Who this is for
Dubai Government entities, and the consultants, contractors and suppliers engaged with one. DESC states the regulation applies to all Dubai Government entities including the people engaged with them who are not government employees. If your contract with a government entity requires ISR alignment, the information you handle for that entity is inside its scope, and the same checklist applies to your part of it.
Start from the current edition
The third edition is the one DESC publishes today, and DESC holds the responsibility under Dubai Law No. 11 of 2014 to keep improving it. A readiness review reads your controls against the current edition, not the one you were last assessed on. Get the document, and get the internal owner for each domain named before you go further.
Governance: the paper that has to exist
The governance domains set the high-level requirements for structuring and managing information security. Before an assessment: a named information security owner at leadership level; an approved policy set that covers the regulation's domains; a risk assessment with results the control choices can be traced back to; a right-fit implementation decision that records which controls apply to you and why, with the cost of controls weighed against the value of what they protect, as DESC asks.
Operation: the controls that have to be running
Continuous monitoring with a record of what was watched and what was escalated. A documented incident-handling process with the case records to show it was followed. An asset and configuration inventory that matches the estate. Periodic assessment and testing with the findings and their retests. Security awareness with tracked results, not attendance. Privileged access controlled and logged. Backups protected and their recovery tested. Cloud usage governed, with the provider's certificate against the DESC Cloud Service Provider Security Standard on file if the provider serves Dubai government.
Assurance: proving it
Evidence collected ahead of the assessment rather than during it: the audit takes days instead of weeks when the record already exists. For each control in scope, the artefact that shows it operating: a monitoring report, an incident case, an inventory export, a test report with retest, a training trend line, an access review, a restore test log. Map each artefact to the domain it evidences, so nobody is guessing which control satisfies which requirement when the assessor asks.
What this article does not do
It does not quote clause numbers or summarise what changed between editions; DESC's public page does not, and this article stays with what the regulator publishes. It is not compliance advice and Protect24x7 holds no DESC approval. What the GRC service does is the gap assessment against the current edition, the mapping of controls to domains, and the evidence collection, ending in a remediation roadmap leadership can approve.
Written by the Protect24x7 GRC team. Published 14 September 2026, last reviewed 14 September 2026. Indicative guidance, not legal advice or a certification claim.
