Khurram Badar / Archive / Papers / UAE National Cloud Security Policy — Reference for the certification client Platform Governance

UAE National Cloud Security Policy — Reference for the certification client Platform Governance

briefing · 2026-07-20 · 1343 words · Khurram Badar

1. Provenance — cite it this way 2.

ai · education · legal · technology · uae

UAE National Cloud Security Policy — Reference for the certification client Platform Governance

**Purpose of this document.** Working reference for citing the National Cloud Security Policy accurately in school and board documents, and for using its nine consumer domains as the spine of the the certification client control library.

**Reading convention.** Sections 1–5 are SOURCED FACT drawn from UAE government sources. Section 6 is CLAUDE'S INFERENCE — mapping only, not official guidance. Section 8 records what could not be verified.

---

1. Provenance — cite it this way

| Field | Detail |
|---|---|
| Full name | The National Cloud Security Policy |
| Issuing authority | **UAE Cyber Security Council** |
| Issued date | **6 February 2023** |
| Document type | Public Policy Document |
| Sector classification | Telecommunication, Technology and Space |
| Target audience | Government entities, private sector enterprises, and community members |
| Primary sources | `uaelegislation.gov.ae` (policy record); `u.ae` official government platform (domain listing) |

**Common error to avoid:** this policy was issued by the **Cyber Security Council**, not TDRA. TDRA issues the separate UAE Information Assurance Regulation. Attributing it to the wrong authority in a board document is the kind of detail an inspector notices.

---

2. Five cloud security principles

These are the decision-making principles the policy sets out for users and providers across policy, operational, and procurement decisions.

1. **Risk-based approach** — assess potential security and resilience risks when adopting and scaling cloud.
2. **Data-driven cloud security** — match the level of security to data sensitivity, business impact, and privacy expectations.
3. **Best practice guidelines** — adopt global best-practice security frameworks for assurance and compliance efficiency.
4. **Ecosystem of cooperation and transparency** — share practices between users, providers, and regulators, and report cloud incidents.
5. **Continuous improvement** — keep cloud security practices relevant, efficient, and effective over time.

**Principle 2 is the one to lean on.** It is the national-policy basis for the position already taken with the schools: security effort should be proportionate to data sensitivity. It supports both the data-classification exercise and the argument that student learning records do not warrant government-grade infrastructure.

---

3. Policy objectives

1. Advance the UAE's strategic cybersecurity objectives.
2. Keep pace with global change in cybersecurity and the digital economy.
3. Safeguard digital assets and cyberspace.
4. Strengthen cloud security as a national priority.
5. Accelerate regional cloud adoption by improving access to data and information on strong security standards.
6. Build a standards-based ecosystem that creates trust in UAE cybersecurity providers.

---

4. Nine domains applicable to cloud consumers

This is the section that matters for the certification client — the school is a cloud **consumer**. These nine domains are a ready-made top-level structure for the control library.

| # | Domain | Stated focus |
|---|---|---|
| 1 | **Cloud Governance** | Leadership and governance for cloud security; prompt risk identification; personnel awareness of responsibilities; reduced supply-chain compromise |
| 2 | **Contractual Agreements** | Protecting confidentiality of consumer data and the rights of both consumer and provider through defined contractual obligations |
| 3 | **Data Security and Lifecycle Management** | Protection through proper classification and robust security for data at rest, in transit, and during processing |
| 4 | **Data Location and Sovereignty** | Consumer awareness of where data is stored, processed, and managed from |
| 5 | **Interoperability and Portability** | Ability to select providers that interoperate; protection from vendor lock-in |
| 6 | **Cloud Architecture, Infrastructure & Virtualization** | Change management, data centre security, asset management, application security, device hardening |
| 7 | **Identity and Access Management** | Preventing unauthorised access to infrastructure, applications, and data |
| 8 | **Security Incident Management, E-Discovery, and Cloud Forensics** | Minimising incident impact, timely reporting, supporting investigations and legal proceedings |
| 9 | **Cloud Resilience** | High availability of information and resources; minimising impact of non-compliance and data loss |

---

5. Domains applicable to cloud service providers

The policy sets a parallel set of domains for providers. The consumer-side value of this list is as a **procurement questionnaire** — these are the things to ask Microsoft, Supabase, Vercel, and any future UAE provider to evidence.

The provider domains mirror the nine consumer domains above, plus two that apply only to providers:

Note the provider-side emphasis on encryption and key management throughout the data lifecycle, and on transparency about processing and storage locations.

---

6. CLAUDE'S INFERENCE — mapping the nine domains to the the certification client platform

Not official guidance. This is a proposed mapping to seed the control library, for the school to review and amend.

| Domain | What the certification client already holds | Visible gap |
|---|---|---|
| 1. Cloud Governance | Digital Learning & Data Protection Policy (draft); board adoption route; named owner | Risk register; documented personnel responsibilities |
| 2. Contractual Agreements | DPA register — Supabase (signed), Vercel, Anthropic | Vercel DPA does not apply on Hobby plan; upgrade needed for the claim to be true |
| 3. Data Security & Lifecycle | Encryption in transit and at rest; RLS; retention rules in policy | Data classification against TDRA levels not yet documented |
| 4. Data Location & Sovereignty | Azure UAE North for Postgres; Frankfurt for existing Supabase; documented honestly | AI inference residency; redaction middleware not yet built |
| 5. Interoperability & Portability | Open-source stack (Postgres, GoTrue, PostgREST); OpenAI-compatible gateway pattern planned | Documented exit/portability plan |
| 6. Architecture & Infrastructure | Container Apps design; Key Vault; managed identity approach | Change-management record; hardening baseline |
| 7. Identity & Access Management | Three-layer domain gate; role-based access; Entra admin | Access review cadence; joiner/leaver process |
| 8. Incident Management | 72-hour breach response in policy; incident log defined | Log not yet operational; no rehearsal |
| 9. Cloud Resilience | Azure availability zones; managed Postgres backups | Restore has not been tested; RTO/RPO not stated |

**The pattern worth noting:** most gaps are documentation and rehearsal, not technology. That is a cheap gap to close and a strong story to tell.

---

7. Suggested citation wording for the policy document

For Section 13 (Governance) or Section 6 (Data Residency) of the Digital Learning & Data Protection Policy:

> This policy is structured with reference to the domains for cloud consumers set out in the National Cloud Security Policy issued by the UAE Cyber Security Council in February 2023, and applies its principle that the level of cloud security should be aligned with the sensitivity of the data concerned.

This wording is accurate, verifiable, and claims alignment rather than certification — which is the defensible position, since no certification scheme is being asserted.

---

8. What could not be verified — carry this forward honestly

**Next verification step:** request the full National Cloud Security Policy document from the Cyber Security Council or via a UAE legal contact, then replace Sections 4 and 5 above with the actual control requirements and update the mapping in Section 6.

---

*Prepared as internal reference material. Sources: uaelegislation.gov.ae policy record; u.ae official government platform. Bracketed judgements in Section 6 are analytical suggestions for school review, not regulatory guidance.*

← TASHRI' SYNC (تشريع) — Legislative Knowledge Graph Build SpecCrypto HFT Stack — 101 for Dummies →
Two years of working thought, indexed.
Ask me to present it in your conference room — WhatsApp +971 55 623 9111
Book Session →