Country guide

Rail cyber security regulations in the United Arab Emirates

Rail cyber security in the UAE requires attention to both national requirements and any applicable emirate-level rules. The Information Assurance framework uses critical-entity designation, while Dubai has its own government information security standards. A project's location alone is not enough to determine the complete requirements for every operator and supplier.

Official sources checked

Who needs to consider these requirements?

Identify the contracting authority, operator, applicable critical-entity designation and any government security requirements incorporated into the project. This matters where an international supplier supports several UAE projects: the same equipment may be delivered under different security, hosting and access conditions. Capture those conditions in the project requirements, not just a generic corporate policy.

Key regulations and frameworks

UAE Information Assurance Regulation

National framework — mandatory for designated critical entities

The UAE government's guidance describes management and technical controls for protecting information and supporting systems. It explains that critical entities are designated under the Critical Information Infrastructure Protection policy to implement the regulation. Applicability therefore requires checking the entity's designation and the requirements communicated by the responsible authority, rather than assuming that every private supplier is directly regulated in the same way.

Official source: UAE Information Assurance Regulation

Dubai information security standards

Emirate-level standards — confirm government and project scope

Dubai Electronic Security Center publishes standards and policies including the Information Security Regulation for Dubai government entities. A rail project involving a Dubai government organisation should check the applicable version and contractual requirements. These should be distinguished from the national Information Assurance framework and from requirements for projects in other emirates.

Official source: Dubai information security standards

Practical steps for rail teams

Use these engineering and project-planning actions to prepare evidence for the requirements that apply to your organisation.

  1. Create a project-specific requirements register distinguishing national controls, emirate-level requirements and contractual additions. Obtain the customer's confirmation of the applicable scope.
  2. Map where operational information is stored and who can access it, including overseas support teams. Agree hosting, support and evidence-retention arrangements before deployment.
  3. Test how the operator and supplier coordinate an incident affecting remote maintenance or the onboard network. Include revocation of access and restoration of an approved configuration.

Using this guide

This is an introduction to selected frameworks, not a complete legal assessment. Applicability depends on your organisation, systems and contracts. Check the linked official texts and obtain advice for your project before relying on a requirement or deadline.