Skip to content
Protect24x7
Esc

Try XDR, DLP, CrowdStrike or PDPL. Arrow keys to move, Enter to open.

Talk to our SOC

Protect24x7 GRC team ·

DESC ISR readiness: the checklist before the assessment

The Information Security Regulation is technology neutral and sets minimum controls across thirteen domains. An assessment goes faster when the evidence exists before anyone asks for it. This is the list.

Who this is for

Dubai Government entities, and the consultants, contractors and suppliers engaged with one. DESC states the regulation applies to all Dubai Government entities including the people engaged with them who are not government employees. If your contract with a government entity requires ISR alignment, the information you handle for that entity is inside its scope, and the same checklist applies to your part of it.

Start from the current edition

The third edition is the one DESC publishes today, and DESC holds the responsibility under Dubai Law No. 11 of 2014 to keep improving it. A readiness review reads your controls against the current edition, not the one you were last assessed on. Get the document, and get the internal owner for each domain named before you go further.

Governance: the paper that has to exist

The governance domains set the high-level requirements for structuring and managing information security. Before an assessment: a named information security owner at leadership level; an approved policy set that covers the regulation's domains; a risk assessment with results the control choices can be traced back to; a right-fit implementation decision that records which controls apply to you and why, with the cost of controls weighed against the value of what they protect, as DESC asks.

Operation: the controls that have to be running

Continuous monitoring with a record of what was watched and what was escalated. A documented incident-handling process with the case records to show it was followed. An asset and configuration inventory that matches the estate. Periodic assessment and testing with the findings and their retests. Security awareness with tracked results, not attendance. Privileged access controlled and logged. Backups protected and their recovery tested. Cloud usage governed, with the provider's certificate against the DESC Cloud Service Provider Security Standard on file if the provider serves Dubai government.

Assurance: proving it

Evidence collected ahead of the assessment rather than during it: the audit takes days instead of weeks when the record already exists. For each control in scope, the artefact that shows it operating: a monitoring report, an incident case, an inventory export, a test report with retest, a training trend line, an access review, a restore test log. Map each artefact to the domain it evidences, so nobody is guessing which control satisfies which requirement when the assessor asks.

What this article does not do

It does not quote clause numbers or summarise what changed between editions; DESC's public page does not, and this article stays with what the regulator publishes. It is not compliance advice and Protect24x7 holds no DESC approval. What the GRC service does is the gap assessment against the current edition, the mapping of controls to domains, and the evidence collection, ending in a remediation roadmap leadership can approve.

Written by the Protect24x7 GRC team. Published 14 September 2026, last reviewed 14 September 2026. Indicative guidance, not legal advice or a certification claim.

Read next

Want this applied to your estate?
One call scopes it. No obligation, and we will say when you do not need something.
Talk to our SOC