Discover your OT Blind spots today! Get your free Executive Readiness Heatmap.

Contact Us
Close
Chat
Get In Touch

Get Immediate Help

Get in Touch!

Tell us what you need and we’ll connect you with the right specialist within 10 minutes.

  • Yes, I agree with the storage and handling of my data by this website, to receive periodic emails from microminder cybersecurity related to products and services and can unsubscribe at any time. By proceeding, you consent to allow microminder cybersecurity to store and process the personal information submitted above to provide you the content requested. I accept microminder's Privacy Policy.*

  • This site is protected by reCAPTCHA.

Thank You

Thank you

We appreciate your interest in our cybersecurity services! Our team will review your submission and reach out to you soon to discuss next steps.

UK: +44 (0)20 3336 7200
UAE: +971 454 01252
KSA: +966 1351 81844

4.9 Microminder Cybersecurity

310 reviews on

Trusted by 2600+ Enterprises & Governments

Trusted by 2600+ Enterprises & Governments

Contact the Microminder Team

Need a quote or have a question? Fill out the form below, and our team will respond to you as soon as we can.

What are you looking for today?

Managed security Services

Managed security Services

Cyber Risk Management

Cyber Risk Management

Compliance & Consulting Services

Compliance & Consulting Services

Cyber Technology Solutions

Cyber Technology Solutions

Selected Services:

Request for

  • Yes, I agree with the storage and handling of my data by this website, to receive periodic emails from microminder cybersecurity related to products and services and can unsubscribe at any time. By proceeding, you consent to allow microminder cybersecurity to store and process the personal information submitted above to provide you the content requested. I accept microminder's Privacy Policy.*

  • This site is protected by reCAPTCHA.

Thank You

Thank you

In the meantime, please help our team scope your requirement better and to get the right expert on the call by completing the below section. It should take 30 seconds!

30 seconds!

Untick the solutions you don’t need

  • Untick All
  • Untick All
  • Untick All
  • Untick All
Thank You

What happens next?

Thanks for considering us for your cybersecurity needs! Our team will review your submission and contact you shortly to discuss how we can assist you.

01

Our cyber technology team team will contact you after analysing your requirements

02

We sign NDAs for complete confidentiality during engagements if required

03

Post a scoping call, a detailed proposal is shared which consists of scope of work, costs, timelines and methodology

04

Once signed off and pre-requisites provided, the assembled team can commence the delivery within 48 hours

05

Post delivery, A management presentation is offered to discuss project findings and remediation advice

Home  Resources  Blogs  Dubai DESC ISR Compliance: Scope, Controls and Certification Path

Dubai DESC ISR Compliance: Scope, Controls and Certification Path

 
Lorna Jones

Lorna Jones, Senior Cyber Security Consultant
Sep 16, 2026

  • LinkedIn

The Dubai Information Security Regulation, issued by the Dubai Electronic Security Center, sets the mandatory minimum information security requirements for Dubai Government entities and their suppliers. The current version, ISR V3, organises requirements into 13 domains across three classes: Governance, Operation, and Assurance. This guide explains who falls in scope, how the domains are structured, and how ISR compares to ISO 27001 and NESA for entities holding more than one certification.

Key Takeaways

Before working through ISR in detail, these points shape everything else.

  • ISR applies to all Dubai Government entities, and obligations flow down to suppliers and contractors through contracts, even when the supplier is a private company.
  • The regulation organises 13 domains into three classes: Governance, Operation, and Assurance.
  • ISR V3 introduced a requirement that a UAE National lead the information security function and report to Top Management, alongside new mandated roles and a prohibition on storing critical information outside the UAE.
  • Cloud service providers serving Dubai Government entities need a separate DESC CSP Security Standard certification, layered on top of international standards including ISO 27001.
  • Meaningful control overlap exists between ISR, ISO 27001, and NESA, though ISR carries Dubai-specific requirements the other two do not.


Understanding this structure first makes the rest of this guide, and any certification conversation with DESC, considerably easier to follow.

Understanding the Dubai Information Security Regulation

The Dubai Electronic Security Centre, part of Digital Dubai, is the government body responsible for protecting information across Dubai's public sector. Its primary instrument is the Information Security Regulation, first formalised under Resolution No. 13 of 2012 and given ongoing maintenance authority through Dubai Law No. 11 of 2014, which tasks DESC with continuously updating the regulation to reflect evolving security practices.

Dubai maintains its own regulation alongside the federal NESA framework because Dubai Government entities carry risk and operational context that a purely federal standard does not fully address, and because DESC needs direct authority to update requirements at the pace of Dubai's digital transformation programme. Our cyber security companies in Dubai guide covers the broader provider landscape entities can draw on when building an ISR compliance programme.

ISR presents minimum control requirements, and Dubai Government entities are expected to conduct their own applicability review against the regulation's domains and controls, implementing a "right-fit" set of controls proportionate to risk and to the value of the information being protected rather than defaulting to blanket implementation regardless of context.

Which Entities Fall Within ISR Scope

ISR applies broadly across the Dubai Government ecosystem, and its practical reach extends well beyond government employees.


Entity typeIn scopeObligation levelHow it usually arises
Dubai Government entitiesYesFull ISR complianceDirect regulatory obligation
Semi-government entitiesYesFull ISR compliance, scoped per entity structureDirect regulatory obligation
Employees, consultants, and contractorsYesBound by the regulation while engaged with government entitiesContractual and employment terms
Cloud service providers serving Dubai GovernmentYesDESC CSP Security Standard, layered on ISR and international standardsCertification required before onboarding as an approved CSP
Suppliers and contractors to in-scope entitiesYes, indirectlyObligations flow down through contractProcurement and vendor agreements

Suppliers to Dubai Government entities are the group most often surprised by their own ISR exposure, since a private company selling into government does not automatically think of itself as bound by a government information security regulation until the obligation arrives through a procurement contract. Confirming scope position early, before a tender rather than during one, avoids a difficult scramble later.

How the ISR Control Framework Is Structured

ISR organises its requirements into 13 domains, grouped under three overarching classes: Governance, Operation, and Assurance. Confirmed directly against the current published ISR V3 document, the domains are:

  • Domain 1: Information Security Management and Governance — organisational structure, policy, and executive accountability for security.
  • Domain 2: Information and Information Assets Management — asset inventory, classification, and handling.
  • Domain 3: Information Security Risk Management — risk identification, assessment, and treatment.
  • Domain 4: Incident and Problem Management — detection, response, and escalation of security incidents.
  • Domain 5: Access Control — user access management and authentication.
  • Domain 6: Operations, Systems and Communications Management — day-to-day technical operations and network security.
  • Domain 7: Business Continuity Planning — continuity and disaster recovery capability.
  • Domain 8: Information Systems Acquisition, Development and Management — secure development and system lifecycle controls.
  • Domain 9: Environmental and Physical Security — protection of facilities and equipment.
  • Domain 10: Roles and Responsibilities of Human Resources — personnel security across the employment lifecycle.
  • Domain 11: Compliance and Audit — internal and external audit obligations.
  • Domain 12: Information Security Assurance and Performance Assessment — ongoing measurement of control effectiveness.
  • Domain 13: Cloud Security — controls specific to cloud-hosted government workloads.


Entities pursuing NESA alignment or ISO 27001 certification will recognise most of this structure directly, since domains like Access Control, Incident and Problem Management, and Business Continuity Planning map closely to equivalent control areas in both frameworks. The dedicated Cloud Security domain and the emphasis on assurance and performance assessment as a distinct domain, rather than folded into general audit, are the two areas where ISR's structure diverges most from its international counterparts.

What Changed in ISR Version 3

DESC released ISR V3 in 2023, building on ISR V2's record of encouraging Dubai Government entities toward UAE-hosted cloud services and expanding the roster of internationally certified cloud providers serving the market. V3 introduced several operationally significant changes, not incremental updates.

The most notable change requires the information security function to be led by a UAE National serving as CISO, reporting directly to Top Management, a governance accountability requirement with no equivalent in NESA or ISO 27001. V3 also formalised new mandated roles beyond the CISO position, specifically Information Security Champions, Internal Auditors, and a defined Incident Response Team, each with roles and responsibilities set out directly in the regulation. On data residency, V3 prevents storing or processing critical government information outside the UAE, explicitly extending to cloud services, which entities already using or evaluating cloud infrastructure must weigh directly against their architecture.

The Certification and Audit Path

Entities pursuing ISR compliance typically follow a structured path: scoping and applicability review against the 13 domains, gap assessment against current practice, risk-prioritised control implementation, documentation and policy development, internal audit, and external assessment leading to a certification or compliance decision. DESC itself operates a separate, more specific certification for cloud service providers: the DESC CSP Security Standard, which layers ISR requirements on top of ISO/IEC 27001, ISO/IEC 27002, ISO/IEC 27017, and CSA STAR Level 2, verified annually with full recertification every three years.

Realistic timelines depend heavily on existing maturity, following the same pattern seen across other UAE compliance frameworks: an entity with an existing ISO 27001 or NESA programme typically moves through ISR gap closure considerably faster than one building a security programme from nothing, since the underlying control work substantially overlaps. Our cyber security audit cost guide covers UAE audit pricing more broadly, including the factors that move cost for a regulatory-standard-specific audit like this one.

ISR, ISO 27001 and NESA: Mapping the Overlap

Dubai entities frequently hold or pursue more than one of these three frameworks simultaneously, and understanding where they align saves real duplicated implementation effort.


AreaISO 27001NESA / UAE IASDESC ISR
Governance and policyAnnex A governance controlsManagement controls domainDomain 1, with the added UAE National CISO requirement
Risk managementAnnex A risk-related controlsRisk management domainDomain 3, closely aligned in substance
Access controlDedicated Annex A domainDedicated technical domainDomain 5, closely aligned in substance
Incident managementAnnex A incident controlsIncident management domainDomain 4, closely aligned in substance
Supplier assuranceAnnex A supplier relationship controlsCovered within broader domainsAddressed through Domain 2 and contractual flow-down
Audit and assuranceInternal audit requirementAudit and compliance obligationsDomains 11 and 12, with Assurance treated as its own domain
Cloud securityAddressed generally, not as a dedicated domainAddressed generallyDomain 13, a dedicated domain with residency restrictions

An entity already holding NESA compliance alignment or ISO 27001 certification carries genuine efficiency into ISR, particularly across governance, risk, access control, and incident management, where the underlying control substance is closely comparable even though the specific documentation and evidence format ISR expects differs from either.

What ISR Means if You Supply Dubai Government Entities

Obligations under ISR flow down through contract to any supplier providing services to an in-scope entity, which means a private company with no direct government charter can still find itself contractually bound to ISR-equivalent controls the moment it wins a Dubai Government tender. Buyers typically ask suppliers to evidence relevant controls, sometimes the full regulation depending on the sensitivity of the engagement, and sometimes a narrower subset tied specifically to the data or systems the supplier will touch.

Preparing before a tender, rather than scrambling once a procurement requirement surfaces mid-process, is the practical difference between winning a government contract smoothly and losing weeks to a compliance gap discovered too late. Our IT security audit guide covers the kind of readiness assessment a supplier can commission proactively to understand its own gap position before a tender response is due.

Where to Start

Getting started with ISR compliance follows a fairly predictable sequence regardless of an entity's starting maturity.

  • Confirm scope position directly, whether as a government entity, semi-government entity, cloud service provider, or a supplier bound through contract.
  • Obtain the current ISR V3 standard directly from DESC rather than relying on secondary summaries, given how substantially V3 changed from V2.
  • Run a gap assessment against the 13 domains, weighted by the entity's own risk and information value.
  • Map existing certifications, ISO 27001 or NESA particularly, against ISR's domain structure to identify genuine overlap before duplicating work.
  • Build the evidence base domain by domain, prioritising governance and risk management first given their foundational role.
  • Plan the assessment path, whether through DESC directly or the CSP Security Standard route for cloud providers specifically.


Our GRC overview covers how a governance function typically coordinates this kind of multi-framework compliance work in practice. This article provides general guidance on ISR's structure and requirements and does not constitute legal advice; the current ISR V3 standard, available directly from DESC, remains the authoritative source for any specific compliance decision.

Don’t Let Cyber Attacks Ruin Your Business

  • Certified Security Experts: Our CREST and ISO27001 accredited experts have a proven track record of implementing modern security solutions
  • 41 years of experience: We have served 2600+ customers across 20 countries to secure 7M+ users
  • One Stop Security Shop: You name the service, we’ve got it — a comprehensive suite of security solutions designed to keep your organization safe

FAQs

What does DESC stand for?

The Dubai Electronic Security Centre, the government body responsible for protecting information across Dubai's public sector.

What is the Dubai Information Security Regulation?

DESC's mandatory minimum information security standard for Dubai Government entities, currently at Version 3.

Who must comply with ISR?

Dubai Government and semi-government entities, and, through contract, their suppliers and contractors.

Is ISR the same as NESA?

No. NESA is federal; ISR is Dubai-specific, though the two share substantial overlap in controls. See NESA compliance.

Does ISO 27001 cover ISR requirements?

Partially. Governance, risk, and access control align closely; ISR's UAE National CISO and cloud residency rules do not appear in ISO 27001.

How long does ISR certification take?

Timeline depends on existing maturity; entities with NESA or ISO 27001 already in place typically move faster.

Do suppliers to the Dubai government need ISR compliance?

Yes, indirectly. Obligations typically flow down through the procurement contract rather than applying automatically.
The Dubai Electronic Security Centre, the government body responsible for protecting information across Dubai's public sector.
DESC's mandatory minimum information security standard for Dubai Government entities, currently at Version 3.
Dubai Government and semi-government entities, and, through contract, their suppliers and contractors.
No. NESA is federal; ISR is Dubai-specific, though the two share substantial overlap in controls. See NESA compliance.
Partially. Governance, risk, and access control align closely; ISR's UAE National CISO and cloud residency rules do not appear in ISO 27001.
Timeline depends on existing maturity; entities with NESA or ISO 27001 already in place typically move faster.
Yes, indirectly. Obligations typically flow down through the procurement contract rather than applying automatically.