Thiqa

STANDARD · INFORMATION SECURITY · ALL JURISDICTIONS

ISO 27001 compliance for regulated institutions in MENA.

Information security controls mapped to the same control set as your regulator, evidenced from the systems you already run rather than rebuilt before each audit.

Request a call →Early access · work email only

ISO 27001, and how Thiqa covers it

ISO 27001 is the international standard for managing information security. It is published by a standards body rather than by a government, so — like PCI DSS — it has no jurisdiction of its own and reaches you through the customers, partners and auditors who ask for it.

Much of what it asks for is what CBE, SAMA and PCI DSS already ask for, which is why running it as a separate programme means evidencing the same control two and three times over. You demonstrate it by audit rather than by supervision, so it sits alongside your regulator instead of replacing it.

Thiqa maps it onto the control set you already operate, identifies those overlaps rather than duplicating them, collects the evidence from cloud and identity systems on schedule, and derives posture from the evidence that exists rather than from a checklist somebody ticked.

Runs alongside CBESAMAPCI DSS v4.0

Who publishes it
A standards body rather than a government, which is why it has no jurisdiction of its own and the country you operate in does not change it.
How it reaches you
Through the customers, partners and auditors who ask for it, rather than through the regulator that supervises you.
How it is demonstrated
By audit rather than by supervision. That is why it sits alongside your regulator instead of replacing it.
What Thiqa maps it to
The control set you already operate for CBE, FRA, SAMA or CBUAE, so a control the two share is evidenced once rather than twice.
Overlap, identified
Much of what it asks for is what your regulator and PCI DSS already ask for. Those overlaps are identified rather than duplicated, which is the whole argument for one control set.
Evidence
Collected from cloud and identity systems on schedule. Access reviews, encryption, logging and vendor due diligence are the same artefacts several frameworks ask for, so each one is attached to every control it proves.
Posture
Derived from the evidence underneath it rather than set by hand in a checklist, so expiring proof shows as a gap when it expires.
What this page is
Thiqa’s own account of its product. Thiqa is not a certification body, using Thiqa is not a certification of anything, and Thiqa is not accredited or endorsed by any standards body.

ISO 27001 FAQ

Does ISO 27001 replace what my regulator asks for?
No, it sits alongside it. Much of what it asks for is what CBE, SAMA and PCI DSS already ask for, so a control the two share is evidenced once rather than two and three times over.
Does Thiqa certify us against ISO 27001?
No. Thiqa is not a certification body and using Thiqa is not a certification of anything. What it does is keep the control set mapped and the evidence collected, so what an auditor asks for already exists rather than being assembled for them.

Keep ISO 27001 evidenced all year.