Comprehensive Cybersecurity Controls (CSC) for organizations operating in the United Arab Emirates
Get StartedLeadership, policies, and oversight
Risk assessment and treatment processes
Inventory and classification of assets
Personnel security and training
Supplier and vendor risk
Detection, response, and recovery
Authentication and authorization
Segmentation, firewalls, IDS/IPS
Encryption, DLP, backup
Email, TLS, DMARC, SPF
Configuration, patching, logging
SDLC, code review, vulnerability mgmt
IaaS, PaaS, SaaS controls
Industrial control systems
Business continuity, DR
Controls are assigned priorities (P1–P4) based on risk and impact. Scoring uses weighted points: any unmet P1 control triggers a Critical flag regardless of overall percentage.
Critical Flag: If any P1 control is non-compliant, the assessment is flagged as CRITICAL even if the overall score is high. This ensures foundational security controls are not bypassed.