance.
  2. Asset & access management Protecting health information systems and controlling who can reach patient data.
  3. Operations & resilience Secure operations, incident handling and continuity.
  4. Third-party & cloud Supplier security and cloud healthcare controls.
  5. Emerging-technology domains AI governance and IoMT (medical device) security. Controls are applied by tier — Basic / Transitional / Advanced — based on entity size and criticality.

How 786 Cyber helps

Cross-framework coverage

Controls in ADHICS also cover:

NCA ECC-2 22 shared
Qatar NIA 22 shared
ISO 27001 21 shared
UAE IA 21 shared
CJIS 20 shared

See how ADHICS connects to the rest → the Security Universe

Control domains

HR · Human Resources Security 4
HR 1
Human Resources Security Policy
Signed/approved HR security policy; version & review date; distribution record.
Do you have an approved HR security policy covering recruitment, employment and termination for staff, contractors and third parties?
1 sub-control
  • HR 1.1 The entity shall develop, enforce, and maintain a human resources security policy covering the security aspects of recruitment, employment and termination of employees, contractors The entity shall develop, enforce, and maintain a human resources security policy covering the security aspects of recruitment, employment and termination of employees, contractors and third-party users The policy shall: 1. Define management requirements on. a) Background verification for employees, contractors, and third-party users b) Roles and responsibilities c) Compliance with acceptable usage and other organizational security policies d) Training and awareness needs e) Return of assets during exit 2. Mandate the requirements of non -disclosure and confidentiality during and after employment. 3. Include reference to organizational disciplinary process Basic 28 UAE IAR Reference: M3.1.1, M4.1.1
CJISCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
HR 2
Prior to Employment
Background-check procedure & sample results; employment contract template with security/NDA clauses.
Are background checks completed before hiring, and do contracts include security responsibilities and confidentiality terms?
2 sub-controls
  • HR 2.1 The entity shall ensure background verification checks are conducted for all candidates for employment, contractors and third-party users The entity shall ensure background verification checks are conducted for all candidates for employment, contractors and third-party users. The entity shall: 1. Define background verification process addressing provisions of government mandates and entity demands 2. Establish criteria for background verification checks based on: a) Role of the individual b) Levels of information access needed c) Access to critical areas d) Risks identified for the role 3. Conduct background verification of its candidates for employment (Permanent employees) 4. Ensure that it receives background verification reports for contractors and third -party users from responsible government bodies/agencies, through their respective company 5. Thoroughly validate the background verification report provided by the third-party prior to granting them access to entity resources or environment 6. Define information security requirements in the Job Descriptions, as required Basic 29
  • HR 2.2 The entity shall establish specific terms and condition of employment as part of the employment contract The entity shall: 1. Include control requirement specific to employees, con The entity shall establish specific terms and condition of employment as part of the employment contract The entity shall: 1. Include control requirement specific to employees, contractors and third parties, relevant to their roles and risk profiles. 2. Include information security responsibilities of the entity and of the employees, contractors and third parties. 3. Ensure employees sign a Non-disclosure Agreement (NDA) with the entity, as required. 4. Ensure the contract includes disciplinary action in case of violation or non-compliance with the information security requirements of the entity. 5. Ensure the Terms and conditions are read, understood, agreed and signed by employees, contractors and third parties. 6. Conduct mandatory briefing sessions to employees, contractors and third parties on standard and specific information and cyber security requirements of the terms and condition. 7. Maintain adequate records on employee, contractor and third-party briefing(s) 8. Maintain Terms and Conditions, Non -disclosure Agreement ( NDA) signed by employee, contractor and third-party resources in -line with entity retention requirements 9. Review and update any existing contract with employees, contractors and third-party users, as required Basic UAE IAR Reference: M4.2.1, M4.2.2 30
NCA ECC-2NCA OTCCNIS2Qatar NIAUAE IAISO 27001NCA CCCPCI DSS 4.0.1SAMA CSF
HR 3
During Employment
Awareness campaign schedule & attendance logs; role-based training records; disciplinary procedure.
Do staff receive security & privacy awareness and role-based training on a defined schedule, with a disciplinary process for breaches?
5 sub-controls
  • HR 3.1 The entity management shall ensure employees, contractors and third-party users adopt and apply security in accordance with established entity policies and procedures The entity management shall ensure employees, contractors and third-party users adopt and apply security in accordance with established entity policies and procedures. The entity shall: 1. Ensure that employees, contractors, and third -party users are aware of security threats and concerns, their information and cyber security responsibilities and compliance requirements. 2. Ensure users read, accept and sign the acceptable usage policy prior to the provision of access to system, application and/or information. 3. Consider segregation of duties to avoid potential misuse of position or conflict of interest Basic
  • HR 3.2 The healthcare entity shall conduct periodic security awareness campaigns, based on established schedules The entity shall: 1. Conduct awareness campaign for general and targeted u The healthcare entity shall conduct periodic security awareness campaigns, based on established schedules The entity shall: 1. Conduct awareness campaign for general and targeted user groups 2. Identify and establish method of delivery 3. Include information security and privacy education as part of the campaign 4. Ensure all the licensed healthcare professionals complete the mandatory training courses assigned to them by DoH 5. Ensure active participation and tracking of training and awareness sessions Basic 31
  • HR 3.3 The entity shall develop new or modify existing information security and privacy education and training program to include requirements of governmental and organizational informati The entity shall develop new or modify existing information security and privacy education and training program to include requirements of governmental and organizational information security and privacy demands The entity shall: 1. Ensure all employees, and where relevant contractors and third -party users, receive information security and privacy training as part of their onboarding process 2. Ensure that an awareness and training program is formally launched and effectively managed 3. Review and update the training content, as required 4. Assess and identify skill and competency gaps on information and cyber security, data privacy compliance demands 5. Implement skill and competency development programs 6. Periodically review training records to ensure that all participants have received the required instruction Transitional
  • HR 3.4 The entity shall provide appropriate role-based trainings to employees, contractors and third-party users with relevant roles and responsibilities The entity shall provide appropriate role-based trainings to employees, contractors and third-party users with relevant roles and responsibilities. The entity shall: 1. Ensure to provide information security and privacy training: a) Prior to authorizing access to system, network, applications, medical devices and/or cloud environment b) In case of any new role that require specific training 2. As needed by awareness and training program Periodically evaluate effectiveness of the awareness program Advanced
  • HR 3.5 The entity shall establish and enforce a disciplinary procedure for employees, where relevant contractors and third parties, who have committed security breaches The entity shall establish and enforce a disciplinary procedure for employees, where relevant contractors and third parties, who have committed security breaches. The entity shall: 1. Ensure employees, contractors and third-party resources are aware of the entity’s disciplinary processes 2. Enforce disciplinary processes and maintain necessary records on the breaches and on management’s actions Transitional Service Providers 32 UAE IAR Reference: M3.2.1, M3.3.1, M3.3.2, M3.3.3, M3.3.4, M3.3.5, M3.4.1, M4.3.1, M4.3.2
CJISCIS ControlsGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1Qatar NIASAMA CSFUAE IAUK GDPR
HR 4
Termination or Change of Employment and Role
Leaver/mover checklist; asset-return records; access-revocation tickets; internal transfer process.
On termination or role change, do you recover assets, revoke access/privileges and communicate the change to stakeholders?
4 sub-controls
  • HR 4.1 The entity shall define responsibilities concerning information security for performing employment termination and/or change of employment The entity shall: 1. Establish internal a The entity shall define responsibilities concerning information security for performing employment termination and/or change of employment The entity shall: 1. Establish internal and external communication protocol on employment exit. 2. Ensure adequate knowledge transfers and responsibility handovers. 3. Ensure employee handover of entity data prior to their exit. 4. Define an employee exit clearance form and ensure it is filled and signed by relevant function/department SPOCs before employee exit Basic
  • HR 4.2 The entity shall ensure recovery of all organizational assets upon termination of employment, contract or agreement The entity shall ensure recovery of all organizational assets upon termination of employment, contract or agreement. The entity shall: 1. Ensure all organizational assets are recovered and necessary acknowledgement and clearance is obtained from appropriate stakeholders 2. Ensure all information, with special focus on health information, has been recovered and cannot be misused anywhere, anytime 3. Ensure resources leaving the entity formally acknowledges and conforms that no information is under their direct or indirect possession or use Basic 33
  • HR 4.3 The entity shall remove physical and logical access rights and revoke privileges of individuals upon exit, termination of employment, contract or agreement The entity shall remove physical and logical access rights and revoke privileges of individuals upon exit, termination of employment, contract or agreement. The entity shall remove access to systems, applications, information, secure areas, and work areas. The entity shall: 1. Ensure access to systems, application, information, secure areas, work areas and identified critical areas are revoked in a timely manner within 24 hours upon exit termination. 2. Communicate with DoH and the entity being served to revoke any relevant system and application access upon termination Basic Service Provider
  • HR 4.4 The entity shall develop internal process to manage internal transfers and change of role The entity shall develop internal process to manage internal transfers and change of role. The entity shall: 1. Ensure communication to all necessary internal and external stakeholders on change of role or internal transfers. 2. Revoke access and privileges associated with previous role and reassign privileges on system, application and information access and utilization consistent with their new role based on necessary authorization. 3. Ensure adequate knowledge transfers and responsibility handovers Basic UAE IAR Reference: M4.4.1, M4.4.2, M4.4.3 34 2. Asset Management Asset Management is an essential part of effective health information Security management. In order to be effective and supportive of organizational business and security objectives, entities shall maintain an updated version of asset inventory, available to relevant management, business and support stakeholders. Information assets include data/information in all its form, as well as the underlying application, technology, physical infrastructure to support its processing, storing, communicating, and sharing and people who have access to data/information. Information Assets include, but are not limited to: • Information (in physical and digital forms) • Medical device and equipment used for diagnosis, therapy, monitoring, rehabilitation, and care etc. • Applications and System Software’s • Information system • Network infrastructure devices • Services and Processes Virtual Infrastructure s • Physical Infrastructure (Data center, Servers, access barriers, electrical facilities, HVAC systems, etc.) • Human resources (in support of services/care delivery) Objective: The regulatory structure surrounding nearly every facet of the healthcare operations, from protecting patient data and improving health outcomes, to reporting on compliance-related issues, necessitates entities to monitor and record the use of information assets. Supporting or dependent entity policy references: i.
CJISCIS ControlsHIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIST CSFQatar NIASAMA CSFUAE IAPCI DSS 4.0.1
AM · Asset Management 5
AM 1
Asset Management Policy
Asset management policy; medical-device inventory section; approval & review record.
Do you maintain an approved asset management policy that explicitly addresses medical devices and equipment?
2 sub-controls
  • AM 1.1 The entity shall develop, implement, and maintain an asset management policy to: 1. Be relevant and appropriate for entities operational and risk environment The entity shall develop, implement, and maintain an asset management policy to: 1. Be relevant and appropriate for entities operational and risk environment. 2. Establish framework to effectively manage the entity’s information assets through ownership assignment, accountability & responsibility definition, recording and maintaining of all/relevant properties of asset. 3. Define roles and responsibilities for actions expected out of asset management policy, and shall have functional KPI’s for business/function leaders. 4. Define and enforce Asset classification scheme in line with section A.5 of this standard. 5. Identify requirements of data retention, handling, and disposal Basic
  • AM 1.2 The entity shall pay specific attention to medical devices and equipment’s while defining policy, and shall categorically address the following demands: 1. Maintain an inventory of The entity shall pay specific attention to medical devices and equipment’s while defining policy, and shall categorically address the following demands: 1. Maintain an inventory of medical devices and equipment, and link them to patients while ensuring that sensitive patient information is redacted and not visible 2. Roles that will be allowed to access, use and maintain medical devices and equipment shall be established 3. To the extent possible, medical devices and equipment to authenticate users, based on entity’s authentication and authorization process 4. The need for handling procedures for each medical device and equipment in use shall be defined and updated as required to stay current 5. The need to establish and maintain risk log concerning medical devices and equipment 6. Decommissioning and/or secure disposal of medical devices and equipment Basic Service Provider UAE IAR References: T1.1.1 36
CJISCIS ControlsCyber EssentialsCyber Essentials PlusDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
AM 2
Management of Assets
Asset inventory (connected & not connected); assigned owners; acceptable-use policy; BYOD control set.
Is there a complete, owned and maintained inventory of all information assets, with acceptable-use and BYOD controls?
5 sub-controls
  • AM 2.1 The entity shall have all their information assets (connected/not connected) identified, recorded, and maintained through an information asset inventory The entity shall have all their information assets (connected/not connected) identified, recorded, and maintained through an information asset inventory. The inventory shall: 1. Capture all information assets (Laptops/ Computers, Mobile devices, Servers, Network devices, Applications, Software, Medical devices, equipment’s etc.) and necessary asset details in the asset inventory be reviewed and updated periodically , or during change in the environment, and shall be accurate and reliable 2. Be accessed and updated by an authorized individual. 3. Be centralized or distributed (function/line -of- business/service wise) based on the entity’s internal structures Basic Service Provider
  • AM 2.2 The entity shall ensure asset inventory establishes the relations between various types of information assets, in support of care delivery Advanced The entity shall ensure asset inventory establishes the relations between various types of information assets, in support of care delivery Advanced
  • AM 2.3 Ownership for each identified asset shall be assigned to a designated role: 1. The owner of an information asset shall define/identify the control requirements to minimize the impa Ownership for each identified asset shall be assigned to a designated role: 1. The owner of an information asset shall define/identify the control requirements to minimize the impact of risk, due to the compromise of assets under his ownership. 2. The owner shall review the adequacy of implemented control measures periodically and amend/modify the control environment as necessary. 3. The owner shall ensure effectiveness of the implemented controls, in addressing the risk environment. 4. Access and/or use of information assets shall be authorized by the asset owner. 5. The owner shall define and periodically review access restrictions and classifications, in line with the access control policy of the entity Basic 37
  • AM 2.4 The entity shall establish and enforce policy on the acceptable use of information assets to which users have access: 1. The policy shall be communicated to all employees, contract The entity shall establish and enforce policy on the acceptable use of information assets to which users have access: 1. The policy shall be communicated to all employees, contractors and third -party users in support of care delivery, and shall be read and acknowledged by all. 2. Entities shall maintain records of user acceptance on the acceptable use of information assets. The policy shall consider general requirements and industry best practices and shall have management requirements to reduce probabilities of information leakage/loss/theft and system compromises. Basic Service Provider
  • AM 2.5 The entity shall identify and implement “Bring Your Own Device (BYOD)” security controls, to ensure secure usage of employees personally owned electronic devices for official purposes The entity shall identify and implement “Bring Your Own Device (BYOD)” security controls, to ensure secure usage of employees personally owned electronic devices for official purposes. The entity shall: 1. Identify and address information security risk for the concept-in-practice “Bring Your Own Device (BYOD)” 2. Ensure probabilities of compromise through the use of personal devices are addressed through suitable security controls and role-based usage agreements. 3. Establish an authorization process on the use of personal devices to access/view/use/share/process/store health information. 4. Ensure usage of BYOD is subject to user acknowledgement on the usage agreements. 5. Ensure no healthcare and entity data/information is stored in employee/user’s personal devices and/or personal spaces within the devices Basic Service Provider UAE IAR References: T1.2.1, T1.2.2, T1.2.3 & T1.2.4 38
CJISCIS ControlsCyber EssentialsCyber Essentials PlusDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
AM 3
Asset Classification and Labelling
Classification scheme; labelled asset samples; tagging/registration records.
Are assets classified and labelled to a defined scheme, including assets received from third parties?
3 sub-controls
  • AM 3.1 The entity shall classify all information assets in line with the information asset classification scheme The entity shall classify all information assets in line with the information asset classification scheme. The entity shall: 1. Determine classification considering the criticality of the information it holds and ensure it is more restrictive/deterrent based on the entity’s tolerance of financial and reputational impact due to compromise of the information considered. 2. Ensure the classification scheme is uniform across the entity and well communicated. 3. Establish process for information labelling in accordance with entity’s information asset classification scheme. 4. Establish process to reassess and/or update information classification, based on the following: • Change in the value of information. • Changes to environment (location, access, storage, processing, usage, etc.) • Changes in protection levels • Changes in government demands Basic Service Provider
  • AM 3.2 The entity shall establish process to interpret classification schemes, while receiving information from other entities/3rd parties and shall apply all essential control measures t The entity shall establish process to interpret classification schemes, while receiving information from other entities/3rd parties and shall apply all essential control measures to safeguard/protect against compromise. Transitional
  • AM 3.3 The entity shall establish process to tag its information assets with unique tags prior to deployment/use in the entity environment The entity shall establish process to tag its information assets with unique tags prior to deployment/use in the entity environment. The asset tags can be used for tracking, inventory, and accountability purposes Transitional UAE IAR Reference: T1.3.1, T1.3.2 39
CJISCIS ControlsGDPR (EU)ISO 27001NCA ECC-2NCA OTCCNIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLQatar NIAPDPL – Federal Decree-Law 45/2021UAE IAUK GDPRNCA CCC
AM 4
Asset Handling
Handling procedures by classification; removable-media controls; media transfer/movement logs.
Are handling, removable-media, medical-device and transfer procedures applied per asset classification?
7 sub-controls
  • AM 4.1 Handling procedures shall be defined for information, consistent with their classification Handling procedures shall be defined for information, consistent with their classification. 1. Handling procedures shall detail security requirements during: • Access granting and privilege allocation. • Processing • Storing • Communication/sharing • Printing • Removal and disposal 2. Security requirements based on asset criticality shall be considered in the handling procedures Basic
  • AM 4.2 The entity shall manage removable media in accordance with the classification scheme, handling procedures and acceptable use of assets The entity shall manage removable media in accordance with the classification scheme, handling procedures and acceptable use of assets. The entity shall: 1. Establish media management procedures to address lifecycle requirements (setup, distribution, utilization, and disposal) 2. Implement controls for protecting removable media against unauthorized access or misuse. Limit the use of removable media to those with valid business justification. 3. Accept all involved/inherent risk concerning the use of removable media, and shall bear all responsibilities and is held accountable for the risks inherent in authorizing the use of removable media Basic Service Provider 40
  • AM 4.3 Access and privilege allocation for medical devices and equipment shall be provided to defined roles, with essential qualification and experience required to operate Access and privilege allocation for medical devices and equipment shall be provided to defined roles, with essential qualification and experience required to operate. The entity shall: 1. Secure and safe-guard medical devices and equipment with adequate security controls in accordance with its classification scheme and risk factors Basic Service Provider
  • AM 4.4 The entity shall prevent unauthorized disclosure, modification, destruction, or loss of patient health information stored on medical devices and equipment The entity shall prevent unauthorized disclosure, modification, destruction, or loss of patient health information stored on medical devices and equipment. The entity shall ensure. 1. Information stored within the medical devices and equipment are encrypted. 2. Secure electronic communication between medical devices and other equipment’s 3. To define minimum essential qualification required to operate and/or handle medical devices and equipment. 4. Copies of valuable health information is moved to a secure storage/location to reduce the risks of its data damage or loss Transitional Service Provider
  • AM 4.5 Healthcare facilities shall consider wired communication facility for medical devices and equipment Healthcare facilities shall consider wired communication facility for medical devices and equipment. Usage of wireless communication facility with medical devices and equipment shall be considered only when the wired communication facility is not available with the medical device. Transitional
  • AM 4.6 Entity shall deploy technology solution to control and monitor removable media and shall be complemented by content encryption and biometric based access provisioning Entity shall deploy technology solution to control and monitor removable media and shall be complemented by content encryption and biometric based access provisioning. Advanced
  • AM 4.7 The entity shall establish control procedures for the removal, movement, and transfer of information assets (information, equipment, medical devices, and information processing equ The entity shall establish control procedures for the removal, movement, and transfer of information assets (information, equipment, medical devices, and information processing equipment/systems). The entity shall: 1. Authorize removal, movement and transfer of information assets. 2. Maintain records of removal, movement and transfer Transitional Service Provider UAE IAR Reference: T1.3.3, T1.4.1, T2.3.7 41
CJISCIS ControlsGDPR (EU)ISO 27001NCA ECC-2NCA OTCCNIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLQatar NIAPDPL – Federal Decree-Law 45/2021UAE IAUK GDPRNCA CCC
AM 5
Asset Disposal
Secure disposal procedure; certificates of destruction; disposal register (owner, media, method, date).
Are assets disposed of beyond recovery when no longer needed, with disposal records kept?
2 sub-controls
  • AM 5.1 The entity shall ensure assets, both digital and physical, when no longer required are disposed beyond recovery The entity shall ensure assets, both digital and physical, when no longer required are disposed beyond recovery. The entity shall 1. Dispose information assets, when no longer required: • by the entity • on basis of legislative and regulatory demands • for legal proceedings 2. Initiate disposal of information assets on authorization of entity management 3. Verify and comply with the data retention policy, regulatory demands and requirements of data/information prior to disposal of any information asset. 4. Establish control procedures for the secure disposal or reuse of media, equipment, devices and systems, containing classified information. 5. Ensure removal of identifiable health information from assets prior to disposal 6. Establish controls that ensure data once destroyed is not recovered Basic Service Provider
  • AM 5.2 The entity shall maintain records, on asset disposal The entity shall maintain records, on asset disposal. The records shall have, but not be limited to, the following fields: • Information and/or asset owner • Type of media • Classification • Disposal type • Reason for disposal • Retention expiry date (if data) • Data removal confirmation and evidence • Disposal authorized by Transitional UAE IAR Reference: T1.4.2, T2.3.6 42 3. Physical and Environmental Security Physical and environmental security measures shall be implemented to ensure processing facilities are physically protected from unauthorized access, damage, interference, and equipment is protected from physical and environmental threats. These security measures or controls shall protect entities from loss of connectivity, availability of information processing facilities, storage (backup and archival) equipment(s)/facilities and medical equipment’s/devices caused by theft, fire, flood, intentional destruction, unintentional damage, mechanical failure, power failure, etc. Objective: To ensure that information assets receive adequate physical and environmental protection, and to prevent or reduce probabilities of physical and environmental control/security compromises (loss, damage, theft, interference, etc.) Supporting or dependent entity policy references: i. Clear Desk and Clear Screen Policy ii. Data Privacy Policy 43
CJISCIS ControlsCyber EssentialsCyber Essentials PlusDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
PE · Physical and Environmental Security 3
PE 1
Physical and Environmental Security Policy
Physical/environmental security policy; approval & review record.
Do you have an approved physical & environmental security policy protecting information assets?
1 sub-control
  • PE 1.1 The entity shall develop, implement and maintain a physical and environmental security policy, to ensure adequate physical and environmental protection of entity’s information assets The entity shall develop, implement and maintain a physical and environmental security policy, to ensure adequate physical and environmental protection of entity’s information assets. The policy shall: 1. Be relevant and appropriate for entity’s operational and risk environment, concerning internal and external threats. 2. Address requirements of secure storage of hazardous or combustible materials that ensure avoidance of: a) human injuries or loss of life b) damage to information and information systems 3. Consider classification of information assets and their physical presence 4. Consider medical devices and equipment’s with special focus on their: a) Criticality of data handled and healthcare operations. 5. Physical and environmental demands, as recommended by the manufacturer and applicable regulatory requirements define roles and responsibilities for actions expected out of physical and environmental security policy Basic UAE IAR Reference: T2.1.1, T2.3.5 44
HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIST CSFPCI DSS 4.0.1Qatar NIASAMA CSFUAE IACJISCIS ControlsDORAGDPR (EU)NIS2PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021UK GDPR
PE 2
Secure Areas
Secure-area map & perimeter definition; access logs; owner list; environmental controls; loading-bay procedure.
Are secure areas defined with perimeters, access controls, owners, environmental protection and controlled delivery/loading?
6 sub-controls
  • PE 2.1 The entity shall define and use security perimeters to protect areas that contain information and information systems The entity shall define and use security perimeters to protect areas that contain information and information systems. The entity shall: 1. Identify secure areas and define security perimeters, based on information assets contained within or information being processed. 2. Ensure adequate security countermeasures are applied to identified secure areas to protect information and information systems within 3. Consider the impact of compromise of confidentiality, integrity and availability of information or information assets while applying security controls. 4. Ensure secure areas are protected by appropriate control measures and only authorized personnel are provided access and authorized activities are being conducted. 5. Control access of mobile, portable and surveillance devices/equipment/utilities to secure areas Basic Service Provider
  • PE 2.2 The entity shall allocate secure private areas to discuss protected health information by authorized stakeholders Advanced The entity shall allocate secure private areas to discuss protected health information by authorized stakeholders Advanced
  • PE 2.3 Secure areas shall be protected by appropriate control measures to ensure only authorized personnel are granted access and authorized activities are being conducted Secure areas shall be protected by appropriate control measures to ensure only authorized personnel are granted access and authorized activities are being conducted. The entity shall: 1. Maintain List of authorised personnel having access to secure areas 2. Authenticate all persons accessing secure areas. 3. Maintain records for secure area access. 4. Maintain visitor access logs for visitors to secure areas. 5. Ensure that all employees, contractors and visitors wear distinguished form of visible identification within the premises of the entity 6. Ensure the locking mechanisms on all access doors are adequate, and alarms configured to alert prolonged open state of doors Basic 45 7. Escort contractors or third parties while inside the secure areas 8. Deploy closed circuit television (CCTV/surveillance camera) in identified vantage points of secure areas as required by Monitoring and Control Centre (MCC) Abu Dhabi 9. Preserve CCTV footage for a period as required by Monitoring and Control Centre (MCC) Abu Dhabi
  • PE 2.4 The entity shall nominate owners for each identified secure area The entity shall nominate owners for each identified secure area. Nominated owners of secure areas shall: 1. Review access records/logs and surveillance footage in accordance with entity policy or in case of any security incident, whichever is earlier. 2. Reconcile list of authorized users, having access to secure areas 3. Maintain a list of physical key inventory, as with whom the keys of secure areas are with 4. Ensure to change the combinations and keys for any entity-defined secure zones, entry/exit points, and cabinets, when compromised Transitional
  • PE 2.5 The entity shall design and apply physical protection against natural disasters, environmental threats, external attacks and/or accidents The entity shall design and apply physical protection against natural disasters, environmental threats, external attacks and/or accidents. The entity shall: 1. Implement and maintain environmental control systems for data center’s, that monitor, maintain, and test the consistency of temperature and humidity conditions in accordance with regulatoryrequirements.s 2. Ensure appropriate fire suppression systems (e.g., sprinklers, fire extinguishers) are located throughout the entity. 3. Ensure fire detectors (e.g., smoke or heat activated) are installed on and/or in the ceilings and floors. 4. Ensure that fallback equipment, device, system and backup media are protected from damage caused by natural or man-made disasters. Basic Service Provider 46 UAE IAR Reference: T2.2.1, T2.2.2, T2.2.3, T2.2.4, T2.2.5, T2.2.6
  • PE 2.6 The entity shall have segregated delivery, loading areas and shall establish control measures over entry and exit The entity shall have segregated delivery, loading areas and shall establish control measures over entry and exit. The entity shall: 1. Establish access procedures to loading and unloading areas to restrict access to only authorized personnel. 2. Inspect and register incoming and outgoing materials, in accordance with entity’s asset management procedures. 3. Physically segregate incoming and outgoing materials, as applicable Basic 47
HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIST CSFPCI DSS 4.0.1Qatar NIASAMA CSFUAE IA
PE 3
Equipment Security
Equipment siting/maintenance procedures; cabling protection; off-site authorisation; clear desk/screen policy.
Is equipment (incl. medical devices), cabling and off-site equipment protected, with a clear desk/screen policy enforced?
5 sub-controls
  • PE 3.1 The entity shall site/position medical devices and equipment in a manner that they are always protected The entity shall site/position medical devices and equipment in a manner that they are always protected. The entity shall: 1. Consider environmental risk condition while positioning medical devices and equipment. 2. Establish guidelines on physical protection and unauthorized access of equipment and medical devices. 3. Implement controls to protect equipment, medical devices and information processing systems when left unattended Basic Service Provider
  • PE 3.2 The entity shall maintain operating procedures to keep equipment in reliable working order The entity shall maintain operating procedures to keep equipment in reliable working order. The entity shall: 1. Establish operating procedures for commissioning, maintenance and decommissioning of equipment activities. 2. Maintain up -to date records for maintenance carried out. Advanced Service Provider 5. Ensure availability of power backup to provide power to key information systems and critical data centre infrastructures
  • PE 3.3 Power, telecommunication, and cables carrying data shall be secured and protected Power, telecommunication, and cables carrying data shall be secured and protected. The entity shall: 1. Ensure that power, telecommunication and data cables are protected against physical tampering. 2. Segregate power and telecommunication/data cables to avoid interference Basic
  • PE 3.4 The entity shall identify and apply security measures to protect equipment, medical devices, and information processing systems while off-site The entity shall identify and apply security measures to protect equipment, medical devices, and information processing systems while off-site. The entity shall: 1. Establish an authorization procedure for taking information assets off-site. 2. Ensure manufacturer’s recommendation and instructions are followed, while equipment, medical devices and information processing systems are off- site. 3. Ensure that movement and possession (chain of custody) logs for off -site equipment, medical devices and information processing systems maintained and verified. 4. Ensure security measures are applied to protect off-site equipment, medical devices, and information processing systems from probabilities of information leakage, tampering and unauthorized activities Transitional Service Provider
  • PE 3.5 The entity shall define and enforce a clear desk and clear screen policy for paper documents, removable storage media, and information processing systems The entity shall define and enforce a clear desk and clear screen policy for paper documents, removable storage media, and information processing systems. The clear desk and clear screen policy shall: 1. Define user responsibilities with respect to clear desk and clear screen requirements. 2. Be appropriate to the purpose and objectives of the entity. 3. Be read and acknowledged by all employees and contractors of the entity. 4. Ensure that health information is not left unattended Basic UAE IAR Reference: T2.3.1, T2.3.2, T2.3.3, T2.3.4, T2.3.5, T2.3.7, T2.3.8, T2.3.9 48 4. Access Control Access control processes enforce security requirements such as confidentiality, integrity, and availability of information assets to prevent unauthorized use of resources. Access controls shall be developed by entity to control access of employees, contrac tors, and third -party users to entity’s information assets and to manage their access in reference to internal network, operating systems, and applications to ensure appropriate protection of entity’s infrastructure health information protected health info rmation. Entity’s management shall be aware of the risk environment and outcomes of unauthorized access, and are accountable for all consequences and impact on Abu Dhabi Government, Abu Dhabi Healthcare-ecosystem or Health Sector, Patients concerned and the entity itself. Objective: To ensure access to information/information systems are controlled, and to minimize probabilities of information leakage/compromise, tampering, loss or system compromises. Supporting or dependent entity policy references: i. Physical and Environmental Security Policy ii. Clear Desk and Clear Screen Policy iii. Log management policy iv. Password Management Policy v. Cloud Security Policy vi. Data Privacy Policy The level of applicability of above-mentioned policies will vary depending on the individual entity. 49
HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIST CSFPCI DSS 4.0.1Qatar NIASAMA CSFUAE IACJISCIS ControlsDORAGDPR (EU)NIS2PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021UK GDPR
AC · Access Control 6
AC 1
Access Control Policy
Access control policy; approval & review record.
Do you have an approved access control policy ensuring access to assets is controlled and secured?
1 sub-control
  • AC 1.1 The entity shall develop, enforce, and maintain an access control policy to ensure access to information and information assets is adequately controlled and secured The entity shall develop, enforce, and maintain an access control policy to ensure access to information and information assets is adequately controlled and secured. The policy shall: 1. Be relevant and appropriate to control and secure access to information, application, technology, medical devices and equipment. 2. Include management demands and directions, scope and specific applicability based on: a) Type of service b) Information c) Application d) Technology e) Infrastructure devices f) Medical devices and equipment 3. Emphasize the requirement-of-need and role-based access principles. 4. Establish requirements, with core focus on. a) granting of access b) access authorization c) access revocation d) access review 5. Address the entity needs on secure password management and practices Basic 50 6. Mandate the usage of unique identity and complex password where relevant, define access control measures and provisions for portable/mobile devices, including user owned devices, that handle the entity’s data or host the entity application(s) to conduct business transactions. 7. Include control requirements for the access and use of network services. 8. Include management actions on violations and deviations. 9. Define roles and responsibilities for actions expected UAE IAR Reference: T5.1.1
CJISCIS ControlsCyber EssentialsCyber Essentials PlusGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPRDORA
AC 2
User Access Management
Joiner/leaver process; privileged-access register; credential/password standard; default-credential change records.
Are user registration/de-registration, privilege allocation (need-to-know) and credential management formally controlled?
3 sub-controls
  • AC 2.1 The entity shall have a formal documented and implemented user registration and de-registration process the entity shall: 1. Ensure request for user registration and de-registratio The entity shall have a formal documented and implemented user registration and de-registration process the entity shall: 1. Ensure request for user registration and de-registration are process driven, and are in compliance with established criteria for access. 2. Ensure unique user accounts are created for each individual requiring access, and shall implement a suitable authentication mechanism. 3. Ensure shared user account are not created or used without explicit approval from the Information System Owner, Business Processes Owner & shall have an owner assigned to ensure accountability. 4. Ensure accounts are deactivated within defined duration of inactivity. 5. Revoke user accounts upon exit, termination of employment, contract, or agreement 6. Revalidate access requirements during role changes. 7. Maintain records/list of persons authorized to use entity’s information systems, applications, medical devices, and equipment Basic Service Provider 51
  • AC 2.2 The entity shall restrict and control allocation of privileges, based on principles of need to know The entity shall restrict and control allocation of privileges, based on principles of need to know. The entity shall: 1. Ensure normal user accounts are not used as service accounts or to conduct privileged application and system level activities. 2. Control and restrict from sharing privilege user IDs to multiple users. 3. Ensure users privileges are restrictive in nature, and are assigned based on needs to conduct business activities supported by necessary approvals. 4. Ensure Privilege or administrative accounts are only used for system administrator activities and not for daily day to day operations. 5. Ensure usage of service accounts are controlled, and are not hardcoded in application codes or scripts. 6. Enforce multifactor authentication scheme for all privilege, administrative and remote access. 7. Ensure remote access is controlled and monitored Transitional Service Provider 52
  • AC 2.3 The entity shall establish a process for secure allocation, use and management of security credentials The entity shall establish a process for secure allocation, use and management of security credentials. The entity shall: 1. Ensure to change default credentials for all information assets before deployment to operational environment. 2. Ensure that passwords are prohibited from being displayed when entered. 3. Ensure passwords are always hashed and stored in encrypted format. 4. Communicate details of user account and password in two different communication modalities 5. Enforce complexity requirements on password characters, and shall have at least: a) Twelve characters b) One number, one upper-case and lower -case character, and a special character 6. Ensure passwords, including that of service accounts and privileged accounts, are changed periodically. 7. Ensure account lockout features are configured to block the users after at least 5 failed attempts. 8. Ensure that password history is maintained, and shall restrict users from using immediately used previous passwords (at least 3 previous passwords) 9. Ensure to change password post remote maintenance session which requires sharing of password. 10. Educate users to adopt good practices while selecting and using passwords Basic Service Provider UAE IAR Reference: T5.2.1, T5.2.2, T5.2.3, T5.3.1, T5.5.2, T5.5.3 53
CJISCIS ControlsCyber EssentialsCyber Essentials PlusGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPRNCA CCC
AC 3
Equipment and Devices Access Control
Device access control list; teleworking access procedure; Telemedicine compliance evidence.
Is access to removable media, portable/medical devices and teleworking sites restricted per role, including DoH Telemedicine requirements?
3 sub-controls
  • AC 3.1 The entity shall restrict access to removable media, portable devices, and medical equipment or devices The entity shall restrict access to removable media, portable devices, and medical equipment or devices. The entity shall: 1. Ensure access is provided on role -based need -to-know principles with appropriate authorization. 2. Ensure media containing confidential and secret information is password protected and encrypted. 3. Where relevant, control access to medical equipment and devices through password enforcement in compliance with the healthcare entity password complexity and usage requirements Transitional Service Provider
  • AC 3.2 The entity shall control access to equipment, devices, system, and facilities at teleworking sites The entity shall control access to equipment, devices, system, and facilities at teleworking sites. The entity shall: 1. Ensure access to equipment, devices, system and facilities at teleworking sites are authenticated, and their access to entity resources are authorized based on need. 2. Ensure confidentiality and protection of health information while providing/consuming services through teleworking principles. 3. Maintain an inventory of assets in use at teleworking sites Transitional Service Provider
  • AC 3.3 The entity shall adhere to security and privacy requirements outlined in the DoH standard for Telemedicine, in addition to fulfilling the requirements set forth in this standard wh The entity shall adhere to security and privacy requirements outlined in the DoH standard for Telemedicine, in addition to fulfilling the requirements set forth in this standard when delivering Telehealth services. Basic Service Provider UAE IAR Reference: T5.6.1, T5.6.3, T5.7.2 54
CJISCIS ControlsCyber EssentialsCyber Essentials PlusGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
AC 4
Access Reviews
Access-review schedule; completed review reports; remediation actions.
Are user access rights and privileges reviewed periodically?
1 sub-control
  • AC 4.1 The entity shall review access and privileges granted to its user The entity shall review access and privileges granted to its user. The entity shall: 1. Establish process for the reviewing user access and associated privileges to various entity resources periodically. 2. Define responsibility for access and privileges review, based on entity resources being accessed. 3. Conduct user access review at least once a year or earlier, as required by the entity’s risk environment. 4. Maintain an up -to-date inventory of access granted and privileges assigned Basic Service Provider UAE IAR Reference: T5.2.4
CJISCIS ControlsHIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIST CSFQatar NIASAMA CSFUAE IAPCI DSS 4.0.1
AC 5
Network Access Control
Network access policy; rogue-device detection logs; port/whitelist config; wireless security config.
Is network access controlled — authorised access, device detection, diagnostic-port control, routing and secured wireless?
5 sub-controls
  • AC 5.1 Access to the entity’s network and network services shall be controlled, and shall be provided based on specific need for which the user is authorized for: The entity shall: 1. Pro Access to the entity’s network and network services shall be controlled, and shall be provided based on specific need for which the user is authorized for: The entity shall: 1. Provide access to entity network in accordance with access control rules and depending on necessity. 2. Implement appropriate authentication methods to ensure secure remote access. 3. Ensure all remote login and access are only through secure channels. 4. Identify all equipment and devices connected to its network, and shall have mechanism to detect unauthorized equipment and devices Basic Service Provider
  • AC 5.2 The entity shall have mechanism to identify all equipment and devices connected to its network, and shall have automated mechanism to detect unauthorized equipment and devices Advanced 55 The entity shall have mechanism to identify all equipment and devices connected to its network, and shall have automated mechanism to detect unauthorized equipment and devices Advanced 55
  • AC 5.3 The entity shall control access to all information assets for the purpose of diagnosis and configuration The entity shall control access to all information assets for the purpose of diagnosis and configuration. The entity shall: 1. Identify and whitelist all ports, services and utilities that are used for troubleshooting, and for diagnostics and configuration purposes. 2. Provide rationale or define security controls for the diagnostic and configuration services and utilities that are essential, and disable services and utilities that are not required. 3. Restrict access for remote troubleshooting, diagnostic and configuration to authorized roles and shall be allowed from authorized workstations Advanced
  • AC 5.4 The entity shall define and implement network routing controls to ensure information flow and system, medical devices and equipment connections are not compromised The entity shall define and implement network routing controls to ensure information flow and system, medical devices and equipment connections are not compromised. The entity shall: 1. Establish processes for secure configuration and rules for network routing requirements. 2. Always ensure source and destination address and services or ports are used while defining and applying routing rules. 3. Enable routing protection countermeasures to avoid manipulation of routing systems and tables. 4. Define and implement network architecture that segregates and isolates internal and externally accessible systems. 5. Manage external connections to information systems and networks using interfaces made up of perimeter security devices (such as firewalls) 6. Ensure that communications with external systems, networks and key internal systems are always monitored for malicious and suspicious payloads. 7. Review and update the configured rules, as required. 8. Periodically scan for any covert channel connections to public networks bypassing entity security defense Transitional Service Provider 56
  • AC 5.5 The entity shall ensure wireless access within the entity is secured The entity shall ensure wireless access within the entity is secured. The entity shall: 1. Ensure that internal wireless is not broadcasted. 2. Establish authorization process for wireless access and usage. 3. Ensure only trusted devices and users gain access to internal networks via wireless access Transitional UAE IAR Reference: T5.4.1, T5.4.2, T5.4.3, T5.4.4, T5.4.5, T5.4.6, T5.4.7
CJISCIS ControlsCyber EssentialsCyber Essentials PlusGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPRDORANCA CCC
AC 6
Operating System Access Control
Authentication standard (MFA where relevant); unique-ID provisioning records; utility-program restriction config.
Are secure log-on/log-off, unique user IDs with authentication, and restricted use of utility programs enforced?
3 sub-controls
  • AC 6.1 The entity shall establish and enforce secure log -on and log -off procedures to control access to system, applications, services, medical devices and equipment The entity shall establish and enforce secure log -on and log -off procedures to control access to system, applications, services, medical devices and equipment. The entity shall: 1. Ensure that access to systems, applications, services, medical devices and equipment that process, use or store health information are authenticated. 2. Enforce automated locking of workstation/system after a predefined period of inactivity. 3. Automatically terminate inactive sessions after a predefined period of session inactivity 4. 6. Display a logon banner that requires the user to acknowledge and accept security terms and their responsibilities before access to the system is granted Basic Service Provider
  • AC 6.2 The entity shall create unique identifier (user ID) for each user who requires access to entities systems, applications, or services, and shall implement a suitable authentication technique The entity shall create unique identifier (user ID) for each user who requires access to entities systems, applications, or services, and shall implement a suitable authentication technique. The entity shall: 1. Grant each user with a unique identifier 2. Ensure all user activities are logged with the associated identifier Basic Service Provider 57
  • AC 6.3 The entity shall restrict and control the use of utility programs and tools that might be capable of overriding system and application controls The entity shall restrict and control the use of utility programs and tools that might be capable of overriding system and application controls. The entity shall: 1. Identify essential system utilities and tools and enforce appropriate controls for use. 2. Provide access to system utilities and tools based on appropriate authorization. 3. Maintain inventory of access to system utilities and tools 4. Monitor use of system utilities and tools Advanced UAE IAR Reference: T5.5.1, T5.5.2, T5.5.4 58 5. Communications and Operation Management Communications and Operations management aims to establish and/or strengthen entities processes and efforts to improve and enhance control environment. Entity shall have controls in place to ensure the safe operation of information processing equipment and the security of data while it is processed, stored and transmitted across networks. The domain addresses requirements of backup, security of network, secure electronic communication and monitoring to ensure protection against malicious code and spyware. Objective: To ensure that activities concerning entities processes, support and maintenance of data, technology, application, and communication are controlled and carried out in a standardized and secured manner to reduce probabilities of errors and compromises, and to increase efficiency and security. Supporting or dependent entity policy references: i. Change Management Policy ii. Capacity Management Policy iii. Patch Management Policy iv. System Acceptance Policy v. Backup Policy vi. Logging and Monitoring Policy vii. Cloud Security Policy viii. Third Party Security Policy 59
CJISCIS ControlsCyber EssentialsCyber Essentials PlusGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPRNCA CCC
CO · Communication and Operation Management 12
CO 1
Communication and Operation Management Policy
Communication/operations management policy; approval & review record.
Do you have an approved communication & operation management policy?
1 sub-control
  • CO 1.1 The entity shall develop, enforce and maintain a secure communication and operation management policy to ensure operational and communication activities concerning data, technology The entity shall develop, enforce and maintain a secure communication and operation management policy to ensure operational and communication activities concerning data, technology and application are controlled. The policy shall: 1. Be relevant and appropriate to the entity’s operational and risk environment concerning data, technology and application. 2. Establish management demands on: a) Segregation of duties b) Configuration management c) Change management d) Baselines and minimum-security configurations e) Standard operating procedures f) Capacity management g) System acceptance h) Malware control i) Backup management j) Network Security Management k) Secure exchange of Information l) Electronic Commerce Services m) Logging and monitoring n) Patch management Basic UAE IAR Reference: T3.1.1, T4.1.1 60
CJISCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
CO 2
Operational Procedures and Responsibilities
Hardening/configuration baselines; documented SOPs; change-management procedure; environment-segregation evidence.
Are hardening baselines, operating procedures, change management and segregated dev/test/staging/prod environments in place?
4 sub-controls
  • CO 2.1 The entity shall develop and enforce baseline and recommended configuration and system settings for hardening of information technology products, applications, virtual machines (VM The entity shall develop and enforce baseline and recommended configuration and system settings for hardening of information technology products, applications, virtual machines (VM), medical devices and equipment The entity shall: 1. Consider the following while developing baseline and recommended configuration setting: a) Requirements of this Standard b) Manufacturer’s security recommendations c) Industry best practices d) Risk mitigation strategies e) Resilience during any unforeseen events f) Corrective and preventive actions (audit, assessment, and incident outcomes) 2. Periodically review and update baseline and configuration requirements in line with evolving vulnerabilities and threats Transitional Service Provider
  • CO 2.2 The entity shall document and follow operating procedures for all administrative, support, operational and maintenance activities of information systems, applications, medical devi The entity shall document and follow operating procedures for all administrative, support, operational and maintenance activities of information systems, applications, medical devices, equipment or Cloud based systems and solutions. The entity shall: 1. Disseminate operating procedures and ensure all relevant internal stakeholders are aware of their responsibilities as needed by their roles. 2. Ensure all the involved third -party users (if any) are well aware of the entity’s operational procedures and they adhere to the same. 3. Ensure operating procedures are relevant and are updated periodically or in case of any significant change, whichever is earlier 4. Ensure system documentation includes up -to-date diagrams. Advanced 61
  • CO 2.3 The entity shall establish, document, approve, communicate, apply, evaluate, and maintain the policies and procedures for managing the risks associated with applying changes to ent The entity shall establish, document, approve, communicate, apply, evaluate, and maintain the policies and procedures for managing the risks associated with applying changes to entity assets including information systems, software’s, applications, medical devices, equipment, infrastructure and technology environment regardless of whether the assets are managed internally or externally. The entity shall: 1. Establish a Change Advisory Board to authorize changes. 2. Define and enforce a process that addresses the following elements: a) Identification and recording of significant changes. b) Planning and testing of changes in test environment c) Assessment of potential risks and impacts of changes d) Formal approval procedure e) Communication of change to all relevant stakeholders f) Identification of stakeholders responsible for the “build, test, and implement” portion of the change. g) Roll-back plan to be utilized during unsuccessful changes. h) Post implementation assessment i) Monitoring of changes j) Maintenance of change records 3. Maintenance of previous version of software, code, and configurations. Maintenance of CMDB with updated Configuration Items. Ensure that movement of system and applications from development or project state to operational or production state are managed through the Authorization and Change Process 4. Identify and segregate roles of conflicting interests and assign responsibilities accordingly. 5. Make sure the third party notifies the entity in advance of any changes to the manner services are provided, including but not limited to: a) Relocation b) Reconfiguration Transitional 62 c) Changes in hardware or software d) Onboarding sub-contractor e) Changes to operating environment
  • CO 2.4 The entity shall identify and maintain separate environment for development, testing, staging and production The entity shall identify and maintain separate environment for development, testing, staging and production. The entity shall: 1. Identify the appropriate level of segregation and protection between production, staging, test, and development environments. 2. Document and apply clear processes for the transfer of data, information, code, configuration, software and systems between environments. 3. Ensure as-is operational data, confidential data and/or PII and PHI is not used in test environment. 4. Restrict usage/migration of test data into operational environment. 5. Ensure to test the change in testing environment before rolling it out in production state. 6. Prepare a rollback strategy Transitional Service Provider UAE IAR Reference: T3.2.1, T3.2.2, T3.2.3, T3.2.4, T3.2.5, T7.6.1, T7.6.2, T7.6.3 63
CJISCIS ControlsCyber EssentialsCyber Essentials PlusDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
CO 3
Planning and Acceptance
Capacity monitoring reports; system acceptance/test criteria & sign-offs.
Are capacity requirements monitored and acceptance criteria set for new systems and changes?
2 sub-controls
  • CO 3.1 The entity shall identify and document current and future capacity requirements for information systems and applications The entity shall identify and document current and future capacity requirements for information systems and applications. The entity shall: 1. Have the ability to monitor and measure the capacity of current systems and estimate future information systems and application demands. 2. Ensure there is sufficient capacity with information systems to support good system performance and reliability. 3. Run stress testing on systems and services to ensure system stability during peak hours. 4. Identify capacity thresholds for all information systems and applications, cloud environment and services and define advance escalation matrix to ensure capacity demands are met. 5. Establish process to: a) decommission systems that are no longer needed. b) optimize databases. c) archive data that is not accessed regularly Advanced 64
  • CO 3.2 The entity shall establish acceptance criteria for new information systems, applications, medical devices, equipment, and for changes, upgrades and releases, in addition to satisfactory test results The entity shall establish acceptance criteria for new information systems, applications, medical devices, equipment, and for changes, upgrades and releases, in addition to satisfactory test results. The entity shall: 1. Establish processes for system acceptance, and ensure system acceptance is acknowledged by the relevant authoritative individual. 2. Develop test cases for each of the requirements and changes and ensure tests are carried out and test results documented prior to usage in an operational environment. 3. Ensure testing is never performed on production systems. 4. Ensure user (with permissions appropriate for the tasks) involved in testing are different from the ones involved in operational and development activities. 5. Ensure development tools and/or editors are not installed on operational systems. 6. Ensure test data and accounts are removed completely before the application is moved into production state Transitional Service Provider UAE IAR Reference: T3.3.1, T3.3.2 65
CJISCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIAUAE IAUK GDPR
CO 4
Malware Protection
Endpoint AV/EDR config & coverage; email/web gateway protection; email authentication (SPF/DKIM/DMARC).
Are anti-malware controls deployed on endpoints and at gateway level for web and email traffic?
2 sub-controls
  • CO 4.1 The entity shall implement security measures to prevent and detect malware in order to safeguard information assets The entity shall implement security measures to prevent and detect malware in order to safeguard information assets. The entity shall: 1. Ensure minimum security configurations is maintained in all information assets, as applicable and as relevant. 2. Implement anti -malware and anti -virus protection mechanisms for network and individual information systems (server, workstation, mobile/portable computing devices, virtual machine, cloud environment, hard drives, USB devices etc. 3. Ensure anti -malware and anti -virus protections mechanisms are updated and current. 4. Prevent access to malicious websites or sites. 5. Enable real-time protection capabilities. 6. Establish and enforce periodic scan schedules. 7. Scan removable media for viruses and malware on all occasions when they are connected to information systems. 8. Disable auto -run features for removable media on information systems. 9. Disallow the use or installation of unauthorized software. 10. Configure anti -malware and anti -virus protection systems to alert responsible stakeholders on event, incident or anomaly detection. 11. Collect information about new threats and provide ongoing awareness for users on techniques, tactics, and procedure to avoid and minimize probabilities Transitional Service Provider 66
  • CO 4.2 The entity shall deploy gateway level protection mechanisms for web and email traffic to detect and defend against malware and viruses The entity shall deploy gateway level protection mechanisms for web and email traffic to detect and defend against malware and viruses. The entity shall: 1. Implement Email Authentication Solution to block harmful or fraudulent uses of email such as phishing and spam. 2. Check any attachments or downloads from email and instant messaging for malware, before use Advanced UAE IAR Reference: T3.4.1
CJISCIS ControlsCyber EssentialsCyber Essentials PlusISO 27001NCA CCCNCA ECC-2NCA OTCCNIST CSFPCI DSS 4.0.1Qatar NIAUAE IA
CO 5
Backup and Archival
Backup policy & schedule; restore-test results; archival/retention procedure.
Are backups of essential information taken and tested, with defined archival and retention processes?
2 sub-controls
  • CO 5.1 The entity shall maintain backup copies of essential information and software needed to support care delivery and its operations The entity shall maintain backup copies of essential information and software needed to support care delivery and its operations. The entity shall: 1. Establish backup management process that identifies. a) Essential and critical information systems and applications in support of care delivery, business, and entity operations b) Data owner c) Data recovery point and time requirements d) Backup frequencies, time of execution and methods e) Security controls to prevent compromise of backup data Basic Service Provider 67 2. Perform backup of all identified systems, applications and its critical data including the configuration 3. Establish a data restoration process and ensure data restoration requirements for continuity and recovery are adequately met. 4. Ensure data backups are tested for restoration in accordance with the entity’s defined recovery plan 5. Ensure data backup of specific instances are not mixed, accidently or deliberately. 6. Ensure backups are not stored on entity live environment
  • CO 5.2 The entity shall establish data archival requirements that satisfies entities retention demands The entity shall establish data archival requirements that satisfies entities retention demands. The entity shall: 1. Establish formal processes for archival and destruction of data. 2. Identify data-sets and establish retention requirements as needed by law, regulation, and entity demands 3. Identify and enforce archival criteria (what and when to archive, how long to archive) and methods (physical/electronic) that satisfies established retention timelines. 4. Preserve data during archival. 5. Destroy data that has crossed retention timelines and are no longer required by the entity. 6. Maintain adequate record on archival and destruction Advanced Service Provider UAE IAR Reference: T3.5.1 68
CJISCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPRNCA CCC
CO 6
Logging and Monitoring
Logging standard; SIEM/central log config; NTP time-sync config; DLP solution evidence.
Is logging & monitoring enforced with centralised log management, time synchronisation and data-leakage prevention?
4 sub-controls
  • CO 6.1 The entity shall establish and enforce Logging and monitoring procedures for information systems application, cloud services, medical devices, equipment etc The entity shall establish and enforce Logging and monitoring procedures for information systems application, cloud services, medical devices, equipment etc. The entity shall: 1. Ensure all critical technology (servers, database, network devices, applications, medical devices equipment etc.) are capable of generating logs and/or reports that can be referred for monitoring. 2. Identify aspects system use, privilege activities, operator and user activities, logon attempts, network, system and application traffic, security events, changes, internal processing, Exemption, information exchange, integration, access, backup process etc.) to be monitored 3. Establish minimum information gathering requirements for each monitoring activities. 4. Conduct real time monitoring or in a defined periodic interval, subject to entity risk environment. 5. Define minimum frequency requirements for reviewing each type of logs. 6. Ensure procedures are in place to respond to alerts from the monitoring system, as required. 7. Define criteria for alerting and escalation. 8. Have defined criteria that quantifies specific outcomes of monitoring as incidents. 9. Establish roles for monitoring activities and assign specific responsibilities. 10. Communicate alerts to relevant stakeholders to address the issues and enhance monitoring capabilities. 11. Ensure that logs and/or reports are protected and not tampered with or modified or destroyed Advanced Service Provider 69
  • CO 6.2 The entity shall preserve logs in a centralized log management system The entity shall preserve logs in a centralized log management system. The entity shall: 1. Control access to the centralized log management solution 2. Ensure the centralized log management solution is managed by individuals who do not have operational role in implementing or maintaining information systems or application. 3. Ensure logs are correlated to identify any security threats or malicious activity. 4. Retain logs for a period commensurate with legal, regulatory and entity demands. 5. Define use cases and dashboards based on the entity’s needs and industry recommendations, and shall consider: a) System utilization and performance trends b) Deviation from entity policy and procedures c) Access control variances and violations d) Any potential sign of security breach or attack Advanced
  • CO 6.3 The entity shall synchronize clock of all information systems and devices with an agreed time source The entity shall synchronize clock of all information systems and devices with an agreed time source. The entity shall: 1. Standardize date/time format and enforce the standard time to be used in all systems. 2. Ensure clock of medical devices and equipment are synchronized with the connected systems. 3. Regularly check that the clocks of all relevant information processing systems are synchronized. Basic
  • CO 6.4 The entity shall implement solutions to prevent data leakage from systems, networks and any other devices that process, store or transmit health information The entity shall implement solutions to prevent data leakage from systems, networks and any other devices that process, store or transmit health information. 1. The entity shall implement Data Leakage Prevention measures to control loss of entity data Transitional Service Provider UAE IAR Reference: T3.6.1, T3.6.2, T3.6.3, T3.6.4, T3.6.5, T3.6.6, T3.6.7, T7.6. 70
CJISCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
CO 7
Security Assessment and Vulnerability Management
Annual assessment schedule; VA/pen-test reports; data-handling/destruction agreement with assessors.
Are periodic independent technical assessments (e.g. VA/pen-test) performed, with assessment data protected afterwards?
2 sub-controls
  • CO 7.1 The entity shall conduct periodic independent (Internal/External) technical assessment to ensure critical information assets are secure and always protected The entity shall conduct periodic independent (Internal/External) technical assessment to ensure critical information assets are secure and always protected. The entity shall: 1. Establish yearly schedules and conduct vulnerability assessment and penetration testing of: a) Entity’s system, network, infrastructures and environment b) Web and mobile applications accessible over internet c) Connected medical devices. 2. Establish processes to conduct security testing and authorization by authorized business and security stakeholders for all new deployment and changes to information assets prior to production roll-out and/or use Co-operate with DoH during DoH vulnerability assessment activity and ensure to provide all required information. 3. Establish processes to mitigate and manage identified findings and vulnerabilities 4. Share reports on identified findings and vulnerabilities and the status of mitigation with entity’s management 5. Define timelines for tracking remediation of the identified technical vulnerabilities 6. Periodically follow up on the progress and status of mitigation measures with the appropriate stakeholders 7. Verify effectiveness and efficiency of mitigation measures by performing revalidation assessment Advanced Service Provider 71
  • CO 7.2 The entity shall ensure that assessment data is not available with third parties engaged to conduct assessments beyond the time of engagement The entity shall: 1. Ensure that syste The entity shall ensure that assessment data is not available with third parties engaged to conduct assessments beyond the time of engagement The entity shall: 1. Ensure that system, network, applications, devices, equipment and security related information is shared with third parties when they are on-site 2. Ensure that all information related to the entity’s system, network, applications, devices, equipment and security infrastructures and environment and assessment outcomes are erased from the involved third party’s assets and environment after the completio n of the assessment activity 3. Ensure that all shared reports are suitably protected and controlled Advanced Service Provider UAE IAR Reference: T7.7.1 72
CJISCIS ControlsCyber EssentialsCyber Essentials PlusDORAISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1Qatar NIASAMA CSFUAE IA
CO 8
Patch Management
Patch management procedure; patch status/tracking reports; obsolete-software register.
Are formal patching procedures defined, with obsolete-software restrictions and patch tracking?
2 sub-controls
  • CO 8.1 The entity shall define and establish formal procedures for updating and patching of information system and application, medical devices and equipment The entity shall: 1. Restrict The entity shall define and establish formal procedures for updating and patching of information system and application, medical devices and equipment The entity shall: 1. Restrict the usage of obsolete software/technology/medical devices/ equipment 2. Ensure all systems and devices that process or communicate information are timely patched and protected 3. Define criteria and process for application of standard, urgent and critical patches 4. Ensure all critical security patches are applied as soon as practicable from the date of release. 5. Ensure patches are deployed to a subset of systems or devices to allow testing before deployment to all. 6. Ensure firmware on devices are kept updated 7. Ensure security patches and updates are obtained from trusted sources and are periodically implemented 8. Ensure third parties provide advance notification to entity prior to the release of any patches or updates to the offered product or service 9. Periodically validate patch status of systems and devices in use Basic Service Provider
  • CO 8.2 The entity shall have mechanisms in place to keep track of the patches and updates Advanced 73 The entity shall have mechanisms in place to keep track of the patches and updates Advanced 73
CJISCIS ControlsCyber EssentialsCyber Essentials PlusDORAISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1Qatar NIASAMA CSFUAE IA
CO 9
Information Exchange
Information-exchange procedure & agreements; media-in-transit controls; messaging security config; UAE email-domain evidence.
Are secure information-exchange procedures, exchange agreements, physical-media protection and electronic-messaging controls in place (incl. UAE-domain email)?
7 sub-controls
  • CO 9.1 Information Exchange Procedures 4 Transitional T4.2.1 Information Exchange Procedures 4 Transitional T4.2.1
  • CO 9.2 The entity shall follow secure practices and capabilities for health information exchange The entity shall follow secure practices and capabilities for health information exchange. The entity shall: 1. Ensure health information is not transacted through medium of mails., unless it is being shared with the data subject. 2. Maintain chain of custody for information while in transit. 3. Connectivity with DoH (AD Healthcare Net) and provide all required information. 4. Ensure secure integration of Electronic Medical Records (EMR) platform to Abu Dhabi Health information Exchange Platform (Malaffi) 5. Ensure that entity resources are given access to Malaffi with the proper authorization and based established need to provide healthcare services 6. Ensure health information (in any form) PII and PHI or its copy is not stored, shared, processed, disseminated and/or transferred outside UAE, except in cases where a valid and specific exemption is issued by DoH is in place 7. Ensure that employees of the entity and third -party involved in service delivery of any kind, fulfill their responsibilities and provide assistance from within the Health Sector Stakeholder premise, and from within UAE, unless a valid exemption has been is sued by the Department of Health (DoH) 8. Not share identified or de -identified health information with third parties, data processors inclusive of counterparts and partners, unless authorized by Department of Health 9. Ensure that information exchanged between entities, and information sharing communities are protected 10. Ensure that username and password are communicated using two different communication channels (email and SMS-text, or email and phone, etc.) 11. Encrypt critical information before transferring and ensure sharing decryption key using a different communication channel Basic Service Provider 75 12. Ensure usage of appropriate interoperability standards for the exchange or transfer of information between systems and custom-developed applications 13.
  • CO 9.3 The entity shall establish agreements between the entity and the external parties for the exchange of information and software The entity shall, prior to the beginning of exchange The entity shall establish agreements between the entity and the external parties for the exchange of information and software The entity shall, prior to the beginning of exchange of information and software: 1. Brief and agree with the external parties on all security requirements to be included in the agreement with regards to the criticality and classification of the information to be exchanged 2. Agree on the process of notifying sender of transmission, dispatch and receipt 3. Clearly define roles and responsibilities of each party to the agreement 4. Establish non-disclosure agreements for all disclosures 5. Agree on the expiration date of the agreement 6. Include in the agreements: a) Definitions of information to be protected b) Classification of information to be shared c) Security requirements to be considered for information protection d) Duration of agreement e) Process for notification of leakage or incident f) Ownership for data protection g) Right to audit and monitor activities that involve health information and personally identifiable information h) Control requirements in handling the information in line with the defined asset handling policy Basic Service Provider 76
  • CO 9.4 The entity shall protect physical media containing information during transit The entity shall: 1. Identify and ensure that physical media containing sensitive information is class The entity shall protect physical media containing information during transit The entity shall: 1. Identify and ensure that physical media containing sensitive information is classified and labelled in accordance with the established classification scheme 2. Ensure that physical media in transit containing sensitive information is protected against: a) Information disclosure or leakage b) Loss of information or media c) Modification d) Unauthorized access 3. Ensure that physical media in transit containing sensitive information is adequately tracked 4. Ensure information in removable media is encrypted before transit 5. Utilize trusted entity staff or courier service for transporting media 6. Ensure that media is controlled and disposed as per the relevant policy Basic Service Provider
  • CO 9.5 The entity shall restrict the usage of public domain email address for any official purposes and ensure email IDs possess email domains within the UAE Basic Service Provider 77 The entity shall restrict the usage of public domain email address for any official purposes and ensure email IDs possess email domains within the UAE Basic Service Provider 77
  • CO 9.6 The entity shall protect information involved in electronic messaging The entity shall: 1. Identify and categorize all means of electronic messaging through which the entity inform The entity shall protect information involved in electronic messaging The entity shall: 1. Identify and categorize all means of electronic messaging through which the entity information can be transmitted 2. Define specific control requirements for each identified category of electronic messaging 3. Ensure exchange of information is based on need and are addressed to authorized and legitimate resources 4. Ensure restrictions are implemented regarding forwarding of communications (e.g., automatic forwarding of electronic mail to external mail addresses), as applicable 5. Ensure appropriate electronic signatures containing legal disclaimers are used for electronic messaging 6. Educate employees about the best practices to be followed for electronic messaging Transitional
  • CO 9.7 The entity shall develop, enforce and maintain procedures to secure information transferred across business information systems, EMR and medical devices, equipment etc The entity shall develop, enforce and maintain procedures to secure information transferred across business information systems, EMR and medical devices, equipment etc. The entity shall: 1. Identify all points of interconnections and integrations between business information systems and identify the information to be protected 2. Identify adequate measures to be applied to protect each type of information 3. Implement strong encryption capabilities for secure data exchange between medical devices and equipment, as applicable 4. Ensure integration of any device, solution and technology with EMR system and/or any critical infrastructure is protected by adequate measures such as encryption, secure protocols, dedicated physical connection etc. Advanced Service Provider UAE IAR Reference: T4.2.1, T4.2.2, T4.2.3, T4.2.4, T4.2.5 78
CJISCIS ControlsGDPR (EU)ISO 27001NCA ECC-2NCA OTCCNIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLQatar NIAPDPL – Federal Decree-Law 45/2021UAE IAUK GDPRNCA CCC
CO 10
Electronic Commerce
E-commerce security controls; transaction integrity controls; public-system content review process.
Is e-commerce / online-transaction information and publicly accessible information protected?
3 sub-controls
  • CO 10.1 The entity shall protect electronic commerce service and information involved passing over public and untrusted networks from service compromise and fraudulent activity, contract d The entity shall protect electronic commerce service and information involved passing over public and untrusted networks from service compromise and fraudulent activity, contract dispute, unauthorized disclosure and modification The entity shall: 1. Maintain a list of electronic commerce services along with details of: a) Service details and information involved b) Electronic commerce service provider and partner detail c) Beneficiary details 2. Identify and implement security measures to protect information used in electronic commerce services 3. Ensure security requirements are agreed and captured in service agreements with electronic commerce partners and regularly monitor the same Transitional Service Provider
  • CO 10.2 The entity shall protect information involved in online transactions against incomplete transmission, misrouting, unauthorized message alteration, unauthorized disclosure and unaut The entity shall protect information involved in online transactions against incomplete transmission, misrouting, unauthorized message alteration, unauthorized disclosure and unauthorized message duplication or replay The entity shall: 1. Identify all information used in online transactions 2. Identify and implement security measures to protect information used in online transactions 3. Ensure security requirements are agreed and captured in service agreements with partners involved in online transactions Transitional Service Provider 79
  • CO 10.3 The entity shall protect information available through the publicly accessible system The entity shall: 1. Identify all information available through the publicly accessible system The entity shall protect information available through the publicly accessible system The entity shall: 1. Identify all information available through the publicly accessible system 2. Establish process to publish and maintain information on the publicly accessible systems 3. Ensure information is sanitized and approved before publication 4. Define security measures to publish information on publicly accessible systems 5. Ensure that information available through the publicly accessible system is always available and is protected against unauthorized modification 6. Ensure non-public information is not available on publicly accessible information systems and systems are hosted in compliance with the applicable laws and regulations Advanced UAE IAR Reference: T4.3.1, T4.3.2, T4.3.3
UAE IACJISCIS ControlsNCA ECC-2ISO 27001NCA CCCPCI DSS 4.0.1Qatar NIASAMA CSF
CO 11
Information Sharing Platforms
List of information-sharing platforms; connection security requirements; secure-connectivity capability evidence.
Is connectivity to information sharing platforms secure and controlled, with a maintained list and defined security requirements?
1 sub-control
  • CO 11.1 The entity shall ensure that connectivity to information sharing platforms is secure and controlled The entity shall ensure that connectivity to information sharing platforms is secure and controlled. The entity shall: 1. Maintain a list of information sharing platforms that the entity connects to and/or operates. 2. Determine security requirements for connecting to or releasing information into identified information sharing platforms. 3. Establish security requirements for accessing entity-operated information sharing platforms. 4. Develop capabilities to establish secure connectivity to any required sector, national or international information sharing community.
CJISCIS ControlsGDPR (EU)ISO 27001NCA ECC-2NCA OTCCNIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLQatar NIAPDPL – Federal Decree-Law 45/2021UAE IAUK GDPRNCA CCC
CO 12
Network Security Management
Network management procedure; segregation/VLAN design; wireless site-survey & security config.
Are all networks managed and protected, segregated by criticality, and wireless networks secured?
3 sub-controls
  • CO 12.1 The entity shall ensure that all networks and supporting infrastructures are adequately managed, controlled and protected The entity shall: 1. Ensure that all network components an The entity shall ensure that all networks and supporting infrastructures are adequately managed, controlled and protected The entity shall: 1. Ensure that all network components and interconnections are identified and sufficiently documented, including documentation of updates and changes incorporated via the change management process 2. Ensure that network documentation includes up to date network architecture diagrams and configuration files of devices (e.g., routers, switches) 3. Prohibit the use of insecure protocols like FTP, Telnet and use only secure protocols such as HTTPS, SFTP 4. Ensure information assets operate with only minimum needed TCP/UDP ports and disable all unused/vulnerable ports, services and protocols 5. Identify threats and vulnerabilities affecting network components and network as a whole 6. Implement specific security controls to mitigate identified vulnerabilities 7. Continually monitor implemented controls for their efficiency and effectiveness Basic Service Provider 81
  • CO 12.2 The entity shall segregate physical, logical and wireless networks based on criticality, nature of services and user information systems The entity shall: 1. Establish criteria for network segregation The entity shall segregate physical, logical and wireless networks based on criticality, nature of services and user information systems The entity shall: 1. Establish criteria for network segregation. 2. Establish and maintain appropriate network security zones, allowing data flow through controlled path 3. Establish minimum and specific security requirements for each of the segregated networks, zones and resources 4. Ensure medical device and equipment network and Remote Patient Monitoring network is segregated from corporate network 5. Implement network segmentation and access control policy to allow permitted traffic to selected network devices. 6. Periodically evaluate the adequacy of implemented segregation strategy and identify areas of improvement Transitional
  • CO 12.3 The entity shall ensure that all wireless networks are adequately protected The entity shall: 1. Conduct site survey to determine the optimal physical location for the placement of The entity shall ensure that all wireless networks are adequately protected The entity shall: 1. Conduct site survey to determine the optimal physical location for the placement of wireless access -points or devices to avoid stray signal leaking outside the entity’s physical boundary 2. Ensure that wireless access points are configured to use strong authentication and cryptographic methods 3. Ensure public and guest access are segregated and isolated from the entity’s internal network Basic UAE IAR Reference: T4.5.1, T4.5.3, T4.5.4 82 6. Data Privacy and Protection Entities generate and utilize Personally Identifiable Information (PII) and/or Protected Health Information (PHI) and establish relations with individuals to give the information a persistent value during its lifecycle of usage and references. It is imperative that, entity implements controls to prevent the inappropriate, unintentional, unauthorized or illegal disclosure of any PII and PHI/PHI and to ensure that this standard is being followed. PII and PHI are comprised of diverse range of data, including but not limited to: a) Patient demographic data and general identifiers such as name, address, birth date, mobile number, Emirates ID, Email Address, Image, Vehicle number/License plate, Biometric data, IP Address etc. b) Information on past, present or future physical or mental health condition and the provision of health care to the patient, or details of medical insurance c) Financial Information i.e., Account number, Card details etc.
CJISCIS ControlsISO 27001NCA ECC-2NCA OTCCNIST CSFQatar NIAUAE IAPCI DSS 4.0.1
DP · Privacy and Protection Practices 3
DP 1
Privacy and Protection Practices
Data privacy policy; consent records; lawful-basis register; data processing inventory & DPIAs; breach procedure (incl. DoH notification).
Do you have a data privacy programme covering consent, lawful/fair/transparent processing, lifecycle protection, DPIAs, processor controls and breach handling for PII/PHI?
7 sub-controls
  • DP 1.1 The entity shall develop, enforce and maintain a data privacy policy that ensures management’s commitment to protect privacy of PII and PHI generated, collected and processed by th The entity shall develop, enforce and maintain a data privacy policy that ensures management’s commitment to protect privacy of PII and PHI generated, collected and processed by the entity The policy shall: 1. Define requirements on; a) Data Generation b) Data Collection c) Data Processing d) Data Security e) Data Localization f) Data Disclosure g) Data Retention h) Data management i) Data Subject 2. Identify and define government sanctions and legal obligations. 3. Include reference to organizational disciplinary process. 4. Include references to other policies and procedures, as applicable Basic Service Provider 84
  • DP 1.2 The entity shall implement measures to take consent from data subjects in the decision -making process while processing their PII and PHI The entity shall: 1. Restrict from process The entity shall implement measures to take consent from data subjects in the decision -making process while processing their PII and PHI The entity shall: 1. Restrict from processing PII and PHI without the consent of the data subject, except for: a) Processing shall be necessary to protect public interest. b) Processing shall be related to PII and PHI which became available and known by all by the act of the data subject. c) Processing shall be necessary to establish or defend any of the procedures for claiming or defending rights and legal claims or related to judicial or security procedures. d) Processing shall be necessary for the purposes of medical diagnosis, provide health treatment, health insurance services, manage health systems and services in accordance with the applicable legislation. e) Processing shall be necessary to protect public health and include protection from communicable diseases and epidemics or for the purposes of ensuring the safety and quality of health care, medicines, drugs and medical devices in accordance with the applicable legislation. f) At the written request of the patient (UAE national or non-national) not residing in UAE and getting non - emergency medical services as a medical tourist in a healthcare facility licensed by Department of Health, Abu Dhabi Basic Service Provider 85 g) At the request of the regulatory body(ies) for the purposes of inspection, supervision and protection of public health. h) Information exchange with Malaffi i) Processing shall be necessary to protect the data subject interests. j) Processing shall be necessary to implement specific obligations in line with applicable legislation. k) Processing shall be necessary for the completion of employment related activities. 2. Collect and store informed consent by the data subject or his/her designated representative. 3. Ensure the consent is prepared in clear, simple, and unambiguous way and is easily accessible (written or electronic) 4.
  • DP 1.3 The entity shall ensure Lawful, Fair and Transparent Processing of PII and PHI The entity shall: 1. Ensure to have an appropriate lawful basis (or bases if more than one purpose) f The entity shall ensure Lawful, Fair and Transparent Processing of PII and PHI The entity shall: 1. Ensure to have an appropriate lawful basis (or bases if more than one purpose) for processing personal data. 2. Collect sufficient and limited PII and PHI, necessary in accordance with the purpose for which the processing has to be carried out. 3. Implement measures to ensure that PII and PHI is not issued in a manner incompatible with the purpose. 4. Implement controls to ensure accuracy of PII and PHI throughout lifecycle with measures for updating it, as requested by data subject. 5. Implement controls for deletion of PII and PHI after the purpose of processing has been exhausted or in line with entity retention policy 6. Ensure compliance with requirements of applicable privacy laws and regulations Transitional Service Provider 86
  • DP 1.4 The entity shall implement appropriate technical and organizational measures for maintaining security and privacy of PII and PHI throughout its lifecycle The entity shall implement appropriate technical and organizational measures for maintaining security and privacy of PII and PHI throughout its lifecycle. The entity shall: 1. Implement information security policies, procedures, and technical controls in accordance with the requirements of this standard and the risks associated with processing PII and PHI. These include but not limited to: a) System controls: User access measures (E.g.: Physical and Logical Access Controls), Network Security, Data Security, Data concealment etc.). b) Process controls: Data classification policies, data backup and retention policy, compliance audits etc. c) People controls: Signing of Non -Disclosure Agreements (NDAs) and Data Processing Agreements (DPAs), Trainings, awareness, Employee background checks, and / or any other project specific requirements. 2. Ensure printing of PII and PHI is limited to local printers and avoid printing through uncontrolled printers 3. Ensure that only people who are physically present in the UAE or who have a valid license issued by DoH to practice their profession there, have access to systems and applications that contain PII and/or PHI. Any exemptions must be approved by entity manag ement and then submitted to the DoH for approval. 4. Ensure health information and its copies in any form, whether encrypted, anonymized, deidentified, pseudonymized, etc., are not stored, processed, or transferred outside the UAE. Any exemptions must be approved by entity management and then submitted to th e Department of Health (DoH) for further approval. 5. Access to health data shall be limited to healthcare professionals, insurance processing individuals and/or breach/compromise investigating individuals. 6. Access to health information, inclusive of personal health information and personally identifiable information, by healthcare professionals shall be based on established need (e.g.
  • DP 1.5 The entity shall prepare Data Processing Inventory to keep track of PII and PHI stored, processed and managed and conduct Data Privacy Impact Assessment (DPIA) before implementing The entity shall prepare Data Processing Inventory to keep track of PII and PHI stored, processed and managed and conduct Data Privacy Impact Assessment (DPIA) before implementing or acquiring information technology that stores, process, or transfers PII and PHI and/or before initiating any processing activity if it is likely to result in high risks The entity shall: 1. Ensure that the Data Processing Inventory captures information including but not limited to: a) Description of the categories of PII and PHI b) Details about the data subject c) Individuals authorized to access personal healthcare d) Period, purpose, limitation and scope e) Details about data exchange/transfer f) Mechanism of transfer, deletion, modifying or processing g) Data related to the cross-border movement, if any h) Technical and organizational measures related to information security and processing operations 2. Ensure DPIA template includes at a minimum of the following: a) Documented necessity, suitability and purpose of proposed processing operations b) Assessment of potential risks and impacts on the security of PII and/or PHI c) Documented plan of action to mitigate the risks and ensure security of PII and/or PHI d) Keep the Data Processing Inventory updated and periodically review DPIA output to assess the processing operations 3. Conduct a DPIA reassessment in response to changes in the risks associated with the processing activity Advanced 88
  • DP 1.6 The entity shall implement measures to ensure that the involved third parties and/or data processors have controls in place for PII and PHI The entity shall: 1. Only appoint a thir The entity shall implement measures to ensure that the involved third parties and/or data processors have controls in place for PII and PHI The entity shall: 1. Only appoint a third party and data processor that has sufficient technical and organizational measures that fulfil the secure processing requirements 2. Document security requirements within the third -party service level agreements 3. Address requirements in case of sub -contracting through contracts and service agreements 4. Ensure the third party / data processor processes data only for agreed purpose and duration and deletes the data once purpose is accomplished 5. Ensure the third parties and data processor notify the entity in case of: a) Appointment of sub-contractors b) Security incident and data breach c) Processing PII and/or PHI beyond agreed time-period Basic Service Provider 89
  • DP 1.7 The entity shall ensure that PII and PHI breaches are detected, reported, prioritized and handled effectively The entity shall: 1. Inform DoH about breach at the entity and/or the The entity shall ensure that PII and PHI breaches are detected, reported, prioritized and handled effectively The entity shall: 1. Inform DoH about breach at the entity and/or the relevant third party/data processor within predetermined timelines. Refer: Guidelines for the Implementation of the Abu Dhabi Health information and Cyber Security Standard –
CJISCIS ControlsGDPR (EU)ISO 27001NCA ECC-2NCA OTCCNIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLQatar NIAPDPL – Federal Decree-Law 45/2021UAE IAUK GDPRNCA CCC
DP 2
Appointment of Data Protection Officer
DPO appointment letter; DPO qualifications; applicability assessment.
Have you appointed a suitably skilled Data Protection Officer where required?
1 sub-control
  • DP 2.1 The entity and the involved data processor shall appoint a Data Protection Officer (DPO) with sufficient skills and knowledge to protect protected health information if: a) Entity The entity and the involved data processor shall appoint a Data Protection Officer (DPO) with sufficient skills and knowledge to protect protected health information if: a) Entity is processing large volumes of PII and PHI b) There is high risk due to automated and processing through technologies. c) Entity is performing profiling and comprehensive assessment of PII and PHI The entity shall: 1. Ensure there is no conflict of interest between the DPO’s role, and the tasks assigned 2. Ensure contact address of the data protection DPO is well communicated to all Data Subject Advanced 91
CJISCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPRPCI DSS 4.0.1
DP 3
Data Subject Rights
Data-subject-rights procedure; sample request log & responses.
Can you fulfil data subject rights requests (access, correction, etc.) for PII/PHI?
1 sub-control
  • DP 3.1 The entity shall ensure protection of data subject rights while processing their PII and PHI The entity shall: 1. Fulfil data subject’s request for: a) Obtaining information about The entity shall ensure protection of data subject rights while processing their PII and PHI The entity shall: 1. Fulfil data subject’s request for: a) Obtaining information about their PII and PHI i.e., Type of processing, purpose of processing, sharing of data, security controls, breach management process etc. b) Transferring of their PII and PHI (to the data subject / another data controller) c) Correction and deletion of their PII and PHI d) Restriction on further processing of their PII and PHI or retaining the data for defending rights and lawsuits e) Objection to results of automated data processing and profiling 2. Keep records of PII and PHI information sharing and disclosures 3. Based on request from the data subject, Transfer the PII and/or PHI to the data subject in machine-readable format 4. Reject data subject’s request to exercise its rights, if the following becomes evident: a) Request is inconsistent with the judicial procedures or investigations or matters of public interest b) Deletion of data request conflicts with any applicable legislation to which the entity is subjected to c) Request may negatively affect the efforts of the controller to protect information security d) Restriction request conflicts with consent Exemption conditions e) Request violates the privacy and confidentiality of others personal data f) Prior contract or consent is available for automated processing Transitional Service Provider UAE IAR Reference: M5.2.4 92 7. Cloud Security Cloud services and resources provide entities with options for quick adaptation and scalability. Its critical, that foundational and essential aspect of security control are considered from the concept stage to better handle threats, technological risks, and protections of cloud environments Entity shall implement procedures, personnel, physical and technical controls through their cloud journey, to ensure security of cloud-based data, applications, infrastructure.
UK GDPRGDPR (EU)PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021
CS · Cloud Security 1
CS 1
Cloud Security Policy
Cloud security policy; shared-responsibility matrix; cloud control configuration evidence.
Do you have a cloud security policy and implement controls (incl. shared-responsibility model) to protect cloud environments?
2 sub-controls
  • CS 1.1 The entity shall develop, enforce, and maintain a Cloud Security Policy to protect the confidentiality, integrity and availability of all IT applications, data, systems and network The entity shall develop, enforce, and maintain a Cloud Security Policy to protect the confidentiality, integrity and availability of all IT applications, data, systems and network resources implemented in a cloud environment and ensure cloud services are acquired, used, managed, and terminated in conformity wi th all applicable laws and regulations. The policy shall: 1. Be relevant and appropriate to the entity’s cloud security demands and applicable legal and regulatory compliance requirements 2. Demonstrate management commitment, objectives and directions 3. Establish a process that facilitates: a) Selection of suitable cloud service provider and scope of cloud services usage b) Identification of suitable information security requirements c) Signing of Service Level Agreements (SLAs) and Non - Disclosure Agreements (NDAs) d) Assignment of roles and responsibilities related to use and management of cloud services e) Agreement on data retention, portability and destruction requirements Basic 94
  • CS 1.2 The entity shall identify and ensure implementation of information security controls to protect their cloud environment against evolving threats and risks: The entity shall: 1. Imp The entity shall identify and ensure implementation of information security controls to protect their cloud environment against evolving threats and risks: The entity shall: 1. Implement the Shared responsibility model for information security of the cloud and ensure that the duties for managing information security in the cloud are assigned to recognized parties, effectively communicated, and executed 2. Ensure cloud environment is physically hosted within UAE without any of the environments, infrastructures, or systems outside the country including backup and disaster recovery 3. Ensure data/health information stored in cloud is not extended for access, use or support by; a) Any other entity/party in a multi-tenant environment. b) Any entity/party that provides analytical services, where the data or copy of data is transferred/sent outside country c) Any entity/party that provides remote support from outside UAE 4. Ensure data-at-rest, data-in-transit/motion is always encrypted 5. Ensure the key used to encrypt data -at-rest and data -in- transit/motion is not provided by the cloud service provider who provides the application, infrastructure and data hosting services 6. Protect data during processing in a cloud environment 7. Procure cloud service that provides feature to generate or configure entity’s own cryptographic keys to be used for applications and services in cloud 8. Ensure the cloud service provider does not store and control the entity's cryptographic keys 9. Ensure role-based security training and awareness is provided to the resources handling cloud environment 10. Engage independent external party to conduct testing of service design, service components and implemented security controls in the cloud 11. Ensure procedures are in place for ease of migration/portability for on -prem to cloud and cloud -to-cloud infrastructure, as required Transitional Service Provider 95 12.
CJISCIS ControlsISO 27001NCA CCCNCA ECC-2Qatar NIASAMA CSFUAE IADORAGDPR (EU)HIPAA Security RuleNCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021UK GDPR
TP · Third Party Security 2
TP 1
Third Party Security Policy
Third-party security policy; approval & review record.
Do you have an approved third-party security policy?
1 sub-control
  • TP 1.1 The entity shall develop, enforce and maintain a third-party security policy to facilitate implementation of the associated controls and to reduce probabilities of risk realization The entity shall develop, enforce and maintain a third-party security policy to facilitate implementation of the associated controls and to reduce probabilities of risk realization concerning third parties. The policy shall: 1. Be relevant and appropriate to the relationship of the entity and the third party 2. Outline roles and responsibilities for managing the third party 3. Establish a process that facilitates: a) Security due diligence of third -party services before appointment b) Secure management of third-party services and their role in healthcare and/or related services c) Defining and including information security objectives in line with applicable mandates and/or requirements of entity d) Third party briefing of security requirements e) Security requirements for sub-contracting f) Signing service delivery agreements & non -disclosure agreements (NDAs) with third parties SLA definition and Performance monitoring 4. Demonstrate management’s commitment, objectives and directions Basic UAE IAR Reference: T6.1.1 98
CJISCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPRNCA CCC
TP 2
Third Party Service Delivery and Monitoring
Third-party agreements with security clauses/SLAs; monitoring & review reports; change-control records.
Are third-party security requirements/SLAs enforced, monitored and changes controlled through a formal process?
3 sub-controls
  • TP 2.1 The entity shall identify and enforce information security requirements, service levels and management requirements as part of relevant third -party service agreements In case the The entity shall identify and enforce information security requirements, service levels and management requirements as part of relevant third -party service agreements In case the agreements are non -negotiable, the entity shall ensure that the risks are clearly identified and accepted by the management. The entity shall: 1. Define and document the type of information that third-party/service provider needs or will have access to 2. Identify security requirements to address the perceived risk associated with the services and mandates of this standard 3. Ensure that specific security requirements are included in the service delivery agreement 4. Ensure third party does not seek to use the entity's data for their own advantages or requirements 5. Include third party data center security requirements as part of the agreement, as applicable 6. Ensure the agreements cover technical support required from third parties throughout tenure of service and beyond till data is to be retained 7. Promptly notify DoH within defined timelines, in the event of any information security incident involving the third party or the service they deliver/support 8. Ensure the third party provides required support in the event of any information security incident within the scope and duration of the third-party service entity Basic Service Provider 99 9. Identify and include Right -to-Audit terms specific to the provisions and environment of service management to manage information security risks 10. Coordinate with entity contract management and legal teams for third party service requirements that needs the storing, processing and transmission of health and/or personally identifiable information 11. Ensure agreement includes termination clauses and transition support required from the third - party during entity decision to exit agreement and/or use another service/solution 12.
  • TP 2.2 The entity shall monitor, and review services provided, reports and records submitted by third parties The entity shall; 1. Monitor compliance of security requirements identified i The entity shall monitor, and review services provided, reports and records submitted by third parties The entity shall; 1. Monitor compliance of security requirements identified in agreements with third parties 2. Conduct security assessments and audits in accordance with this standard's applicable mandates and the entity's information security needs 3. Implement controls for authenticating and monitoring the exchange of information between various parties to ensure security compliance 4. Assess and manage business, commercial, financial and legal risk associated with third party services Advanced
  • TP 2.3 The entity shall regulate/control changes to the provisions of the signed third-party agreement through a formal management process The entity shall: 1. Ensure that changes to acti The entity shall regulate/control changes to the provisions of the signed third-party agreement through a formal management process The entity shall: 1. Ensure that changes to activities and provisions in the agreement are in compliance with security requirements 2. Include as part of the agreement, formal processes to manage changes in the agreement 3. Define parameters of change that shall be communicated and agreed between the entity and the third party Transitional UAE IAR Reference: T6.2.1, T6.2.2, T6.2.3 101 9. Information Systems Acquisition, Development, and Maintenance Entity management shall implement appropriate information systems acquisition, development, and maintenance process to avoid unauthorized alteration or misuse of information/configurations in applications, to maintain security during the in -house and outsourced development lifecycle and support procedures, and to assure protection of data used for testing. Based on detailed assessment and entity risk appetite, the entity’s management shall choose from one of the below options: a) In-house development, maintenance and support of application and systems b) Outsource the development, maintenance and support of application and systems c) Out-of-shelf product deployment, maintained and supported by the vendor d) Cloud-based application utilization e) Hybrid approach for the development, maintenance, and support requirements Objective: To emphasis the need for adoption of secure system and software development lifecycle management processes and to ensure that systems and applications in use are securely managed and supported to avoid misuse of privileges and authority, reduce probabilities of information, system and application compromises, and to uphold entity and Abu Dhabi government’s reputational value and public trust. Supporting or dependent entity policy references: i. Access Control Policy ii. Communications and Operations Management Policy iii. Third Party Security Policy iv.
CJISCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
SA · Information Systems Acquisition, Development, and Maintenance 6
SA 1
Information Systems Acquisition, Development, and Maintenance Policy
SA/SDLC policy; approval & review record.
Do you have a secure systems acquisition, development & maintenance policy?
1 sub-control
  • SA 1.1 The entity shall develop, enforce and maintain an information systems acquisition, development and maintenance policy to facilitate implementation of secure system development and The entity shall develop, enforce and maintain an information systems acquisition, development and maintenance policy to facilitate implementation of secure system development and maintenance practices The policy shall: 1. Be relevant and appropriate to the model and relationship of the entity and involve internal and external stakeholders 2. Demonstrate management’s commitment, objectives and directions 3. Establish a process that facilitates: a) Defining and including information security objectives b) Identification and mitigation of risks in involved business and application processes c) Selection of the right model and approach d) Definition of roles and responsibilities 4. Establish management expectations on: a) Privacy and protection of information assets b) Secure design, development, testing, deployment, maintenance and support c) Secure access to systems, applications, devices, and equipment d) Secure processing and communication of information and data e) Non-disclosures requirements f) Cryptographic controls and requirements Basic UAE IAR Reference: T7.1.1, T7.4.1 103
CJISCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
SA 2
Security Requirement of Information Systems and Applications
Secure SDLC standard; developer training records; validation/control evidence.
Are security engineering principles, developer training and input/data validation applied to systems and applications?
4 sub-controls
  • SA 2.1 The entity shall apply security engineering principles in the specification, design and development of new information systems, medical devices and equipment , applications or enha The entity shall apply security engineering principles in the specification, design and development of new information systems, medical devices and equipment , applications or enhancements to existing systems, devices and applications The security requirement shall: 1. Be relevant to be used for new information assets or enhancements to existing information assets 2. Be approved by individuals authorized to do so on behalf of business and information security 3. Address all risk elements identified during risk assessments throughout the system development lifecycle 4. Address risks from all software components, medical device and equipment 5. Consider additional/compensating controls if design level risk mitigations are not possible 6. Be compliant with the requirements of this standard and secure coding practices 7. Outline validation criteria to verify security control efficiency and effectiveness. 8. Ensure no activity in development lifecycle is carried out outside the boundaries of UAE 9. Define system acceptance criteria. 10. Ensure maintenance of High -Level Design and low -level design of the System Architecture with descriptive details of every component in the architecture along with their interconnectivities Transitional Service Provider 104
  • SA 2.2 The entity shall ensure developer of information systems, system components or information system services are provided suitable training prior to their involvement in development The entity shall ensure developer of information systems, system components or information system services are provided suitable training prior to their involvement in development activities The entity shall: 1. Identify baseline training requirements that are essential for the developer 2. Acknowledge that developer(s) received relevant baseline training prior to their involvement in development activities 3. Identify training requirements based on implemented security functions and features 4. Design and execute training programs to address additional and future security requirements 5. Include training requirement in agreements when the requirements are delivered and managed by third parties Advanced UAE IAR Reference: T7.2.1, T7.2.2 105 Control Demands Control Criteria Basic/Transitional/Advanced
  • SA 2.3 The entity shall incorporate validation checks into applications to detect any corruption and to ensure data is correct and appropriate The entity shall: 1. Define criteria, rules The entity shall incorporate validation checks into applications to detect any corruption and to ensure data is correct and appropriate The entity shall: 1. Define criteria, rules and validation parameters to validate data input into applications 2. Develop or configure applications to reject input data that is identified as incorrect or inappropriate 3. Establish minimum requirements for validation checks on internal processing of application under development to ensure correct processing of data a) Ensure application developers to provide evidence of compliance with minimum requirements b) Ensure that the incorporated validation checks are valid and relevant over a period of time and meet minimum requirements through the applications’ lifecycles 4. Identify and enforce requirements to ensure authenticity and integrity of messages transmitted between systems and applications 5. Define criteria, rules and validation parameters to validate data output from applications Transitional Service Provider SA2.4 The entity shall ensure that all distributed and mobile applications are designed with the ability to tolerate communication failure Distributed and mobile applications shall: 1. Include off-line and duplicate or out-of-sequence response message handling capabilities Transitional Service Provider UAE IAR Reference: T7.3.1, T7.3.2, T7.3.3, T7.3.4 106
  • SA 2.4 Off-line Processing Capabilities 1 Transitional Service Provider T7.3.2 Off-line Processing Capabilities 1 Transitional Service Provider T7.3.2
CJISCIS ControlsGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1Qatar NIASAMA CSFUAE IAUK GDPR
SA 3
Cryptographic Controls
Cryptography/key-management policy; encryption standards (at rest/in transit); key management evidence.
Are cryptographic controls used effectively (encryption, key management) to protect health information?
1 sub-control
  • SA 3.1 The entity shall ensure cryptographic controls are used effectively to protect health information based on the needs of regulatory requirements and risk environment The entity shall ensure cryptographic controls are used effectively to protect health information based on the needs of regulatory requirements and risk environment. The entity shall: 1. Use encryption for the protection of information stored and transmitted within and outside entity. 2. Establish key management process to: a) Securely generate and use cryptographic keys for applicable systems and applications. b) Securely share keys with authorized users c) Protect keys against modification, loss and destruction d) Set date of activation and deactivation for keys e) Revoke/block keys, as needed f) Backing up or archiving keys g) Recover keys that are lost or corrupted h) Replace keys when they are weakened or compromised i) Monitoring of key management related activities 3. Define standards for: a) Key strength for various environments b) Key storage Transitional Service Provider UAE IAR Reference: T7.4.1, T7.4.2 107
UAE IACJISCIS ControlsGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUK GDPRDORA
SA 4
Security of System Files
Software-installation control; source-code access restrictions; test-data handling procedure.
Is software installation controlled and are test data and source code protected?
2 sub-controls
  • SA 4.1 The entity shall control the installation of software on operational systems The entity shall: 1. Ensure software installations are carried out only by authorized resources and for The entity shall control the installation of software on operational systems The entity shall: 1. Ensure software installations are carried out only by authorized resources and for justified business need 2. Keep a copy of all software installed, including any previous versions 3. Adhere to software standards and ensure only licensed software is installed on an entity system 4. Ensure that no unauthorized software is installed on entity system and maintain an up-to-date inventory of authorized software that is necessary for the entity's business needs 5. Ensure software installed in production systems are subject to entity change management process and approval Transitional Service Provider
  • SA 4.2 The entity shall protect system test data and restrict access to program source code The entity shall: 1. Use sample data sets to test application, business and security functional The entity shall protect system test data and restrict access to program source code The entity shall: 1. Use sample data sets to test application, business and security functionalities 2. Restrict the use of real data from production systems for testing, 3. Ensure health information is anonymized before being made available for testing and training purpose. 4. Maintain records of copying, using and erasing of operational information in test environment 5. Ensure that personally identifiable information is not used as test data 6. Erase any data from test applications immediately after completion of the test 7. Ensure that access to program source code is strictly based on need and is in compliance with entity access control policy Transitional Service Provider UAE IAR Reference: T7.5.1, T7.5.2, T7.5.3 108
CJISCIS ControlsCyber EssentialsCyber Essentials PlusGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
SA 5
Outsourced Software Development
Outsourced-development agreement with security requirements; code review/acceptance evidence.
Is outsourced software development supervised and controlled to secure engineering standards?
1 sub-control
  • SA 5.1 The entity shall supervise and have control over outsourced software development The entity shall: 1. Ensure that the outsourced development adheres to secure engineering principle The entity shall supervise and have control over outsourced software development The entity shall: 1. Ensure that the outsourced development adheres to secure engineering principles and the entity holds sole custody of the source code and source code backups. 2. Define acceptance and quality assurance processes 3. Include in the outsourced software development agreement the requirement to comply with: a) All relevant entity policies, including information security and quality related policies, requirements and functionalities b) Provisions of this Standard c) Regulatory and legal requirements d) Industry specific secure coding practices 4. Include in the agreement the right to audit clause 5. Conduct source code review, security assessments to identify potential vulnerabilities, back-door and malicious code 6. Control the number, rotation and termination of staff involved in outsourced development activities to restrict: a) Unauthorized access b) Leakage of information c) Information compromise Transitional Service Provider UAE IAR Reference: T7.6.5 109
CJISCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
SA 6
Supply Chain Management
Supplier security requirements; supply-chain risk strategy; critical-supplier/second-source register.
Do you manage supply-chain risk — supplier conformance, strategy, deficiency handling and supply assurance for critical assets?
4 sub-controls
  • SA 6.1 Prior to procurement, it is imperative for the entity to ensure that all highly critical third-party products and services conform to the information security requirements as well Prior to procurement, it is imperative for the entity to ensure that all highly critical third-party products and services conform to the information security requirements as well as comply with relevant laws, regulations, circulars, and standards Basic Service Provider
  • SA 6.2 The entity shall develop a comprehensive information security strategy against supply chain threats to the information systems and application, medical devices and equipment The en The entity shall develop a comprehensive information security strategy against supply chain threats to the information systems and application, medical devices and equipment The entity shall: 1. Define an evaluation process for suppliers of information systems, system components, medical devices and services 2. Agree with suppliers of systems, applications, medical devices equipment, related products/services on control measures and include them in the supplier contract 3. Limit sharing of configuration and architecture with suppliers 4. Limit the amount of information you share with suppliers; only share essential and relevant information on need-to- know basis through a secure channel. 5. Define acceptance criteria for all new systems and device purchases and ensure information systems, system components, and medical devices are genuine and are satisfying system acceptance requirements 6. Ensure software delivered has not been altered or modified 7. Procure and use medical devices/equipment that incorporates security features to strengthen the protection and integrity of the devices/equipment e.g., specialized security chips/coprocessors that integrate security into the devices 8. Include in the supplier contract: a) Right-to-Audit clause Advanced Service Provider 110 b) Non-disclosure requirements c) Terms to comply with entity information security policy and requirements d) Terms to comply with relevant federal and local government requirements
  • SA 6.3 The entity shall establish processes to address weakness or deficiencies in supply chain elements The entity shall: 1. Identify and document supply chain elements and their interde The entity shall establish processes to address weakness or deficiencies in supply chain elements The entity shall: 1. Identify and document supply chain elements and their interdependencies 2. Identify and address issues concerning supply chain elements 3. Conduct regular assessments and audits of supply chain elements Advanced Service Provider
  • SA 6.4 The entity shall ensure adequate supplies of critical information systems, medical devices and system/devices components The entity shall: 1. Engage with more than one supplier for The entity shall ensure adequate supplies of critical information systems, medical devices and system/devices components The entity shall: 1. Engage with more than one supplier for critical products and systems 2. Establish contingency plans for the supply of any critical information systems, medical devices and system/device components 3. Consider stockpiling of essential and critical spare components Advanced UAE IAR Reference: T7.8.1, T7.8.2, T7.8.3, T7.8.4, T7.8.5, T7.8.6, T7.8.7 111 10. Information Security Incident Management Entity’s management shall be aware that information security incidents may not always be preventable, the frequency, severity, and impact on an entity's assets, reputation, financial situation, and legal standing can all be reduced with the implementation of suitable policies, processes, and technology for detection, reporting, and handling, together with education, awareness, and training. Information security incidents shall be reported, and evidence of security incidents shall be collected and analyzed to ensure that information security events and weaknesses are properly communicated and security incidents adequately managed. Objective: To ensure that entity define and utilize suitable processes and resources to identify and respond to information security and privacy incidents, that they are not severely impacted by incident outcomes and that they are able to restore affected operations within an acceptable timeframe. Supporting or dependent entity policy references: i. Access Control Policy ii. Communications and Operations Management Policy iii. Third Party Security Policy iv. Compliance Policy v. Data Privacy Policy 112
CJISCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
IM · Information Security Incident Management 3
IM 1
Information Security Incident Management Policy
Incident management policy; approval & review record.
Do you have an approved information security incident management policy?
1 sub-control
  • IM 1.1 The entity shall create, implement, and uphold an incident management policy to ensure that information security and privacy incidents are addressed and managed properly, enabling The entity shall create, implement, and uphold an incident management policy to ensure that information security and privacy incidents are addressed and managed properly, enabling prompt corrective and preventive actions. The policy shall: 1. Be relevant and appropriate to the entity’s operation and risk environments. 2. Demonstrate management commitment, objectives and directions 3. Establish incident management roles and responsibilities 4. Establish a proactive, collaborative and sustainable process of identifying and resolving adverse information security and privacy incidents. 5. Establish management demands on: a) Incident identification b) Incident response c) Incident notification/communication d) Containment & Eradication e) Learning from incident Basic UAE IAR Reference: T8.1.1 113
CJISCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
IM 2
Incident Management and Improvements
Incident response procedure; CSIRT charter & roster; classification scheme (DoH matrix); test/exercise reports; incident log.
Are incident procedures, a CSIRT, classification, response testing and incident records in place?
5 sub-controls
  • IM 2.1 The entity shall establish incident management procedure to guide information security and cybersecurity response activities The entity shall: 1. Have procedures to handle incident The entity shall establish incident management procedure to guide information security and cybersecurity response activities The entity shall: 1. Have procedures to handle incident during preparation, detection, analysis, containment, eradication, and recovery 2. Clearly document roles and responsibilities of the relevant stakeholders and management 3. Establish a formal channel for entity and external stakeholders to report information and privacy events and weakness in any information asset as soon as they are identified 4. Assess information security events and/or alerts and determine if they are to be categorized as incident 5. Inform Abu Dhabi Health SOC of the information security and privacy incidents within predetermined timeframes Refer: Guidelines for the implementation of the ADHICS –
  • IM 2.2 The entity shall establish a Computer Security Incident Response Team (CSIRT) or equivalent responsible for incident management and response efforts The entity shall: 1. Establish The entity shall establish a Computer Security Incident Response Team (CSIRT) or equivalent responsible for incident management and response efforts The entity shall: 1. Establish CSIRT organization with adequate authority, essential roles and responsibilities 2. Identify and nominate competent resources for each identified role of the CSIRT 3. Establish communication and response protocols 4. Allocate adequate funds for CSIRT operations 5. Ensure CSIRT coordinates with its counterparts and DoH for incidents which have significant impact on the entity’s assets or operations. 6. Conduct information security forensic analysis, as required 7. Participate in forensics and the national incident response effort, as required 8. Identify impactful reoccurring incidents and implement controls to reduce the recurrence 9. Ensure lessons learnt from past information security incidents are maintained and shared with relevant stakeholders to aid in: a) Addressing future information security incidents b) Minimizing the recurrence of such incidents 10. Build knowledge database on information security incident diagnosis and response. 11. Provide suitable training to members of the CSIRT to cover: a) Past incidents and lessons learnt b) Current threat environment of the entity c) New threats and attack trends across the world Advanced 115
  • IM 2.3 The entity shall assess and classify information security incidents The entity shall: 1. Establish an incident classification scheme which captures the requirements of matrix recom The entity shall assess and classify information security incidents The entity shall: 1. Establish an incident classification scheme which captures the requirements of matrix recommended by DoH. Refer: Guidelines for the implementation of the Abu Dhabi Health information and Cyber security Standard –
  • IM 2.4 The entity shall test its Computer Security incident response capabilities The entity shall: 1. Develop test procedures to validate the effectiveness of its incident response capab The entity shall test its Computer Security incident response capabilities The entity shall: 1. Develop test procedures to validate the effectiveness of its incident response capabilities periodically 2. Establish the expected outcome of test and compare test results to identify gaps 3. Modify process and procedures to address gaps identified 4. Share test results with the management Transitional 116
  • IM 2.5 The entity shall document and preserve records on all information security incidents The entity shall document and preserve records on all information security incidents. The entity shall: 1. Identify all relevant data and evidence to be collected during and after realization of an information security incident. 2. Establish procedures for collecting evidence considering the: a) Chain of custody b) Safety of evidence c) Safety of personnel d) Roles and responsibilities of personnel involved e) Competency of the personnel f) Documentation g) Briefing h) Other identified requirements 3. Prepare a damage assessment report 4. Conduct a post incident analysis and implement controls identified as recommendations 5. Preserve documents, records, reports and evidences in compliance with the entity’s retention policy Transitional UAE IAR Reference: T8.2.1, T8.2.2, T8.2.3, T8.2.4, T8.2.5, T8.2.6, T8.2.7, T8.2.8, T8.2.9, T8.3.2, T8.3.3 117
CJISCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPRNCA CCC
IM 3
Information Security Events and Weakness Reporting
Event/weakness reporting procedure; threat-intel sources/membership; sample reports.
Do you report security events/weaknesses and participate in information-sharing/threat-intel communities?
1 sub-control
  • IM 3.1 The entity shall develop a situational awareness culture by participating in the information sharing community and obtaining cybersecurity information from various sources The enti The entity shall develop a situational awareness culture by participating in the information sharing community and obtaining cybersecurity information from various sources The entity shall: 1. Identify priority information and share it internally to build the entity’s business model based-context 2. Ensure all identified cybersecurity information is relevant to the: a) Entity’s business operations b) Entity’s information system and application, medical devices and equipment c) Entity’s processes and control environment d) Entity’s risk environment 3. Establish and coordinate with the healthcare sector regulator of Abu Dhabi to receive relevant cybersecurity information Advanced UAE IAR Reference: T8.3.1 118 11. Information Systems Continuity Management Entity shall have proactive strategies and plans in place to counteract interruptions to entity operations and to protect critical business operations and processes from the consequences of significant information system, medical device and/or equipment failures to enable timely resumption of affected processes. Objective: To ensure systems, applications and resources are available to support service continuity requirements of identified critical services and processes during adverse situations or environment. Supporting or dependent entity policy references i. Incident Management Policy ii. Business Continuity Policy iii. Business Continuity and Recovery Plan iv. Communications and Operations Management Policy v. Compliance Policy vi. Backup Policy 119
CJISCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
SC · Information Systems Continuity Management 2
SC 1
Information Systems Continuity Management Policy
Continuity planning policy; approval & review record.
Do you have an approved information systems continuity planning policy?
1 sub-control
  • SC 1.1 The entity shall develop, enforce and maintain an information systems continuity planning policy to manage scenarios that challenge the continued availability of information system The entity shall develop, enforce and maintain an information systems continuity planning policy to manage scenarios that challenge the continued availability of information systems and applications supporting critical business services The policy shall: 1. Be relevant and appropriate to the entity’s information systems and applications continuity demands 2. Demonstrate management commitment, objectives and directions 3. Establish roles and responsibilities of involved stakeholders 4. Establish management expectations on: a) Planning for information system, medical device, equipment and application continuity during adverse situations b) Ensuring Information security during business continuity and disaster recovery c) Compliance with organizational business continuity plans d) Testing of continuity and restoration plans Advanced UAE IAR Reference: T9.1.1 120
CJISCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPRNCA CCC
SC 2
Information Systems Continuity Planning
Business Impact Analysis; continuity/recovery plans (RTO/RPO); test results & maintenance records.
Have you conducted a BIA and developed and tested information systems continuity & recovery plans?
3 sub-controls
  • SC 2.1 The entity shall conduct Business Impact Analysis (BIA) to capture information necessary to predict the impact of a critical information systems medical devices, equipment and appl The entity shall conduct Business Impact Analysis (BIA) to capture information necessary to predict the impact of a critical information systems medical devices, equipment and application failure and gather information to define the strategies to mitigate or minimize the risk The entity shall: 1. Perform Risk Assessment to identify points of failure and understand likelihood, impact in time for identification and prioritization of critical Information systems 2. Determine the criticality of information systems and their need for recovery 3. Establish Recovery Time Objective (RTO) and Recovery Point Objective (RPO) to resume activities timely and effectively 4. Identify dependencies between services and supporting resources (facilities, personnel, equipment, software, data files, system components, and vital records) Advanced Service Provider 121
  • SC 2.2 The entity shall develop Information Systems Continuity and Recovery plans that shall prevent or minimize interruptions and support in recovery of critical information assets and s The entity shall develop Information Systems Continuity and Recovery plans that shall prevent or minimize interruptions and support in recovery of critical information assets and services during adverse situations The plan shall: 1. Enlist information systems, medical devices, equipment and applications in scope of continuity plan 2. Identify continuity requirements for recovering from events that affect availability of critical information assets and services Have recovery strategies for critical information assets to minimize the period and impact of disruption 3. Be harmonized and support organizational business continuity planning and/or disaster recovery demands 4. Identify individuals with assigned roles and responsibilities, along with necessary contact information 5. Define call tree matrix and escalation matrix 6. Defined criteria and conditions for plan activation 7. Have provisions to address information security incident - based scenarios and provide guidance to operate and support critical business services during such scenarios 8. Ensure required level of continuity for information security during disruption 9. Consider redundant system, components or architectures for critical business services, processes and technology, wherever availability cannot be guaranteed using the existing systems architecture Advanced Service Provider 122
  • SC 2.3 The entity shall test, reassess, and maintain its information systems’ continuity plans at planned intervals or in case of any significant change, to ensure that they are up to date and effective The entity shall test, reassess, and maintain its information systems’ continuity plans at planned intervals or in case of any significant change, to ensure that they are up to date and effective. The entity shall: 1. Define schedules and test information system, medical devices, equipment’s and application continuity plans to ensure: a) Adequacy and effectiveness of the plans b) Entity and resource readiness to execute the plans 2. Conduct fail over testing to check the efficiency of redundant information systems 3. Document test outcomes and lessons learned 4. Assess plan adequacy during changes to business services, systems and applications 5. Update and maintain information system and application continuity plans based on lessons learned and assessment outcome Advanced UAE IAR Reference: T9.2.1, T9.2.2, T9.3.1 123 4.Key stakeholder Roles and Responsibilities The entity shall be committed and responsible to address all information and cyber security risks to its environment. The entity shall invest time, efforts, and resources to remediate and reduce the impact of risks to maintain a secure and trusted environment and practices. Based on their job assignment or association, everyone associated (including any external stakeholders, third parties/ contractors/vendors) with the entity has certain responsibilities to maintain day -to-day security of the Entity’s environment, services, systems, and information. Main responsibilities of the involved stakeholders/parties concerning Abu Dhabi Healthcare sector are listed below: Stakeholder Responsibility Department of Health a) Establish ADHICS. b) Enforce ADHICS Standard for Abu Dhabi Healthcare sector, covering all in scope entities, healthcare professional(s) and support staff who have access to patients’ health/diagnostic/personal information. c) Maintain ADHICS Standard, based on learning and industry evolution.
CJISCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIAUAE IAUK GDPR

Frequently asked questions

What does ADHICS stand for?

The Abu Dhabi Healthcare Information and Cyber Security Standard, issued by the Department of Health – Abu Dhabi (DoH). It is the cybersecurity and information-protection standard for the emirate's healthcare sector.

What is ADHICS v2?

The current edition of the standard, effective from August 2024. It sets out the governance and technical controls healthcare entities in Abu Dhabi are expected to implement to protect patient data and clinical systems.

Who must comply with ADHICS?

Healthcare entities operating in Abu Dhabi under the Department of Health — providers, facilities and the organisations that handle health information on their behalf. Suppliers and technology partners serving those entities are routinely asked to evidence alignment as a condition of the contract.

How many controls does ADHICS v2 contain?

786 Cyber's catalogue tracks 47 controls across 11 domains, expanding into 131 sub-controls. The domains span human resources, asset management, physical and environmental security, access control, communications and operations, and privacy and data protection. The Department of Health's own publication is the source of record.

What changed in v2?

Version 2 supersedes the original standard and takes effect from August 2024. Treat it as a re-baseline: reassess against the current control set rather than assuming evidence gathered under the previous version carries across unchanged.

What are the ADHICS tiers?

ADHICS applies controls proportionately rather than demanding an identical implementation from every entity, so the set that applies to you depends on your classification. 786 Cyber scopes the assessment to the controls that apply to your organisation instead of presenting all of them as equally required.

How do I run an ADHICS gap analysis?

786 Cyber's guided assessment walks the ADHICS control set, records what you already have in place, and ranks the gaps by impact rather than returning a flat list. Each control is evidenced once in the Evidence Vault and reused across every other framework that shares it — so an ADHICS readiness exercise also moves your ISO 27001 or UAE IA position rather than being throwaway work. You can start free and see your gap position before committing to anything.

Related frameworks

Ready to assess against ADHICS?

Start free trial →

Where to go next

See it priced

Map ADHICS on any plan — active frameworks scale by tier.

Pricing →

Talk to us

Book a walkthrough with someone who knows the platform.

Book a walkthrough →