Public reference

UAE Regulatory Reference

Every framework SYBERIS references is listed here with its official source link, so each claim is independently checkable by you — not merely asserted by SYBERIS.

This page is reference material, not legal advice. The official text held by the issuing authority is the binding version and may change. Always verify at the official source.

UAE Cybersecurity Council

View official source

National cybersecurity strategy, policies and incident coordination.

UAE National Cybersecurity StrategyPublished · source-verified
National strategy

Sets national cybersecurity objectives, governance and sector priorities for UAE entities.

View official source
UAE Information Assurance StandardsPublished · source-verified
UAE IA — 188 controls (34 always-applicable)

Control framework for government and critical-infrastructure entities. SYBERIS maps observable external findings to IA control families only.

View official source

TDRA (Telecommunications and Digital Government Regulatory Authority)

View official source

Telecom and digital government regulation; publisher of the UAE IA Standards.

Information Assurance StandardsPublished · source-verified
UAE IA v1.1

The published control catalogue referenced throughout SYBERIS compliance mapping.

View official source

Dubai Electronic Security Center (DESC)

View official source

Information security requirements for Dubai government entities and their suppliers.

Dubai Information Security Regulation (ISR)Reference only — not scored
ISR v2

Applies to Dubai government entities and organisations processing Dubai government data. SYBERIS does not currently score ISR controls — this entry is reference only.

View official source

Central Bank of the UAE

View official source

Regulation of licensed financial institutions, including technology and information security risk.

Consumer Protection Regulation & StandardsReference only — not scored
Circular 8/2020 and related standards

Includes data control, security and outsourcing obligations for licensed financial institutions. SYBERIS does not score CBUAE controls — reference only.

View official source

UAE Data Office / Federal PDPL

View official source

Federal personal data protection across the UAE outside ADGM and the DIFC.

Federal Decree-Law No. 45 of 2021 (PDPL)Published · source-verified
31 articles

The federal personal data protection law: lawful basis, data subject rights, security measures and breach notification.

View official source
Federal Decree-Law No. 34 of 2021 (Cybercrime)Published · source-verified
Combating Rumours and Cybercrimes

Criminalises unauthorised access to IT systems. SYBERIS therefore requires a written authorisation statement before any scan.

View official source

ADGM Office of Data Protection

View official source

Data protection for entities registered in Abu Dhabi Global Market.

ADGM Data Protection Regulations 2021Published · source-verified
64 sections

Self-standing regime for ADGM entities, including annual registration with the Office of Data Protection.

View official source

DIFC Commissioner of Data Protection

View official source

Data protection for entities registered in the Dubai International Financial Centre.

DIFC Data Protection Law No. 5 of 2020Published · source-verified
65 articles

Self-standing regime for DIFC entities, including notification to the Commissioner and breach reporting duties.

View official source

International (non-UAE) — ISO/IEC

View official source

Voluntary international standard, frequently required contractually in the UAE.

ISO/IEC 27001:2022Published · source-verified
Annex A — 93 controls

Information security management system standard. Voluntary — it is not UAE legislation, and certification requires an accredited body.

View official source