UAE IA Regulation

NESA compliance for Linux servers: what a monitoring agent can evidence

Written for the engineer who has to produce the technical half of a NESA pack, not for the consultant who writes the policy half.

The short answer

The UAE Information Assurance Regulation is the standard commonly called NESA. It is published by the authority now known as the Signals Intelligence Agency, and you will see it referenced as NESA, SIA, the UAE IA Regulation (IAR) and the UAE Information Assurance Standards (IAS) interchangeably. For Linux servers, its technical controls concentrate on asset management, access control, secure configuration, vulnerability management, logging and monitoring, and incident response. SecAI assesses against the official v2.1 catalog (134 controls, November 2025) and can evidence parts of the technical families continuously. The governance, risk-assessment and policy controls remain human work and SecAI reports them as such rather than as satisfied.

Four names, one regulation

This trips people up before they start. NESA was the National Electronic Security Authority. It was renamed, and the same body is now the Signals Intelligence Agency, so newer material says SIA. The regulation itself is the UAE Information Assurance Regulation, abbreviated IAR, and the control set within it is referred to as the UAE Information Assurance Standards, or IAS.

Practically: if a tender, an auditor or an internal policy says NESA, SIA, IAR or IAS, they are pointing at the same programme. Searching for only one of the four names is why the material feels thinner than it is.

What the technical controls ask of a Linux server

  • Know what you have: an inventory of systems, the software on them and the services they expose.
  • Control access: who can log in, how, with what privileges, and evidence that privileged access is limited and reviewed.
  • Configure securely: a defined secure baseline and evidence that systems match it.
  • Manage vulnerabilities: identify known vulnerabilities affecting your systems and remediate them on a defined timeline.
  • Log and monitor: capture security-relevant events, keep them, and actually watch them.
  • Respond to incidents: detect, record, act, and be able to show what happened and when.

What SecAI can evidence continuously

Inventory and exposure: hostname, operating system and kernel, installed packages from the system package manager, and services bound to network ports, refreshed continuously rather than captured once.

Access: SSH authentication events including failures, sources and method, sudoers and privileged-account configuration, setuid binaries, local accounts and changes to passwd, group and shadow.

Secure configuration: hardening findings covering SSH configuration, root login, password authentication, file permissions and firewall state, each with the specific setting observed.

Vulnerabilities: every installed package matched against public vulnerability data, reported by severity for that specific machine rather than as a generic feed.

Monitoring and response: the incident history with severity and timestamps, and the automated actions taken, including every address blocked and when.

What stays human work under NESA

A large part of the regulation is deliberately organisational: information security policy, risk assessment and treatment, asset classification, supplier and third-party management, human resources security, physical security, business continuity, and the governance structures around all of it. No agent observes any of that, and SecAI reports those controls as manual verification required rather than quietly leaving them green.

Some technically-flavoured controls are also outside what a host agent can confirm: whether backups actually restore, how long logs are retained and whether they are immutable, and how multi-factor authentication is configured for your organisation. Those are named as gaps in the product, not omitted from the report.

The catalog SecAI assesses against

SecAI assesses against the official UAE Information Assurance Standard version 2.1, published by the UAE Cyber Security Council in November 2025 and classified as Open on its own cover page. That is 134 controls across fifteen families: six management families (M1 to M6) covering strategy, risk management, awareness, human resources, compliance and performance evaluation, and nine technical ones (T1 to T9) covering asset management, physical security, operations, network security, identity and access, third parties, system development, incident management and continuity.

Each control carries two attributes that SecAI keeps separate, because the standard defines them separately. A control has a priority from P1 to P4, and independently it is either always applicable or applicable based on risk. They answer different questions, how urgent and whether it applies to you at all, and collapsing them into one field misstates what an organisation actually has to implement.

Until the official catalog was loaded, SecAI listed this framework and refused to assess it rather than producing a percentage from a control list assembled from secondary sources. That refusal is worth mentioning because it is the same standard applied to the results: a number produced from an invented catalog would have looked exactly like a real one.

What an honest NESA number looks like

Run an assessment today and the technical evidence coverage is low, and it should be. Of the 134 controls, the large majority depend on policy, approval, risk assessment, training records, contracts, management review or physical security. SecAI reports every one of those as manual verification required or out of scope, and manual controls stay in the denominator rather than being quietly removed from it.

The controls SecAI does evidence are the ones you would expect a server agent to evidence: configuration management, logging, monitoring system use, clock synchronisation, management of technical vulnerabilities, network controls and the services exposed, identity and privileged access, privileged utility programs, security event reporting and incident documentation.

A vendor could make that number look much better by dropping the governance controls from the calculation. The reason not to is that those controls are the bulk of the work a NESA programme actually involves, and a tool that hides them from you is not helping you pass an assessment, it is helping you be surprised by one.

Related

Questions people ask

See it on your own server

Install the SecAI agent with one command and watch it protect a Linux server in about 60 seconds. 14-day free trial, no credit card.