All workspaces
UAE, National Electronic Security Authority

NESA IAS Workspace

A purpose built workspace for UAE government, semi government, and critical infrastructure entities. Map all 188 IAS controls across the P1 to P4 priority tiers, run risk based applicability assessments, and generate SIA ready evidence packs.

01Inside the workspace

Preloaded and ready on day one

Controls, evidence requests, and reporting views come configured, so your team starts on execution instead of setup.

  • All 188 NESA IAS controls pre loaded across the P1 to P4 priority tiers
  • The M2 risk assessment methodology built in, to determine which controls apply to your organization
  • The always mandatory baseline controls flagged separately from risk based controls
  • Coverage across management and technical control domains, from governance, risk, and policy management to access control, physical security, operations, and incident response
  • Evidence and documentation templates mapped to each control and sub control
  • Dashboards that show compliance by priority tier, so your team can close the highest impact gaps first
  • SIA and auditor ready compliance and evidence reports
02Inside the product

Dashboards your team will actually use

Waaqi NESA IAS CISO dashboard showing compliance percentage, control family implementation, and maturity radar across all 15 families
CISO dashboard: overall compliance, always applicable gaps, evidence coverage, control family implementation, and the maturity radar across all 15 families.
Waaqi NESA IAS implementation roadmap with four priority waves from P1 critical baseline to P4 advanced controls
Implementation roadmap: a four wave, stage gated journey to full compliance, delivered in the standard's own P1 to P4 priority order.
03FAQ

Questions we get asked

The UAE Information Assurance Standards (IAS) were issued by the National Electronic Security Authority (NESA), which now operates as the Signals Intelligence Agency (SIA). Compliance is mandatory for UAE government entities, semi government entities, and organizations identified as part of the country's critical infrastructure.

The framework has 188 security controls, organized into four priority tiers, P1 through P4. P1 controls carry the highest priority and, on their own, address most of the threats NESA identified through its research, which is why most organizations start there.

A defined set of controls, including the management controls in the M2 family, always apply regardless of priority level. For the rest, the workspace runs the same risk based methodology NESA sets out, using your risk assessment results to work out which additional controls apply to your organization.

Yes. The workspace generates evidence packs and compliance reports mapped to each control and sub control, formatted for internal audit, regulator review, or tender submissions that reference the UAE IA Regulation.

See the NESA IAS Workspace in action

Book a session with our team and we will provision a sandbox tenant for your organisation with this workspace enabled.

Book a demo