Enterprise IT · Schools policy guide

ADEK School Digital Policy: what it asks of an Abu Dhabi school’s IT team

The ADEK School Digital Policy (version 1.1, September 2024) requires Abu Dhabi’s private and charter schools to encrypt, patch and protect school devices, enforce web filtering and multi-factor authentication on critical services, keep automated backups of critical data “vaulted and stored offline”, vet IT vendors and report cyber incidents to ADEK. Compliance has been due since the Fall term of academic year 2025/26. This guide explains each IT clause, the evidence to keep for the annual review, and what the policy leaves to the school.

Policy version
1.1, September 2024 (checked 8 October 2026)
Compliance from
Academic year 2025/26, Fall term
Applies to
Private and charter schools in Abu Dhabi
Main IT clauses
5.1, 5.3, 5.5, 6.1 to 6.3, 6.5, 6.6 and 7.3
Original PRO TECHnology diagram: documents published under clause 1.1 of the ADEK School Digital Policy lead to IT controls in sections 5 to 7 (devices, vendors, security, backups, incidents, data plan), then to dated evidence for the clause 2.2 annual review
An original PRO TECHnology diagram, not an ADEK graphic. PRO TECHnology is not affiliated with or endorsed by ADEK; the authoritative text is ADEK’s own PDF of the policy.

Key takeaways

  • In our reading, IT does most of the drafting for four of the seven documents a school must publish under clause 1.1.
  • School-managed devices need anti-malware, hard disk encryption and regular security patching under clause 6.1 item 4, and where staff reach school data from other devices or a Bring Your Own Device (BYOD) scheme runs, clause 5.1 requires the school to define and implement precautions such as a minimum device specification and antivirus.
  • Critical data needs automated backups that are “vaulted and stored offline” and a disaster recovery plan (clause 6.1 item 5). Schools with onsite storage also keep backups apart from the network (6.5), and restore steps and recovery tests belong in the data plan and annual review (7.3, 2.2).
  • Clause 6.6 asks for plans to report a cybersecurity incident to the school leadership team and to ADEK, and bars telling outside parties other than the service provider involved and ADEK; clause 6.6(2) also requires schools to follow applicable UAE laws, so confirm any other reporting duty with your legal adviser.
  • The policy’s IT controls name no product, vendor, certification or security framework, so a school shows compliance through its published documents, the controls it runs and the annual review, not through a purchase.

What the ADEK School Digital Policy is, and when it applies

The ADEK School Digital Policy is the Abu Dhabi Department of Education and Knowledge’s rulebook for how private and charter schools plan, secure and govern their technology. ADEK says it “sets out the basic requirements for schools” on a digital strategy, teaching about digital safety and the secure use of digital technology. The last of these is IT’s.

Version
1.1, dated September 2024. Version 1.0 was issued in January 2024.
Effective from
Academic year 2024/25, Fall term (clause 9.1).
Full compliance from
Academic year 2025/26, Fall term (clause 9.1).
Scope
Private and charter schools in Abu Dhabi. Any circular issued before the policy, or issued later specifically for charter schools, supersedes it.
Penalties
Clause 9.2 makes non-compliance subject to “legal accountability” and penalties under ADEK’s regulations and federal law, with no amounts stated.

The timetable matches ADEK’s wider update of 5 November 2024: the Abu Dhabi Media Office release, covering 39 updated private school policies and 27 new early education policies, said full compliance with most of them was expected by the next academic year.

The seven documents clause 1.1 asks a school to publish

Each goes on the school website in Arabic and English, or the language of instruction. In our reading, the four marked IT are mostly technical drafting.

  1. Digital strategy covering five years (clause 2.1).
  2. Responsible usage policies for students, parents, staff and visitors (clause 4.1).
  3. IT: a framework for selecting external providers and products (clause 5.5; the English PDF’s clause 1.1 says “5.4”, but the section is 5.5, as the Arabic text has it).
  4. IT: the Data and Cybersecurity Infrastructure document (clause 6.1).
  5. IT: a response plan for cybersecurity incidents (clause 6.6).
  6. IT, with leadership: the school data protection plan and policy (section 7).
  7. Digital media and social media policies (section 8).

Policy version checked: version 1.1 (September 2024), still listed on ADEK’s health, safety and wellbeing policy page on 8 October 2026. This guide summarises the policy with clause numbers and short quotes; the PDF on adek.gov.ae is the text that counts. It is a planning guide for IT teams, not legal advice. PRO TECHnology is not affiliated with or endorsed by ADEK.

Which clauses belong to IT, and which do not

ADEK gives oversight to a Digital Wellbeing Committee or Lead (clause 2.2), which develops the strategy, reviews it every year and consults people such as “the Digital Officer, Head of IT”. IT supplies most of the review’s evidence.

ClauseWhat it coversWho usually leads
1.1Seven documents published on the school websiteLeadership, with IT drafting four of them
2.1 and 2.2Five-year digital strategy and the annual review, which tests systems and reviews data and cybersecurity provisionsDigital Wellbeing Committee or Lead, with IT evidence
2.3A named liaison with ADEKLeadership appoints
3.1Digital competencies and outcomes by gradeTeaching and learning, not IT
3.2Staff training, including data protection and cybersecurityShared
4.1Responsible usage: personal devices, the student VPN restriction, password rulesShared: policy by leadership, enforcement by IT
4.2Filtering, monitoring and analysis of web filter violationsShared: pastoral team and IT
4.3Digital incidents: misuse such as cyberbullyingSafeguarding and HR, not IT
4.4Parents monitoring students’ device use outside schoolParent engagement, not IT
5.1, 5.3Device security, BYOD precautions, distance learning readinessIT
5.2Staff access to ADEK’s digital systems, including the Learning Management SystemLeadership, with IT for accounts and access
5.4Assistive technology for students with additional learning needsInclusion team, with IT support
5.5Third-party risk assessment of IT providers and productsIT, with procurement
6.1 to 6.3, 6.5, 6.6IT security controls, maintenance, single sign-on, backups, cybersecurity incidentsIT
6.4Consent and approval for live virtual sessions with invited visitorsSafeguarding, not IT
7.1 to 7.3Data protection policy, sharing data with ADEK, the annual data protection planLeadership, with IT on the technical steps
8.1 to 8.5Digital media, social media, email and the school websiteCommunications, not IT

This split is PRO TECHnology’s planning reading. ADEK assigns oversight to the Digital Wellbeing Committee or Lead, not clauses to departments.

School-issued, shared and personal devices

Clause 5.1 says devices issued to members of the school community must have “appropriate security features”. Where staff can reach school data or systems from other devices, or the school runs Bring Your Own Device for staff or students, the school must define and implement digital safety precautions, with a minimum device specification and antivirus requirements given as examples.

Clause 6.1 item 4 sets the baseline for every school-managed device: up-to-date anti-virus or anti-malware software, hard disk encryption and regular security patching. Clause 6.2 adds maintenance of operating systems, security systems and software, plus regular testing. Clause 5.3 asks for distance learning measures for emergencies such as a temporary closure, which for IT means accounts and devices that work away from campus.

Three records cover most of what the annual review will ask about devices:

  • Keep a device list with encryption, anti-malware and patch status for each school-managed device.
  • Write the BYOD precautions down: minimum specification, antivirus, and which school systems a personal device may reach.
  • Cover shared devices in the responsible usage policy, as clause 4.1 item 1 requires (“including shared devices”).

An endpoint management console is one way to produce encryption and patch evidence across a mixed fleet; our guide to how mobile device management (MDM) and unified endpoint management (UEM) tools manage Macs, iPads and Windows laptops explains those tools.

Lockable charging trolleys for shared class sets help with custody of shared devices, but no ADEK clause requires them: the physical security item, clause 6.1 item 9, concerns servers, networking equipment and other critical infrastructure.

Sign-in, filtering and the school network

Access control and learning apps

Clause 6.1 item 1 asks for multi-factor authentication “across critical services” and role-based access control. Clause 6.1 item 13 covers the cloud: providers with “stringent security standards”, proper configuration and access controls, software as a service (SaaS) integrated with school identity services “where possible”, and SaaS Security Posture Management, which the policy defines as an automated tool that finds misconfigurations, unnecessary accounts and excessive permissions. Clause 6.3 asks for safeguards such as single sign-on for external learning applications.

Together they point towards a single school identity that learning apps use wherever possible. The policy does not say which services are critical, so the Data and Cybersecurity Infrastructure document should name them. Creative apps the school pays for are part of the picture: Adobe’s K-12 privacy page says schools, not Adobe, set up and manage student accounts, and our page on Adobe Education licences signed in through the school’s own identity covers how that works.

Responsible use, filtering and monitoring

Clause 4.1 item 2(a) tells schools to restrict students’ use of Virtual Private Networks on school premises or through school networks, unless explicitly authorised for specific educational or administrative purposes. Clause 4.1 item 4 asks for rules on setting and sharing passwords for school accounts.

Clause 4.2 item 2(b) requires “appropriate filtering and monitoring systems” for student internet use on school devices and systems, and item 2(c) regular analysis of internet usage and web filter violations to spot adverse trends.

Clause 6.1 item 3 lists the network controls, including next generation firewalls and intrusion detection or prevention systems, enforced web filtering, detection of infected machines, identity-based firewalls and regular audit of network traffic.

ADEK’s backup clauses: vaulted, offline and kept apart from the network

Four clauses deal with backups, and ADEK’s own wording is the safest guide to the evidence a school should keep. Clause 6.5 covers schools with onsite data storage and backups of “important information, software, and configuration settings”, with frequency and retention set by the ADEK School Records Policy.

ADEK’s wordingClauseEvidence to keep
“automated regular backup procedures for critical data”6.1 item 5(a)The backup schedule and recent job logs
“vaulted and stored offline”6.1 item 5(b)Where the offline copy is kept and who holds it
a disaster recovery plan to keep downtime short after a security incident6.1 item 5(c)The plan, with its date and owner
“stored securely and separately from the school network”6.5(1)How the copy is separated from the network
data “synced to the cloud” where external cloud storage is used6.5(2)Sync status for cloud-held data
“procedures for restoring backed-up information”7.3The written restore procedure
testing digital systems, with backup recovery as the example2.2(2)(c)A dated record of the last recovery test

ADEK does not define “vaulted”, and this policy sets no backup frequency of its own; it defers to the Records Policy. The method is the school’s to choose, write down and show working. Our backup guide covers the 3-2-1 rule and how to test a restore, and the Kanguru Defender HDD350 page describes an encrypted hard drive as the offline copy in a backup rotation.

Data classification, data loss prevention and the data protection plan

Clause 6.1 item 2 asks for encryption of data in transit and at rest. Clause 6.1 item 6 asks for data classification across school and student data, and data loss prevention tools to stop leaks and exfiltration.

Section 7 turns this into documents. The clause 7.1 Data Protection Policy must comply with Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data and set out at least:

  • The types of personal information the school may collect.
  • Consent procedures: consent must be freely given, specific, informed and unambiguous, and can be withdrawn at any time.
  • The conditions for sharing personal information, for example with ADEK.
  • A non-disclosure agreement in contractor agreements under which personal data “cannot be shared within or outside the country for any purposes, without the explicit consent of ADEK” (clause 7.1(3)(a)).

Clause 7.3 asks for a data protection plan, reviewed every year, recording classification methods, authorisation levels, protections against cyber and other threats, and restore procedures.

For IT, that means a classification scheme systems actually apply, a register of where student data is stored, and contractor agreements checked for the non-disclosure clause. Before relying on any reading of that clause for a particular cloud service, ask ADEK how it applies. Where student data has to leave the network on a drive, encrypt the drive; the comparison of hardware and software encryption on our Kanguru page explains the options.

Choosing IT and edtech vendors under clause 5.5

Clause 5.5 asks every school for a third-party risk assessment framework for selecting external IT providers and products, including learning application providers and open-source applications. Its eight minimum criteria turn naturally into supplier questions.

Criterion in clause 5.5(1)Questions to put to the supplier
(a) Compatibility with existing school systemsDoes it connect to our systems and sign in through our identity service?
(b) Secure management of dataWhat student data does it collect, where is it stored, and how is it deleted at contract end?
(c) Compliance with cybersecurity standards and frameworksWhich standards does it follow, and what evidence can it share? ADEK names none.
(d) Security against cyber threatsHow are vulnerabilities patched, and does the service support multi-factor sign-in?
(e) Service delivery and backup or recovery provisionsHow is our data backed up and restored, and what happens during an outage?
(f) Reputation and financial stabilityWhich references and proof of financial standing can it give?
(g) Adherence to the Personal Data Protection Law and ADEK’s terms, copyright policy and data privacy policyWill the provider confirm this in writing?
(h) Educational quality and age-appropriateness, where relevantWhich ages is the content designed for, and can teachers review it first?

Clause 5.5(2) asks the school to tell each vendor that it is subject to the Personal Data Protection Law and ADEK’s terms and policies. Clause 6.1 item 15 asks schools to vet and monitor third-party educational technology vendors against security standards, so for those vendors the assessment recurs rather than being a one-off.

Hypothetical example. A school wants a reading app for Grades 1 to 3. The IT lead records the supplier’s answers against criteria (a) to (h), confirms students sign in with school accounts (clause 6.3), checks the contract for the non-disclosure clause (7.1(3)(a)), and schedules a re-check for the next review.

Incident response, logs and the tabletop exercise

The policy uses two kinds of incident. A digital incident under clause 4.3 is misuse by a member of the school community, such as cyberbullying. It is handled under the school’s behaviour, protection and staff policies, recorded and signed by the Principal, and reported to ADEK where required. A cybersecurity incident is a breach that threatens the confidentiality, integrity or availability of systems or sensitive data. The second belongs to IT.

Clause 6.6 asks for response and business continuity plans that guide staff through a cybersecurity incident, including how it is reported to the school leadership team and to ADEK and how operations continue. Clause 6.6(1) says schools shall not communicate any cybersecurity incident to external parties “except for the service provider involved and ADEK”. Clause 6.6(2) requires adherence to applicable laws and to policies set by the Department of Government Enablement and other UAE authorities, including Federal Decree-Law No. 34 of 2021 on Countering Rumours and Cybercrimes.

Clause 6.1 item 8 asks for a regularly updated incident response plan and a tabletop cyber-attack simulation, a guided walk-through of an imagined attack, with school management taking part. Clause 6.1 item 11 asks for real-time monitoring and detailed logs for auditing and analysis.

Points to settle before anything happens

  • Who reports to ADEK: the policy does not say, though the clause 2.3 liaison is an obvious candidate.
  • Which service providers may be told about an incident, and who speaks to them.
  • Where logs are kept, for how long, and who can read them.
  • The date of the last tabletop exercise and which members of management took part.
  • How teaching continues while systems are down (clause 6.6, with the distance learning measures in 5.3).

Evidence for the annual review, and what the policy does not prescribe

Clause 2.2 makes the review annual, so keep dated evidence in one place. A workable pack for the IT clauses holds:

  1. The seven clause 1.1 documents as published, in Arabic and English or the language of instruction, with their publication dates.
  2. A device inventory showing encryption, anti-malware and patch status (clauses 5.1, 6.1 item 4, 6.2). Our guide to keeping a device and software inventory that stays current covers the method.
  3. Backup job logs, the location of the offline copy and the last restore-test record (clauses 6.1 item 5, 6.5, 7.3, 2.2(2)(c)).
  4. The web filtering policy, dated analysis of filter violations and the published student VPN rule (clauses 4.1 and 4.2).
  5. Multi-factor coverage of critical services and the list of cloud apps with their sign-in method (clauses 6.1 items 1 and 13, 6.3).
  6. Vendor assessments against clause 5.5 criteria (a) to (h), with re-check dates (clause 6.1 item 15).
  7. The incident response plan, the tabletop exercise record and the log retention settings (clauses 6.1 items 8 and 11, 6.6).
  8. Training records for staff and students (clauses 3.2 and 6.1 item 7).
  9. The data protection plan with its annual review date, and the contractor non-disclosure clauses (clauses 7.1 and 7.3).

The policy names no products for its IT controls; the only products it names are social media and messaging apps, given as examples. Clause 6.1 item 10 refers to “local and international data protection regulations and standards” without listing them, and the purpose statement refers to “the requirements of the Monitoring and Control Center” without saying what they are or which body sets them, so ask ADEK what applies.

Where PRO TECHnology can help with the IT clauses

PRO TECHnology is a Dubai-based IT supplier, not an auditor. The table maps clauses to what the Enterprise IT division supplies, with the limits of each.

ClauseWhat PRO TECHnology offersLimits to note
5.1, 6.1 item 4, 6.2FileWave endpoint management, to manage devices and report their status. FileWave documents managing FileVault on Macs enrolled through Automated Device Enrollment or an MDM profile, a Windows Compliance Pack that reports BitLocker status and recovery keys and can switch BitLocker on where the Windows edition includes it, testing and deploying Apple and Windows updates, and inventory.Not anti-malware. BitLocker can be switched on only on Windows editions licensed for it. Under Apple User Enrollment, FileWave removes the school’s managed data, not the whole device.
6.1 item 5(b), 6.5(1)Kanguru Defender HDD350 encrypted hard drives, as one way to hold a backup copy that is kept offline and separate from the network.A manually connected drive does not meet item 5(a), automated backup procedures, or item 5(c), the disaster recovery plan.
6.3, 6.1 item 13(c)Adobe Education licences, sold as an authorised Adobe reseller, with onboarding and Admin Console setup.Adobe is one of the learning apps that should sit behind the school’s identity, not a single sign-on system the school deploys.
None (custody of shared devices)LapCabby trolleys and cabinets: PRO TECHnology supplies, delivers and installs them and trains the staff who use them.Not an ADEK requirement.
6.2 (keeping equipment in working order)Diagnostics and repairs on site or at PRO TECHnology’s Dubai service centre.Warranty claims and spare parts are handled only for brands PRO TECHnology distributes. Whether an engineer can visit the campus, and repair times, depend on the product, its warranty terms and the location.
6.1 items 1, 3, 6(b), 11, 13(d)No product described on this site provides multi-factor authentication, firewalls and web filtering, data loss prevention, logging or SaaS posture management as school-wide controls.Some Dropbox plans add two-step verification and audit logs, Dropbox Enterprise adds data classification, and some Kanguru Remote Management Console (KRMC) packages keep event logs, but only for their own service or drives. The division’s remit includes wireless and networking, so ask what it can scope for your campus.

PRO TECHnology is FileWave’s distributor and partner for the Middle East, and FileWave’s 1 July 2026 announcement describes the partnership as covering sales, deployment and local support across the region. To see how the console reports on your devices, book a demonstration from the FileWave page, at the Business Bay showroom or at your school. For the other practices, see the Enterprise IT division.

Frequently asked questions

When did Abu Dhabi private schools have to comply with the ADEK School Digital Policy?

From the start of academic year 2025/26, Fall term. The policy, version 1.1 dated September 2024, took effect in the Fall term of 2024/25 and gave schools one academic year to become fully compliant, as clause 9.1 states. It applies to private and charter schools in Abu Dhabi. Clause 9.2 makes failure to comply subject to legal accountability and to penalties under ADEK’s regulations, but states no amounts. Check adek.gov.ae for a newer version before relying on these dates.

Does the ADEK School Digital Policy cover early education institutions or government schools?

The policy names only private and charter schools in Abu Dhabi as its scope, and says that any circular issued before it, or issued later specifically for charter schools, supersedes its requirements. Early education institutions received a separate set of 27 new ADEK policies, announced on 5 November 2024 alongside the 39 updated private school policies. The Digital Policy says nothing about government schools, so confirm with ADEK or your school operator which rules apply to a particular campus.

Does ADEK require encryption on school laptops and tablets?

Yes, on school-managed devices. Clause 6.1 item 4 requires hard disk device encryption and regular security patching, together with anti-virus or anti-malware software that is installed and kept up to date. Clause 6.1 item 2 also asks for encryption of data in transit and at rest. The policy names no encryption product or method, so the school chooses its tools and keeps evidence, such as a device list showing encryption status, for the annual review.

What does ADEK mean by backups that are “vaulted and stored offline”?

The phrase comes from clause 6.1 item 5(b), and ADEK does not define vaulted any further. The same item asks for automated regular backups of critical data and a disaster recovery plan. Clause 6.5 adds that schools with onsite storage keep backups stored securely and separately from the school network, clause 7.3 asks for written restore procedures, and clause 2.2 names backup recovery as an example of what the annual review tests. How the copy is held is the school’s decision, and the school should document it.

Does the ADEK Digital Policy allow BYOD for students and staff?

The policy neither requires nor forbids it, but sets conditions where a school runs it. Clause 5.1 says that where a school lets staff reach school data or systems from other devices, or has a Bring Your Own Device policy for staff or students, it must define and implement digital safety precautions, such as a minimum device specification and antivirus requirements. Clause 4.1 adds that responsible usage policies must set rules for personal devices on the school network and premises, including during field trips. Check other ADEK policies and circulars before extending a scheme to students’ own phones.

Do schools have to block student VPNs under the ADEK policy?

They must restrict them. Clause 4.1 item 2(a) says schools shall restrict students’ use of Virtual Private Networks on school premises or through school networks, unless explicitly authorised for specific educational or administrative purposes. The rule belongs in the responsible usage policy. Enforcement usually sits in the school’s firewall and filtering setup, which clause 6.1 item 3 also covers, but the policy does not specify a technical method.

Who must a school notify after a cybersecurity incident under the ADEK policy?

Under the policy, the school leadership team and ADEK. Clause 6.6 requires response and business continuity plans with protocols for reporting to both. Clause 6.6(1) says the school must not communicate the incident to external parties other than the service provider involved and ADEK. Clause 6.6(2) adds that schools follow applicable UAE laws, including Federal Decree-Law No. 34 of 2021 on Countering Rumours and Cybercrimes. Confirm any other reporting duty with ADEK and your legal adviser.

Can a school’s IT contractor share student data outside the UAE under the ADEK policy?

Not without ADEK’s consent, under the contract clause the policy requires. Clause 7.1(3)(a) says agreements with contractors must include a non-disclosure agreement under which personal data cannot be shared within or outside the country, for any purpose, without the explicit consent of ADEK. The policy says nothing more specific about where cloud services are hosted, and Federal Decree-Law No. 45 of 2021 has its own rules on transfers outside the UAE, so confirm with ADEK and your legal adviser how both apply to a particular service before relying on it.

Does buying any product make a school compliant with the ADEK Digital Policy?

No. The policy’s IT controls name no product, vendor, certification or security framework. Compliance rests on the documents the school publishes, the controls it runs under sections 5 to 7, and the annual review led by the Digital Wellbeing Committee or Lead. A product can be one way to meet or evidence a clause, for example a console that reports device encryption status, but the school still has to define, operate and review the control itself.

Does KHDA have an equivalent digital policy for Dubai private schools?

Not as of 8 October 2026: we found no published KHDA document with an IT control list like ADEK’s. Gulf News reported on 1 October 2026 that KHDA’s Director General, Aisha Miran, expects its policy and standards on artificial intelligence and devices to be ready, hopefully, by next year. That is a press report, not a KHDA document, so check KHDA’s own website before planning a Dubai campus around it. The ADEK policy applies only in Abu Dhabi.

سياسة المدارس بشأن الرقمية الصادرة عن دائرة التعليم والمعرفة: ما المطلوب من فريق تقنية المعلومات

تُلزم سياسة المدارس بشأن الرقمية الصادرة عن دائرة التعليم والمعرفة (الإصدار 1.1، سبتمبر 2024) المدارسَ الخاصة ومدارس الشراكات التعليمية في أبوظبي بالامتثال الكامل اعتبارًا من الفصل الدراسي الأول من العام الدراسي 2025/2026. وتطلب السياسة نشر سبع وثائق على موقع المدرسة باللغتين العربية والإنجليزية أو بلغة التدريس المعتمدة، منها إطار لاختيار مزوّدي الخدمات والمنتجات الخارجية (البند 5.5)، ووثيقة البنية التحتية للبيانات والأمن السيبراني، وخطة الاستجابة للحوادث السيبرانية، وخطة وسياسة حماية البيانات.

وعلى صعيد تقنية المعلومات، تشترط السياسة على الأجهزة التي تديرها المدرسة برامج محدّثة لمكافحة الفيروسات والبرمجيات الخبيثة وتشفير الأقراص والتحديث الأمني المنتظم. وعند السماح بالوصول إلى بيانات المدرسة من أجهزة أخرى أو تطبيق سياسة الأجهزة الشخصية، تطلب تحديد وتنفيذ تدابير للأمان الرقمي مثل الحد الأدنى لمواصفات الجهاز ومتطلبات مكافحة الفيروسات. كما تطلب المصادقة متعددة العوامل للخدمات بالغة الأهمية، وتصفية المحتوى ومراقبة استخدام الطلبة للإنترنت، ونسخًا احتياطية منتظمة وآلية للبيانات المهمة تكون مؤمنة ومخزنة بعيدًا عن الشبكة مع خطة للتعافي من الكوارث. وتشترط أيضًا خططًا للإبلاغ عن أي حادث سيبراني إلى قيادة المدرسة والدائرة، وتمنع إبلاغ أي طرف خارجي باستثناء مزوّد الخدمة المعني والدائرة، مع وجوب الالتزام بالقوانين والسياسات المعمول بها في الدولة.

ولا تسمّي السياسة في ضوابط تقنية المعلومات أي منتج أو مورّد أو شهادة أو إطار أمني، لذلك لا يكفي شراء منتج لتحقيق الامتثال؛ فالامتثال يقوم على الوثائق المنشورة والضوابط المطبّقة والمراجعة السنوية. وPRO TECHnology ليست تابعة للدائرة ولا معتمدة منها، ويمكنها المساعدة في جوانب محددة: فهي الموزّع والشريك لـ FileWave في الشرق الأوسط لإدارة الأجهزة وإثبات حالة التشفير والتحديثات، وتورّد أقراص Kanguru Defender HDD350 المشفّرة لحفظ نسخة احتياطية منفصلة عن الشبكة، وتبيع تراخيص Adobe للتعليم بصفتها بائعًا معتمدًا من Adobe. وقد تحقّقنا في 8 أكتوبر 2026 من أن الإصدار 1.1 لا يزال الإصدار المنشور على موقع الدائرة، لذا تحقّق من عدم صدور إصدار أحدث قبل الاعتماد على هذا الملخص. وهذا الملخص دليل تخطيطي لفرق تقنية المعلومات وليس استشارة قانونية.

Ask which of your school’s IT clauses we can help with

Send the number of devices by operating system, how backups run today, and which clause 6.1 items you would like help with. The team will say which parts PRO TECHnology can supply and which sit elsewhere.

PRO TECHnology Co. L.L.C. · Office 204, Aswar Building, Sheikh Zayed Road, Business Bay, Dubai, UAE · +971 4 343 5501 · info@protech.ae