# Qatar National Information Assurance Policy v2.0

Framework id: `qatar_nia`. Regulatory. Publisher: National Cyber Security Agency (NCSA). Version: 2.0. Region: Qatar. Mapping licence: CC BY-SA 4.0.
Source text: https://www.ncsa.gov.qa/

Each line is a clause, the NIST SP 800-53 controls OSA maps to it, and OSA's estimate of how far those controls cover it.
Clause titles and coverage figures are OSA's own summaries and estimates. No line-by-line check against the source text is recorded for this framework, so quote the source, not this card.

## Clauses (11, average coverage 87%)
- AC Access Control: AC-01, AC-02, AC-03, AC-04, AC-05, AC-06, AC-07, AC-08, AC-09, AC-10, AC-11, AC-12, AC-13, AC-14, AC-16, AC-17, AC-18, AC-19, AC-20, AC-21, AC-22, AC-24, AC-25, IA-01, IA-02, IA-03, IA-04, IA-05, IA-06, IA-07, IA-08, IA-09, IA-10, IA-11, IA-12 (92%)
- AM Asset Management: CM-08, CM-12, CM-13, PM-05, RA-02, MP-01, MP-02, MP-03, MP-04, MP-05, MP-06, MP-07, MP-08, PE-16, SR-12, AC-16, SC-04 (85%)
- BC Business Continuity: CP-01, CP-02, CP-03, CP-04, CP-05, CP-06, CP-07, CP-08, CP-09, CP-10, CP-11, CP-12, CP-13, PM-08, PM-11, SI-13 (82%)
- CS Communications Security: SC-01, SC-02, SC-03, SC-04, SC-05, SC-07, SC-08, SC-10, SC-11, SC-12, SC-13, SC-15, SC-16, SC-17, SC-20, SC-21, SC-22, SC-23, SC-26, SC-28, SC-32, SC-36, SC-37, SC-38, SC-39, SC-40, SC-44, SC-46, SC-47, AC-04, AC-17, AC-18, AC-20, CA-03, CA-09, SI-08 (93%)
- GV Information Security Governance: PL-01, PL-02, PL-04, PL-09, PL-10, PL-11, PM-01, PM-02, PM-03, PM-05, PM-06, PM-07, PM-09, PM-10, PM-13, PM-14, PM-15, PM-28, PM-30, PM-31, PM-32, CA-01, CA-02, CA-05, CA-06, CA-07, PS-09, AT-01, RA-01, SA-01, SA-02 (78%)
- HR Human Resources Security: PS-01, PS-02, PS-03, PS-04, PS-05, PS-06, PS-07, PS-08, PS-09, AT-01, AT-02, AT-03, AT-04, AT-06, PL-04, PE-02 (88%)
- IM Incident Management: IR-01, IR-02, IR-03, IR-04, IR-05, IR-06, IR-07, IR-08, IR-09, AU-06, AU-07, SI-04, SI-05, PM-14 (80%)
- OS Operations Security: CM-01, CM-02, CM-03, CM-04, CM-05, CM-06, CM-07, CM-08, CM-09, CM-10, CM-11, CM-12, CM-14, CP-09, CP-10, AU-01, AU-02, AU-03, AU-04, AU-05, AU-06, AU-07, AU-08, AU-09, AU-10, AU-11, AU-12, AU-13, AU-14, AU-16, SI-02, SI-03, SI-04, SI-05, SI-07, SI-16, RA-05, RA-07, CA-02, CA-07, CA-08 (91%)
- PS Physical Security: PE-01, PE-02, PE-03, PE-04, PE-05, PE-06, PE-07, PE-08, PE-09, PE-10, PE-11, PE-12, PE-13, PE-14, PE-15, PE-16, PE-17, PE-18, PE-19, PE-20, PE-21, PE-22, PE-23 (90%)
- RM Risk Management: RA-01, RA-02, RA-03, RA-05, RA-07, RA-09, RA-10, PM-04, PM-09, PM-28, CA-02, CA-05, CA-07, PL-02, PL-10 (85%)
- SD Systems Development and Maintenance: SA-01, SA-02, SA-03, SA-04, SA-05, SA-08, SA-09, SA-10, SA-11, SA-15, SA-16, SA-17, SA-20, SA-21, SA-22, CM-02, CM-03, CM-04, CM-05, CM-14, SR-01, SR-02, SR-03, SR-04, SR-05, SR-06, CA-02 (87%)

## More
- A pattern's controls with their clauses in this framework: /api/v1/patterns/{id}/crosswalk?framework=qatar_nia
- Control-to-clause mappings as JSON: /api/v1/frameworks/qatar_nia?fields=mappings&per_page=100
- Rationale and gaps for each clause, as JSON: https://raw.githubusercontent.com/opensecurityarchitecture/osa-data/main/data/framework-coverage/qatar-nia.json
- Page for people: /frameworks/qatar-nia/
