ADHICS Training

What is ADHICS (S.A.T.) Security Awareness Training?

A plain-language guide to the ADHICS Control Domain: what the Abu Dhabi healthcare cybersecurity standard requires for security awareness training, and the evidence auditors expect.

Published: 2026-07-17Updated: 2026-09-21
What is ADHICS Security Awareness Training?

If your organization is licensed to operate in Abu Dhabi's healthcare sector, ADHICS compliance is not optional — and the security awareness domain, HR-3.2-3.4, is one of the controls every auditor checks. This guide explains what ADHICS D-1 requires, in plain language, and what records you need to keep.

What is ADHICS?

The Abu Dhabi Healthcare Information and Cyber Security (ADHICS) Standard is the mandatory cybersecurity framework issued by the Abu Dhabi Department of Health (DoH) for healthcare organizations in the UAE. It defines the information security and cyber resilience controls that every licensed healthcare entity — hospitals, clinics, pharmacies, laboratories, and their service providers — must implement and maintain.

The Domain1[HR3.2 - 3.4]: Security Awareness

It requires organizations to deliver security awareness training to all staff — clinical and non-clinical — and, critically, to be able to prove that the training happened. Running a training session is not enough on its own; the standard expects documented, auditable evidence.

HR-3.2.1, the healthcare entity shall ensure all employees and where relevant contractors and third parties receive appropriate awareness and training to enhance the entity’s security posture and to minimize probabilities of information security risks

HR 3.2.2 The healthcare entity shall ensure that an awareness and training program is formally launched and professionally managed

HR 3.2.3 The healthcare entity shall enhance training content and enrich delivery of awareness aspects based on evolving needs

HR 3.2.4 The healthcare entity shall evaluate effectiveness and maintain appropriate record of awareness and trainings delivered

Assessment evidence

proves attendance; proves learning. You must demonstrate that staff were assessed on their security knowledge after training — usually through a scored quiz or exam. Auditors ask for assessment score reports showing each attendee's result and whether they passed the required threshold.

Annual renewal

Security awareness training under ADHICS is not a one-time exercise. Training must be renewed annually, which means your organization needs a schedule of when each employee's training expires and a process for re-enrolling them before it does. An expiry schedule report is the practical evidence auditors look for here.

How Cisoshare Training covers SAT Controls

Cisoshare Training is built specifically for this workflow: you enroll your staff, they complete ADHICS-aligned security awareness courses with assessments, and the platform automatically issues certificates and generates the attendance, assessment, and expiry schedule reports as audit-ready PDFs.

For compliance management across all ADHICS domains — governance, risk, audit, and more — see GRSCIA.

FAQ

What is the ADHICS standard?

ADHICS (Abu Dhabi Healthcare Information and Cyber Security Standard) is the mandatory cybersecurity framework issued by the Abu Dhabi Department of Health for licensed healthcare organizations in the UAE.

Who must comply with ADHICS SA-1?

All healthcare entities licensed by the Abu Dhabi Department of Health — including hospitals, clinics, pharmacies, and laboratories — must deliver and document security awareness training for all staff under domain SA-1.

What evidence do ADHICS auditors ask for on security awareness training?

Auditors typically request training attendance records (SA-1.2), assessment score reports proving staff were tested (SA-1.3), and an annual renewal schedule showing training is repeated every year (SA-1.4).

How often must ADHICS security awareness training be renewed?

Annually. Each employee's security awareness training and certificate must be renewed every year, and organizations should maintain an expiry schedule to plan re-enrollment.

Sources and further reading

  1. AAMEN and ADHICS V2 Department of Health Abu Dhabi
  2. Department of Health launches ADHICS Department of Health Abu Dhabi (2019-03-02)
  3. Data protection laws The Official Platform of the UAE Government

Related articles

Build verifiable ADHICS training evidence for your workforce.