Why Your ISO 27001 Toolkit Won't Pass an ADHICS Assessment
There is a conversation that happens in Abu Dhabi healthcare organisations more often than it should.
The IT team has bought an ISO 27001 toolkit. It is a good toolkit. It has policies, procedures, a risk methodology, a Statement of Applicability. The team maps it to ADHICS, finds it mostly aligns, and proceeds with confidence.
Then the assessment happens, and the findings arrive — not because the security is weak, but because mostly aligns is not a standard anyone is assessed against.
Close is not the same as compatible
ADHICS — the Abu Dhabi Healthcare Information and Cyber Security standard issued by the Department of Health — shares ancestry with ISO/IEC 27001. Similar domains, similar logic, similar vocabulary. That resemblance is exactly what makes it dangerous to assume equivalence.
ADHICS has its own control structure, its own domain organisation, and healthcare-specific expectations that a generic information security framework does not carry. Every place where the mapping is approximate becomes a place where evidence is missing, and in an assessment, missing evidence is a finding regardless of how secure the environment actually is.
Build to the standard you're assessed against
The alternative is a system written to ADHICS directly. In practice that means:
- The Information Security Governance Committee as approving authority, with the Information Security Manager owning the system — the governance shape ADHICS expects, not a generic ISMS forum.
- Procedures organised by ADHICS control domain — governance, risk assessment and treatment, asset and information classification, access control and identity management, human resources security, physical and environmental security, operations and change management, third-party and supplier security, incident management, business continuity, document control, audit and management review.
- A document architecture defined on purpose — structure, numbering, classification and interrelation set out in a scheme document, so the security team can extend the system over the years without breaking its logic.
- Registers that carry the weight — risk register, asset inventory, incident log — because these are what an assessor actually reads.
Around forty documents across eight folders, classified Restricted, with the forms, checklists, guidance and awareness training that turn controls into daily practice.
Healthcare has no grace period
Health data is the most sensitive category most organisations will ever hold, and healthcare is among the most targeted sectors globally. ADHICS is mandatory, and it is enforced. For hospitals, clinics, diagnostic centres, pharmacies, insurers and health-tech providers, the practical question is not whether to comply but whether to comply against an approximate map or an exact one.
A complete Healthcare Information & Cyber Security Management System built directly on ADHICS and the Department of Health implementation guidelines — 43 controlled documents — is available now.
The toolkit for this guide: Healthcare Information & Cyber Security Management System (ADHICS). Instant download, fully editable, yours to keep.