DuoKey
Compliance

TDRA UAE IA Regulation

Federal Information Assurance Regulation. Cryptography in T7.4, key management in T7.4.2. Successor to NESA IAS.

Requirements

What the regulation expects

The UAE Information Assurance Regulation (v1.1, March 2020 on the TDRA site) is the federal cybersecurity baseline for government entities and critical information infrastructure operators. It succeeds the NESA Information Assurance Standards. DuoKey's posture engine ships a built-in rule pack for this regime. Control text and numbering below follow the published TDRA document.
What the regulation expects

Federal baseline for government and CII

Management families M1 to M6 and technical families T1 to T9. Cryptography sits in T7.4; key management in T7.4.2.

Crypto policy as enforced configuration

T7.4.1 expects a crypto policy reviewed at planned intervals. Approved key types that reject unapproved creation are the practical form.

Key generation and storage standards

T7.4.2 requires generation process and storing standards. Custody is a per-vault configuration, not a per-team habit.

Tamper-evident logs

T3.6.4 protects log information against tampering. Hash-chained trails and optional on-premise WORM mirror answer that directly.

Cloud requirements in agreements

T6.3 expects security requirements for cloud retention, processing and storage, governed through service agreements. External keys turn a contractual promise into a technical control.

Solutions

How DuoKey supports the framework

OpenBAO + DuoKey SD-HSM

Enforced key types, NIST-style states, vault inventory and SIEM-forwarded audit trail.

Learn more

AWS XKS / cloud BYOK

Key custody outside the cloud provider attached to the cloud risk assessment.

Learn more

Microsoft 365 Customer Key & DKE

Customer-held keys for regulated mail and files.

Learn more

Key themes

Where independent key control fits

Control text and numbering from UAE IA Regulation v1.1 on the TDRA website. Only controls a KMS materially contributes to are listed.

T7.4.1 Cryptographic controls policy

Approved key types, sizes and usages per vault and tenant; creation outside the set is refused. Dated posture reports for each review cycle.

Relevant products

T7.4.2 Key management

Generation in software vault, MPC or PKCS#11 HSM. Revoke/block via enforced states. Protect keys against modification, loss, unauthorized use and disclosure.

Relevant products

T3.6 Audit logging

HMAC-signed audit log and hash-chained activity log. Chain verification for T3.6.4. Administrator actions on the same trail (T3.6.5).

Relevant products

T5.2 Privileged access

Leaf-level permissions, MFA for admin access, logged administrative actions, and scheduled privilege-creep audits for T5.2.4.

Relevant products

T3.5.1 Backups

Tenant snapshot/restore for control plane; key backup follows the custody model so hardware-pinned keys stay non-exportable.

Relevant products

T6.3 Cloud security requirements

Holding the key outside the cloud application so the provider processes ciphertext it cannot unilaterally read.

Resources

Continue reading

Discuss the decisions that matter most to your security programme.

Tell us where control is difficult today. We will help you identify a practical next step.