UAE, National Electronic Security Authority
NESA IAS Workspace
A purpose built workspace for UAE government, semi government, and critical infrastructure entities. Map all 188 IAS controls across the P1 to P4 priority tiers, run risk based applicability assessments, and generate SIA ready evidence packs.
01Inside the workspace
Preloaded and ready on day one
Controls, evidence requests, and reporting views come configured, so your team starts on execution instead of setup.
- All 188 NESA IAS controls pre loaded across the P1 to P4 priority tiers
- The M2 risk assessment methodology built in, to determine which controls apply to your organization
- The always mandatory baseline controls flagged separately from risk based controls
- Coverage across management and technical control domains, from governance, risk, and policy management to access control, physical security, operations, and incident response
- Evidence and documentation templates mapped to each control and sub control
- Dashboards that show compliance by priority tier, so your team can close the highest impact gaps first
- SIA and auditor ready compliance and evidence reports
02Inside the product
Dashboards your team will actually use


03FAQ
Questions we get asked
The UAE Information Assurance Standards (IAS) were issued by the National Electronic Security Authority (NESA), which now operates as the Signals Intelligence Agency (SIA). Compliance is mandatory for UAE government entities, semi government entities, and organizations identified as part of the country's critical infrastructure.
The framework has 188 security controls, organized into four priority tiers, P1 through P4. P1 controls carry the highest priority and, on their own, address most of the threats NESA identified through its research, which is why most organizations start there.
A defined set of controls, including the management controls in the M2 family, always apply regardless of priority level. For the rest, the workspace runs the same risk based methodology NESA sets out, using your risk assessment results to work out which additional controls apply to your organization.
Yes. The workspace generates evidence packs and compliance reports mapped to each control and sub control, formatted for internal audit, regulator review, or tender submissions that reference the UAE IA Regulation.
See the NESA IAS Workspace in action
Book a session with our team and we will provision a sandbox tenant for your organisation with this workspace enabled.
