UAE framework guide · Dubai Electronic Security Center (DESC)
DESC ISR compliance in Dubai
The minimum information security controls for every Dubai Government entity, and for the contractors and consultants engaged with one. Thirteen domains across governance, operation and assurance.
Who DESC ISR applies to
- All Dubai Government entities. DESC states the regulation sets the minimum requirements for information security controls across them.
- The people engaged with those entities who are not government employees: DESC names employees, consultants, contractors and visitors engaged with an entity through various means.
- Suppliers in practice: if your contract with a Dubai government entity requires ISR alignment, the information you handle for that entity is inside its scope.
- Cloud providers separately: any CSP offering cloud services to Dubai government and semi-government entities must comply with the DESC Cloud Service Provider Security Standard, and can certify against it.
What DESC ISR asks for
The Dubai Information Security Regulation, as the regulator publishes it, by theme rather than clause number.
- Thirteen domains, three classes
- Each domain covers one or more of governance, operation and assurance. The governance domains set the high-level requirements for structuring and managing information security; the rest set what has to operate and what has to be proven.
- Technology neutral
- The regulation states control requirements and leaves the implementation to each entity, which is why a gap assessment reads your actual controls against it rather than a product list.
- Right-fit implementation
- Entities determine which domains and controls apply to them, commit resources to a right-fit implementation, and keep the cost of controls below the value of what they protect, guided by their risk assessment.
- Continuous monitoring and incident handling
- The operating expectation every managed service on this site is built around: alerts watched, incidents handled by a documented process and reported.
- Visibility, testing, awareness, access, recovery
- Asset and configuration visibility, periodic assessment and testing, security awareness, privileged access with audit logging, and backup and recovery, each a control area the mapping below points at.
From requirement to what we run
Each theme, and the service, the technology guide and the portfolio vendors that support it. A mapping, not a compliance claim: the service is what makes the control demonstrable.
Portfolio capabilities that support alignment15
Each row is published on the matching vendor page and reproduced here from the same source. This is a capability map, not compliance advice: it is not a certification, an audit result or a guarantee of coverage, and it does not interpret the regulation. Confirm applicability and scope with the vendor and a qualified compliance advisor before relying on it.
Questions buyers ask
- Does DESC ISR apply to us?
- It applies to all Dubai Government entities, and DESC extends it to the employees, consultants, contractors and visitors who are not government employees but are engaged with an entity. If you supply a Dubai government entity, your contract will say so, and the information you handle for that entity is inside its obligations.
- What does the regulation actually require?
- Thirteen domains, each covering one or more of three classes: governance, operation and assurance. It is technology neutral, so it states minimum control requirements and leaves the implementation to you. In practice that is continuous monitoring and incident reporting, documented incident handling, asset and configuration visibility, periodic testing, security awareness, privileged access with audit logging, backup and recovery, and cloud governance.
- Which version applies?
- The third edition is the one DESC publishes today. DESC holds the responsibility, under Dubai Law No. 11 of 2014, to maintain and continuously improve the regulation, and the regulation itself was formalised under Resolution No. 13 of 2012. A gap assessment reads your controls against the current edition, not the one you were last reviewed on.
- Does it matter who runs our cloud?
- Yes. The DESC Cloud Service Provider Security Standard is mandatory for any CSP wishing to offer cloud services to Dubai government and semi-government entities, and CSPs certify against it under a scheme DESC aligns with ISO/IEC 27001 certification. Ask your provider for its certificate before you design controls around its platform.
- Is Protect24x7 certified or approved by DESC?
- No. This page and the coverage map are a capability map, not compliance advice, a certification or an audit result. Confirm applicability and scope with DESC and a qualified compliance advisor. What Protect24x7 provides is the gap assessment, the control mapping and the evidence work, and the monitored services that make the controls demonstrable.
- Where do we start?
- With a gap assessment against the regulation as it applies to you, then controls mapped to its domains, then evidence collected ahead of the review rather than during it. That is the GRC and audit readiness service, and it ends in a remediation roadmap your leadership can approve.
Sources
Every regulatory statement on this page comes from one of these documents. Where they are silent, so is the page.
