What is ADHICS SA-1 Security Awareness Training?
Published: 2026-07-17
If your organization is licensed to operate in Abu Dhabi's healthcare sector, ADHICS compliance is not optional — and the security awareness domain, SA-1, is one of the controls every auditor checks. This guide explains what ADHICS SA-1 requires, in plain language, and what records you need to keep.
What is ADHICS?
The Abu Dhabi Healthcare Information and Cyber Security (ADHICS) Standard is the mandatory cybersecurity framework issued by the Abu Dhabi Department of Health (DoH) for healthcare organizations in the UAE. It defines the information security and cyber resilience controls that every licensed healthcare entity — hospitals, clinics, pharmacies, laboratories, and their service providers — must implement and maintain.
The SA-1 domain: Security Awareness
Domain SA-1 of ADHICS covers security awareness. It requires organizations to deliver security awareness training to all staff — clinical and non-clinical — and, critically, to be able to prove that the training happened. Running a training session is not enough on its own; the standard expects documented, auditable evidence.
SA-1.2: Training attendance records
Under SA-1.2, you must maintain records of who attended security awareness training, when they attended, and their completion status. During an ADHICS audit, this typically takes the form of a training attendance report listing every employee, their department, the course they completed, and the completion date.
SA-1.3: Assessment evidence
SA-1.2 proves attendance; SA-1.3 proves learning. You must demonstrate that staff were assessed on their security knowledge after training — usually through a scored quiz or exam. Auditors ask for assessment score reports showing each attendee's result and whether they passed the required threshold.
SA-1.4: Annual renewal
Security awareness training under ADHICS is not a one-time exercise. Training must be renewed annually, which means your organization needs a schedule of when each employee's training expires and a process for re-enrolling them before it does. An expiry schedule report is the practical evidence auditors look for here.
How Cisoshare Training covers SA-1
Cisoshare Training is built specifically for this workflow: you enroll your staff, they complete ADHICS-aligned security awareness courses with assessments, and the platform automatically issues certificates and generates the SA-1.2 attendance, SA-1.3 assessment, and expiry schedule reports as audit-ready PDFs. For compliance management across all ADHICS domains — governance, risk, audit, and more — see GRSCIA.
FAQ
What is the ADHICS standard?
ADHICS (Abu Dhabi Healthcare Information and Cyber Security Standard) is the mandatory cybersecurity framework issued by the Abu Dhabi Department of Health for licensed healthcare organizations in the UAE.
Who must comply with ADHICS SA-1?
All healthcare entities licensed by the Abu Dhabi Department of Health — including hospitals, clinics, pharmacies, and laboratories — must deliver and document security awareness training for all staff under domain SA-1.
What evidence do ADHICS auditors ask for on security awareness training?
Auditors typically request training attendance records (SA-1.2), assessment score reports proving staff were tested (SA-1.3), and an annual renewal schedule showing training is repeated every year (SA-1.4).
How often must ADHICS security awareness training be renewed?
Annually. Each employee's security awareness training and certificate must be renewed every year, and organizations should maintain an expiry schedule to plan re-enrollment.
Enroll your workforce in ADHICS SA-1 security awareness training and download audit-ready evidence reports.