UAE National Cloud Security Policy — Reference for the certification client Platform Governance
**Purpose of this document.** Working reference for citing the National Cloud Security Policy accurately in school and board documents, and for using its nine consumer domains as the spine of the the certification client control library.
**Reading convention.** Sections 1–5 are SOURCED FACT drawn from UAE government sources. Section 6 is CLAUDE'S INFERENCE — mapping only, not official guidance. Section 8 records what could not be verified.
---
1. Provenance — cite it this way
| Field | Detail |
|---|---|
| Full name | The National Cloud Security Policy |
| Issuing authority | **UAE Cyber Security Council** |
| Issued date | **6 February 2023** |
| Document type | Public Policy Document |
| Sector classification | Telecommunication, Technology and Space |
| Target audience | Government entities, private sector enterprises, and community members |
| Primary sources | `uaelegislation.gov.ae` (policy record); `u.ae` official government platform (domain listing) |
**Common error to avoid:** this policy was issued by the **Cyber Security Council**, not TDRA. TDRA issues the separate UAE Information Assurance Regulation. Attributing it to the wrong authority in a board document is the kind of detail an inspector notices.
---
2. Five cloud security principles
These are the decision-making principles the policy sets out for users and providers across policy, operational, and procurement decisions.
1. **Risk-based approach** — assess potential security and resilience risks when adopting and scaling cloud.
2. **Data-driven cloud security** — match the level of security to data sensitivity, business impact, and privacy expectations.
3. **Best practice guidelines** — adopt global best-practice security frameworks for assurance and compliance efficiency.
4. **Ecosystem of cooperation and transparency** — share practices between users, providers, and regulators, and report cloud incidents.
5. **Continuous improvement** — keep cloud security practices relevant, efficient, and effective over time.
**Principle 2 is the one to lean on.** It is the national-policy basis for the position already taken with the schools: security effort should be proportionate to data sensitivity. It supports both the data-classification exercise and the argument that student learning records do not warrant government-grade infrastructure.
---
3. Policy objectives
1. Advance the UAE's strategic cybersecurity objectives.
2. Keep pace with global change in cybersecurity and the digital economy.
3. Safeguard digital assets and cyberspace.
4. Strengthen cloud security as a national priority.
5. Accelerate regional cloud adoption by improving access to data and information on strong security standards.
6. Build a standards-based ecosystem that creates trust in UAE cybersecurity providers.
---
4. Nine domains applicable to cloud consumers
This is the section that matters for the certification client — the school is a cloud **consumer**. These nine domains are a ready-made top-level structure for the control library.
| # | Domain | Stated focus |
|---|---|---|
| 1 | **Cloud Governance** | Leadership and governance for cloud security; prompt risk identification; personnel awareness of responsibilities; reduced supply-chain compromise |
| 2 | **Contractual Agreements** | Protecting confidentiality of consumer data and the rights of both consumer and provider through defined contractual obligations |
| 3 | **Data Security and Lifecycle Management** | Protection through proper classification and robust security for data at rest, in transit, and during processing |
| 4 | **Data Location and Sovereignty** | Consumer awareness of where data is stored, processed, and managed from |
| 5 | **Interoperability and Portability** | Ability to select providers that interoperate; protection from vendor lock-in |
| 6 | **Cloud Architecture, Infrastructure & Virtualization** | Change management, data centre security, asset management, application security, device hardening |
| 7 | **Identity and Access Management** | Preventing unauthorised access to infrastructure, applications, and data |
| 8 | **Security Incident Management, E-Discovery, and Cloud Forensics** | Minimising incident impact, timely reporting, supporting investigations and legal proceedings |
| 9 | **Cloud Resilience** | High availability of information and resources; minimising impact of non-compliance and data loss |
---
5. Domains applicable to cloud service providers
The policy sets a parallel set of domains for providers. The consumer-side value of this list is as a **procurement questionnaire** — these are the things to ask Microsoft, Supabase, Vercel, and any future UAE provider to evidence.
The provider domains mirror the nine consumer domains above, plus two that apply only to providers:
- **Cloud Operation and Maintenance** — operational sovereignty and service reliability, including on-site technical support for Sovereign Cloud environments.
- **Integration with UAE Initiatives** — alignment with national priorities, integration with government cybersecurity initiatives, Emiratisation, national workforce development, and local innovation.
Note the provider-side emphasis on encryption and key management throughout the data lifecycle, and on transparency about processing and storage locations.
---
6. CLAUDE'S INFERENCE — mapping the nine domains to the the certification client platform
Not official guidance. This is a proposed mapping to seed the control library, for the school to review and amend.
| Domain | What the certification client already holds | Visible gap |
|---|---|---|
| 1. Cloud Governance | Digital Learning & Data Protection Policy (draft); board adoption route; named owner | Risk register; documented personnel responsibilities |
| 2. Contractual Agreements | DPA register — Supabase (signed), Vercel, Anthropic | Vercel DPA does not apply on Hobby plan; upgrade needed for the claim to be true |
| 3. Data Security & Lifecycle | Encryption in transit and at rest; RLS; retention rules in policy | Data classification against TDRA levels not yet documented |
| 4. Data Location & Sovereignty | Azure UAE North for Postgres; Frankfurt for existing Supabase; documented honestly | AI inference residency; redaction middleware not yet built |
| 5. Interoperability & Portability | Open-source stack (Postgres, GoTrue, PostgREST); OpenAI-compatible gateway pattern planned | Documented exit/portability plan |
| 6. Architecture & Infrastructure | Container Apps design; Key Vault; managed identity approach | Change-management record; hardening baseline |
| 7. Identity & Access Management | Three-layer domain gate; role-based access; Entra admin | Access review cadence; joiner/leaver process |
| 8. Incident Management | 72-hour breach response in policy; incident log defined | Log not yet operational; no rehearsal |
| 9. Cloud Resilience | Azure availability zones; managed Postgres backups | Restore has not been tested; RTO/RPO not stated |
**The pattern worth noting:** most gaps are documentation and rehearsal, not technology. That is a cheap gap to close and a strong story to tell.
---
7. Suggested citation wording for the policy document
For Section 13 (Governance) or Section 6 (Data Residency) of the Digital Learning & Data Protection Policy:
> This policy is structured with reference to the domains for cloud consumers set out in the National Cloud Security Policy issued by the UAE Cyber Security Council in February 2023, and applies its principle that the level of cloud security should be aligned with the sensitivity of the data concerned.
This wording is accurate, verifiable, and claims alignment rather than certification — which is the defensible position, since no certification scheme is being asserted.
---
8. What could not be verified — carry this forward honestly
- **The full policy text with numbered control requirements is not available in the public sources consulted.** The nine domains and five principles are published; the underlying detailed requirements are not. Any specific control number or clause reference must not be cited until the full document is obtained.
- **Self-assessment and annual reporting.** A law firm commentary (Pinsent Masons, describing the Cyber Security Council policy) reports that the policy sets requirements for compliance self-assessments and annual reporting for both consumers and providers. This was **not** found on the government pages consulted. Treat as reported-but-unconfirmed until verified against the source document.
- **Whether compliance is mandatory for a private school.** The stated target audience includes private sector enterprises, so the school is within the audience. Whether a non-critical private education entity carries a formal obligation, versus being expected to align voluntarily, is not established by the sources consulted. Do not state or imply a mandatory obligation.
- **Related framework, different scope:** the UAE Information Assurance Regulation was developed by TDRA and provides management and technical information security controls. Its mandatory application runs through entities designated as critical under the UAE CIIP Policy — which a private school is not. Useful as best practice; not a compliance obligation to claim.
**Next verification step:** request the full National Cloud Security Policy document from the Cyber Security Council or via a UAE legal contact, then replace Sections 4 and 5 above with the actual control requirements and update the mapping in Section 6.
---
*Prepared as internal reference material. Sources: uaelegislation.gov.ae policy record; u.ae official government platform. Bracketed judgements in Section 6 are analytical suggestions for school review, not regulatory guidance.*