UAE Regulatory Reference
Every framework SYBERIS references is listed here with its official source link, so each claim is independently checkable by you — not merely asserted by SYBERIS.
This page is reference material, not legal advice. The official text held by the issuing authority is the binding version and may change. Always verify at the official source.
UAE Cybersecurity Council
View official sourceNational cybersecurity strategy, policies and incident coordination.
Sets national cybersecurity objectives, governance and sector priorities for UAE entities.
View official sourceControl framework for government and critical-infrastructure entities. SYBERIS maps observable external findings to IA control families only.
View official sourceTDRA (Telecommunications and Digital Government Regulatory Authority)
View official sourceTelecom and digital government regulation; publisher of the UAE IA Standards.
The published control catalogue referenced throughout SYBERIS compliance mapping.
View official sourceDubai Electronic Security Center (DESC)
View official sourceInformation security requirements for Dubai government entities and their suppliers.
Applies to Dubai government entities and organisations processing Dubai government data. SYBERIS does not currently score ISR controls — this entry is reference only.
View official sourceCentral Bank of the UAE
View official sourceRegulation of licensed financial institutions, including technology and information security risk.
Includes data control, security and outsourcing obligations for licensed financial institutions. SYBERIS does not score CBUAE controls — reference only.
View official sourceUAE Data Office / Federal PDPL
View official sourceFederal personal data protection across the UAE outside ADGM and the DIFC.
The federal personal data protection law: lawful basis, data subject rights, security measures and breach notification.
View official sourceCriminalises unauthorised access to IT systems. SYBERIS therefore requires a written authorisation statement before any scan.
View official sourceADGM Office of Data Protection
View official sourceData protection for entities registered in Abu Dhabi Global Market.
Self-standing regime for ADGM entities, including annual registration with the Office of Data Protection.
View official sourceDIFC Commissioner of Data Protection
View official sourceData protection for entities registered in the Dubai International Financial Centre.
Self-standing regime for DIFC entities, including notification to the Commissioner and breach reporting duties.
View official sourceInternational (non-UAE) — ISO/IEC
View official sourceVoluntary international standard, frequently required contractually in the UAE.
Information security management system standard. Voluntary — it is not UAE legislation, and certification requires an accredited body.
View official source