Ayati One — Managed Cyber Defence

UAE NESA/SIA & Dubai ISR: Security Monitoring for Compliance

19 July 2026 · 3 min read · Cloud Armor Security Team

  • NESA
  • Dubai ISR
  • UAE
  • Compliance
  • Ayati One

TL;DR — In the UAE, two overlapping regimes govern security operations: the federal UAE Information Assurance (IA) Standard, overseen by the SIA (Signals Intelligence Agency, formerly NESA), and Dubai's Information Security Regulation (ISR), enforced by DESC. Both mandate a security-operations/monitoring capability. NESA/SIA's 39 Priority-One (P1) controls are mandatory for in-scope entities; ISR structures requirements across security domains including SOC operations.

Global vendors rarely write a word about NESA, SIA or DESC — yet for a bank, government supplier or critical-infrastructure operator in the UAE, these are the frameworks an assessor actually tests. Add ADHICS in Abu Dhabi healthcare and the sector-specific overlays, and the common thread is clear: continuous monitoring, run and evidenced.

The two regimes, briefly

  • UAE IA Standard (SIA / ex-NESA) — federal, 188 controls, with 39 P1 controls mandatory for all in-scope entities; covers IAM, patch management, data protection, incident response and monitoring. The 2025 v2 update tightened cloud, OT and supply-chain requirements.
  • Dubai ISR (DESC) — mandatory for Dubai government entities and their suppliers; ISR v3 spans domains including governance, access control, cloud security, SOC operations and supplier risk.
The overlap trap A Dubai-based supplier to a government entity can be in scope for both the federal IA Standard and Dubai ISR at once — plus PDPL for personal data. Treating them as one-off audits instead of a continuously operated monitoring capability is how organisations pass a point-in-time assessment and then fail the next.

What both regimes need from your SOC

Strip away the control-numbering and the operational demand is consistent: continuous detection, log retention, incident response readiness, and the ability to show it is running — not just that a policy exists.

How Ayati One supports UAE compliance A 24×7 managed SOC operated from our Dubai and India operations, mapped to the monitoring and incident-response controls in the IA Standard and ISR, with continuous VA and asset telemetry as add-ons — and deployment that keeps data in-region. Flat per-asset pricing, no ingestion meter.

Mapping controls to operations

Requirement (IA Standard / ISR) Operational need Ayati One
Security monitoring / SOC operations 24×7 detection + triage Managed SIEM + AI-SOC
Incident response readiness Playbooks, response Analyst-run response
Patch & vulnerability management Continuous exposure visibility Continuous VA + asset telemetry
Data protection / residency In-region storage Dubai / in-tenancy deployment
Supplier & OT risk (v2/ISR v3) Broader monitoring scope Unified telemetry

Frequently asked questions

Is NESA still called NESA?

The authority is now the SIA (Signals Intelligence Agency); "NESA" is still widely used for the IA Standard it oversees. The controls and obligations carry over.

We operate in both India and the UAE — one MSSP or two?

One is better. Cloud Armor runs from Hyderabad, Dubai and New York, so a single MSSP can cover both jurisdictions with per-region data residency and fluency in each regulator.

Does ISR require data to stay in Dubai/UAE?

Residency expectations are strongest for government-linked data; in-region or in-tenancy deployment is the clean answer. Talk to us to scope your obligations.


Meeting NESA/SIA or Dubai ISR? Talk to Cloud Armor about a Dubai-operated managed SOC, and get it priced per asset — in-region data, predictable cost.

Blog timeline

Explore the full series

  1. 27 July 2026 · 4 min read

    Wazuh vs Commercial SIEM: The Real Enterprise Trade-off

  2. 27 July 2026 · 3 min read

    Managed SOC & SIEM With Data Residency in India

  3. 26 July 2026 · 3 min read

    Choosing an MSSP in Hyderabad, Dubai & the GCC

  4. 26 July 2026 · 8 min read

    IBM QRadar Alternatives: Ayati One as a Managed SIEM + AI-SOC

  5. 25 July 2026 · 3 min read

    An Arctic Wolf Alternative for India: Pricing & Residency

  6. 24 July 2026 · 2 min read

    A Rapid7 InsightIDR Alternative: Managed, In-Region SIEM

  7. 23 July 2026 · 3 min read

    A Microsoft Sentinel Cost Alternative: Beyond Per-GB Pricing

  8. 22 July 2026 · 3 min read

    IBM QRadar Migration: A Practical Path Off QRadar

  9. 21 July 2026 · 3 min read

    RBI Cybersecurity Framework: SOC Monitoring & 6-Hour Reporting

  10. 20 July 2026 · 3 min read

    SEBI CSCRF Compliance: SIEM, SOC & the M-SOC Option

  11. 19 July 2026 · Currently reading

    UAE NESA/SIA & Dubai ISR: Security Monitoring for Compliance

  12. 18 July 2026 · 3 min read

    IRDAI 2023 Cyber Security Guidelines: SOC, VAPT & Reporting

  13. 18 July 2026 · 3 min read

    The Enterprise DLP Implementation Checklist: What Most Rollouts Miss

  14. 17 July 2026 · 3 min read

    DPDP Act & Rules 2025: Breach Detection & 72-Hour Notification

  15. 15 July 2026 · 4 min read

    Data Loss Prevention for BFSI in India: The RBI, IRDAI and DPDP Act Compliance Guide

  16. 12 July 2026 · 3 min read

    Forcepoint vs Safetica: How to Choose Between Enterprise DLP and Cloud-Native SaaS DLP

  17. 10 July 2026 · 3 min read

    IAM vs SSO: What's the Difference, and What Does Your Enterprise Actually Need?

  18. 8 July 2026 · 3 min read

    Business Email Compromise in BFSI and Pharma: A Layered Defence Playbook

  19. 5 July 2026 · 3 min read

    Pharma Cybersecurity: Protecting Drug IP, Clinical Trial Data and GxP Systems

Put this into practice.

Our engineers deliver what these guides describe — from assessment to a running control. Bring us your environment.

Tip: tell us your current cyber security requirement — what you are trying to protect, roughly how large the estate is, and any audit or deadline driving it. The more specific you are, the more useful our first reply will be.

We reply from a named engineer, not a sales queue. Your details are used only to answer this enquiry — see our privacy policy.