For a private company working with a Dubai Government Entity, there is one question that can be surprisingly difficult to answer: does the Dubai Information Security Regulation (ISR) apply to us, or are its requirements only for the government organisation?
The confusion is easy to understand. A private company may provide IT services, manage systems, process government information, or have staff who need access to a government entity’s environment. That alone does not tell you whether ISR applies directly to the company. It may still have security requirements imposed through the government entity it works with.
DESC describes ISR as a technology-neutral set of minimum information-security requirements for Dubai Government Entities. It covers government information in any form and extends to employees, consultants, contractors and visitors engaged with those entities.
Dubai Law No. 15 of 2024 adds another layer to the rules. It gives DESC responsibility for developing ISR and overseeing compliance by Government Entities and Critical Non-government Entities. The law also requires Government Entities that oversee Non-government Entities to set electronic-security controls and check compliance with them.
In September 2026, DESC and Microsoft announced a new dashboard that gives DESC a continuously updated view of how participating Dubai Government Entities are performing against ISR controls. We plan to roll out to more than 80 additional entities.
This blog explains what the Dubai Information Security Regulation covers, who it applies to, what changed in 2024, and what private organisations should check before deciding whether ISR applies to them.
What Is the Dubai Information Security Regulation?
DESC establishes the Dubai Information Security Regulation (ISR) as a set of minimum information-security requirements for Dubai Government Entities. It intends to protect the confidentiality, integrity and availability of information and help government organisations reduce security risks and limit the impact of incidents.
How ISR Works
ISR is technology-neutral. DESC does not tell every government organisation which firewall, security platform or vendor it must buy. Instead, each organisation decides how to implement the controls based on its systems, environment and risk assessment.
Two government entities may therefore use different security products and still meet the same ISR requirements. Buying a particular security product does not, by itself, make an organisation compliant.
Technology-Neutral Does Not Mean Optional
Not prescribing a specific technology does not make an ISR control optional.
Government Entities conduct an applicability review to determine which ISR domains and controls apply to them. Where a control applies, the organisation needs to implement it and be able to show that it is in place and working. DESC describes this as a “right-fit” approach based on the organisation’s risk assessment and the value of the information it protects.
An ISR review is not simply a check of which security products an organisation has purchased. It also looks at whether the applicable controls are in place, working as intended and supported by the organisation’s security processes.
Where Does ISR Fit in Dubai’s Cybersecurity Rules?
To understand where ISR sits today, it helps to look at what changed in 2024.
Executive Council Resolution No. 13 of 2012 formalised ISR. Dubai Law No. 15 of 2012 later repealed that resolution. However, the new law says that the legislation issued under the repealed resolution can continue to apply where it does not conflict with the 2012 law, until the relevant authorities issue replacement legislation.
The 2024 law also gives DESC responsibility for developing ISR and overseeing compliance by Government Entities and Critical Non-government Entities. It sets out separate requirements for Non-government Entities that a Government Entity oversees.
This is worth remembering when reading older information about ISR. A page that only refers to the 2012 resolution may not explain the legal position today.
Who Does DESC ISR Apply To?
The answer depends on which type of organisation or person you are looking at. The rules are not the same for all of them.
| Organisation or person | How ISR relates to them |
| Dubai Government Entity | ISR applies directly to the organisation. |
| Employee, consultant, contractor or visitor | Covered by ISR in connection with their engagement with a Dubai Government Entity. |
| Critical Non-government Entity | Must comply with DESC’s electronic-security requirements under the 2024 law. |
| Other Non-government Entity | May have electronic-security controls set by the Government Entity overseeing its activities. |
Dubai Government Entities
This is the main scope of ISR. The regulation applies to Dubai Government Entities and covers government information regardless of its type or medium. The responsibility is not limited to the IT team. DESC says the regulation covers all business functions and divisions of a Government Entity.
This means teams such as HR, finance, procurement and operations can also have information-security responsibilities when they handle government information or use systems covered by the organisation’s security controls.
The 2024 law defines a Government Entity to include Dubai Government departments, public agencies and corporations, Government councils, public authorities and other public entities affiliated with the Government.
Critical Non-government Entities
The 2024 law also creates a separate category called a Critical Non-government Entity. This is a Non-government Entity that DESC has classified as critical under the classification system approved by its Board of Directors.
A private company should not assume that it falls into this category simply because it operates in an important sector or handles sensitive information.
Article 14 requires Government Entities and Critical Non-government Entities to comply with DESC’s electronic-security regulations, standards and rules. DESC also has responsibility for overseeing Critical Non-government Entities under Article 6.
Other Private Organisations Working With Government
A private company does not become a Dubai Government Entity simply because it has a government client, supplies technology to one, or works on a government project.
Article 15 deals with these Non-government Entities separately. Where a Government Entity oversees their activities, that Government Entity must set the electronic-security controls, directives and measures the private organisation must follow. DESC must approve those requirements, and the Government Entity must check compliance.
For a supplier or service provider, the contract and the Government Entity’s oversight arrangements can matter. The requirements could cover access to government systems, handling government information, technical services or other parts of the contract.
Cloud providers and managed service providers need to check what access they have to government systems and information. Providing technology services to a Dubai Government Entity does not, by itself, turn the provider into a Government Entity or mean that every ISR control applies directly to it.
DESC ISR Version 3 and Version 3.1
What Changed in DESC ISR Version 3?
Version 3 expanded several parts of the Information Security Regulation. The changes were not limited to technical controls. They also added or strengthened requirements covering information-security roles, third parties, data-centre security, incident and problem management, business continuity and cyber resilience.
Version 3 adds requirements around information-security leadership and roles such as Information Security Champions, Internal Auditors and the Incident Response Team. It also adds controls for third-party services, data-centre security and cyber resilience.
Version 3 also includes data-residency requirements within its cloud-security controls, covering areas such as data protection, storage and agreements with cloud service providers.
What About ISR Version 3.1?
Version 3.1 needs a little caution.
The current public DESC Standards & Policies page does not list a separate ISR Version 3.1. The official material we could verify refers to the Information Security Regulation and Version 3.
Copies labelled “Version 3.1” are available online, but that is not enough to treat them as the current official DESC document.
If a Government Entity, tender or contract refers to ISR Version 3.1, ask for the specific document being used and confirm which controls and requirements apply before starting an assessment.
How Do We Structure DESC ISR?
The 13 ISR Domains
DESC organises the Information Security Regulation into 13 domains grouped under three classes: Governance, Operation and Assurance. Governance deals with how information security is managed. Operation covers the technical and non-technical controls used to protect information and systems. Assurance looks at whether those controls are working as intended.
Every Government Entity does not have to implement the 13 domains in exactly the same way. Each organisation conducts an applicability review to determine which domains and controls apply to its environment. It then implements the controls according to its risk assessment and the value of the information it protects.
| Domain | What it covers |
| 1. Information Security Management and Governance | Security leadership, policies, accountability and management oversight. |
| 2. Information and Information Assets Management | Managing information and the assets used to store, process and handle it. |
| 3. Information Security Risk Management | Assessing information-security risks and deciding how they should be managed. |
| 4. Incident and Problem Management | Managing security incidents and dealing with the causes of recurring or serious problems. |
| 5. Access Control | Controlling who can access systems and information and what they are permitted to do. |
| 6. Operation, Systems and Communication Management | Security controls for day-to-day IT operations, systems and communications. |
| 7. Business Continuity Planning | Preparing to maintain or restore important services when disruption occurs. |
| 8. Information Systems Acquisition, Development and Management | Security requirements when systems are acquired, developed, changed and maintained. |
| 9. Environmental and Physical Security | Protecting facilities, equipment and physical environments that support information systems. |
| 10. Roles and Responsibilities of Human Resources | Security responsibilities linked to employees, contractors and the employment lifecycle. |
| 11. Compliance and Audit | Meeting applicable requirements and carrying out compliance and audit activities. |
| 12. Information Security Assurance and Performance Assessment | Checking whether security controls and the information-security programme are working as intended. |
| 13. Cloud Security | Security requirements for the use and management of cloud services. |
Key DESC ISR Requirement Areas
The 13 domains tell you how ISR is organised. The practical question is what those controls mean for the security team.
Governance and Risk
ISR places responsibility for information security with the organisation, not just its IT team. It includes requirements for security policies, roles, accountability, risk assessment and management oversight.
A Government Entity needs defined security responsibilities, documented policies and procedures, and a process for recording and managing information-security risks. Senior management also needs visibility into those risks and the actions being taken.
The controls that apply will depend on the organisation’s environment and risk assessment, so the same approach will not apply to every Government Entity.
Information, Assets and Access
An organisation must know what information it holds, where it stores it, and which systems and devices support it. ISR covers information and information-asset management, including ownership, classification, handling and disposal.
Organizations must keep records of information and assets, assign responsibility for them, classify information by its sensitivity or value, and apply security controls when storing, transferring, or disposing of information. They must also control access to systems and information. People should have the access required for their roles, while administrator and other high-privilege accounts need stronger controls.
This covers areas such as user access, authentication, privileged access and access reviews. Access should also be changed or removed when a person’s role changes.
Systems and Applications
ISR covers the security of the systems and applications used by a Government Entity, including day-to-day operations, networks and communications.
Security also needs to be considered when systems are acquired, developed or changed. Depending on the system and its risks, this can include security requirements during development, security testing, controlled changes, separate development and production environments, and checks before a system or change goes live.
Security processes also matter after deployment. Secure configuration, system administration, logging, monitoring and responses to security issues all form part of keeping systems secure.
Organizations can use penetration testing when they need deeper testing to find weaknesses that routine security checks may not uncover. However, they should not present it as a requirement for every system or every ISR control.
Incident Management and Business Continuity
ISR covers both security incidents and the problems that may cause them. Incident management deals with detecting, handling, investigating and recording security incidents. Problem management looks at why an issue occurred and what needs to change to reduce the chance of it happening again.
Business continuity covers how important services will continue or be restored when systems, facilities or other resources are disrupted. This can include business impact analysis, recovery planning, backups and recovery testing.
Recovery plans must match the services you are protecting and the risks that could disrupt them.
Third-Party and Cloud Security
Using an external provider does not remove a Government Entity’s responsibility for security. ISR includes controls for third parties and cloud services, so security needs to be considered before and during an external relationship.
This can include checking a provider’s security controls, setting security responsibilities in contracts, controlling third-party access and managing risks created by outsourced services.
For cloud services, the organisation also needs to check how its information and systems are protected in the cloud environment. The controls will depend on the service, the information involved and the terms of the relationship.
Is DESC ISR a Certification?
Not in the same way as ISO 27001.
DESC describes the Information Security Regulation as a set of minimum information-security requirements for Dubai Government Entities. It does not describe ISR as a certification scheme in which an organisation receives an “ISR certificate” after passing a certification audit.
That does not mean ISR is only a document to follow. Government Entities are subject to compliance assessment and audit. ISR Version 3 requires auditing how effectively the regulation has been implemented. Organizations can assign the audit to an independent audit team or an external party, with requirements for objectivity and impartiality.
The Government Entity, the ISR controls that apply to it, and any additional requirements linked to its work with other organisations will determine what gets assessed.
What an ISR Assessment May Look At
An assessment is not limited to checking whether policies exist on paper. The assessor may review the controls that apply, examine supporting evidence and check how those controls work in practice.
This can include:
- reviewing which ISR controls apply
- examining policies, records and other evidence
- checking how controls work in practice
- testing selected controls where required
- recording findings and corrective actions
- following up on outstanding issues
The assessment process can vary depending on the scope and controls being assessed. Having a policy in place does not, by itself, prove that an ISR control is working.
What Is the ISR Auditor Certification Program?
In September 2026, DESC announced its ISR Auditor Certification Program for auditors and information-security professionals. The programme is intended to give auditors a consistent method for assessing ISR compliance and reviewing evidence.
This is a certification programme for auditors, not a certification scheme for organisations under ISR.
Is ISO 27001 Enough?
No. ISO/IEC 27001 certification does not automatically mean an organisation complies with DESC ISR.
ISR sets information-security requirements under Dubai’s electronic-security rules. ISR sets information-security requirements under Dubai’s electronic-security rules. There can be overlap between the two, but they are not the same set of requirements.
An organisation that already follows ISO 27001 can compare its existing controls with the ISR requirements that apply to it. This can reduce duplicate work and help the organisation spot ISR requirements that ISO 27001 does not cover.
Are You in Scope? A Practical Decision Path
For a private organisation, start with its legal status and its relationship with the Dubai Government. Handling government information or accessing government systems may create security obligations, but neither fact alone means that every ISR requirement applies directly to the organisation.
1. Are you a Dubai Government Entity?
If yes, ISR applies directly to you as a Government Entity. DESC states that ISR applies to all Dubai Government Entities, subject to the applicability review that determines which domains and controls apply.
2. Have you been classified as a Critical Non-government Entity?
If yes, review the electronic-security requirements that apply to Critical Non-government Entities under Dubai Law No. 15 of 2024 and the rules issued by DESC.
3. Does a Dubai Government Entity oversee your activities as a Non-government Entity?
If yes, check the electronic-security controls, directives and measures set by the supervising Government Entity, along with the contract and other applicable documents. Article 15 requires these controls and measures to be approved by DESC.
4. Does your contract or tender impose ISR or DESC security requirements?
Check the contract, security schedule, tender documents and other agreements for security requirements you are required to follow.
If you are still unsure, confirm which requirements apply with the Government Entity responsible for the relationship or with DESC before starting an assessment.
DESC ISR Compliance Roadmap
Once you know which ISR requirements apply, the next step is to compare them with the controls already in place and work through anything that still needs attention.
1. Confirm the Requirements
Start with the ISR version and controls that apply to the organisation. Then check whether the Government Entity involved has set additional security requirements through a contract, tender, security schedule or other agreement.
2. Review Controls and Risks
Compare the applicable requirements with the controls already in place. Record where controls are working, where changes are needed and which risks need attention first. The priority will depend on factors such as the information involved, system importance, threat exposure and potential business impact.
3. Complete the Required Actions
Assign an owner to each action and set a target date for completion. Depending on the findings, this may involve changes to policies, access controls, technical safeguards, operating procedures or supplier arrangements.
Controls should then be tested where required to check that they work as intended. Keep the supporting evidence as the work progresses, such as policies, risk records, access reviews, vulnerability reports, patch records, monitoring records and security test results.
4. Keep the Controls Current
Security controls need to be maintained after an assessment. Systems change, new services are introduced, suppliers change and new vulnerabilities can appear. Review the controls and supporting evidence when the organisation’s environment or risks change.
Evidence Checklist
An ISR assessment is not based only on whether a policy exists. The organisation may also need to provide records showing how the controls are managed and used. The exact evidence will depend on the ISR domains and controls that apply.
| Area | Examples of evidence |
| Governance | Security policies, committee records, role descriptions and CISO or information-security reporting arrangements |
| Risk | Risk register, risk assessments, risk treatment records and approved risk acceptance |
| Information and assets | Asset inventory, ownership records, information classification and retention or disposal records |
| Access control | Access reviews, privileged-access records, MFA records and user joiner, mover and leaver records |
| Technical security | Configuration records, vulnerability assessment reports, patch records, penetration-testing reports and encryption records |
| Monitoring and incidents | Security logs, alerts, monitoring records, incident tickets and SOC reports |
| Business continuity | Business impact analysis, continuity plans, backup test results and disaster recovery exercise records |
| Third parties | Supplier due-diligence records, contracts with security requirements, security questionnaires and supplier assessment reports |
| Assurance and audit | Internal audit reports, control test results, corrective-action records, approved exceptions and management reports |
How Qualysec Supports DESC ISR Compliance
An ISR assessment can become difficult when the security team has policies and security tools in place but cannot confidently say whether the controls actually hold up under testing. A recent penetration test may also leave questions about scope, findings, remediation and retesting.
Qualysec supports the security-testing side of this work through Human led ai penetration testing. Its Three Layered Defence System combines automated testing, AI-powered analysis and human-led validation to examine security weaknesses across applications, APIs, networks, cloud environments and other in-scope systems.
The focus is not simply on producing a list of vulnerabilities. The testing gives security teams findings, remediation guidance and retesting evidence that they can use alongside their wider ISR assessment and security records.
For organisations preparing for an ISR review, this can help connect a security requirement with what is actually happening in the environment, rather than treating compliance as a paperwork exercise.
Conclusion
DESC ISR sets minimum information-security requirements for Dubai Government Entities and also applies to Critical Non-government Entities under Dubai’s electronic-security rules. Other Non-government Entities may have security requirements set by the Government Entity overseeing their activities.
For a private organisation, the important first step is to understand its legal status and its relationship with the dubai information security regulation. The information, systems and services involved, along with the security requirements set for that relationship, then help define what you need to review.
Preparing for ISR is therefore more than collecting policies before an assessment. Organisations need to review the controls that apply to them, test where required, fix issues and keep evidence up to date as their systems and services change.
If your organisation needs help with ISR scope, security testing or assessment preparation, Qualysec can support with applicabilityx reviews, risk assessments, security testing and evidence preparation.
Frequently Asked Questions
1. What does DESC ISR stand for?
DESC ISR stands for Dubai Electronic Security Center Information Security Regulation.
2. Who must comply with DESC ISR?
Dubai Government Entities are within the direct scope of ISR. Dubai Law No. 15 of 2024 also places Critical Non-government Entities under DESC’s electronic-security requirements. Other Non-government Entities may have requirements set by a supervising Government Entity.
3. Does ISR apply to all private companies in Dubai?
No. Being a private company in Dubai does not automatically place an organisation under ISR. A company’s legal classification and its relationship with a Dubai Government Entity determine which electronic-security requirements apply.
4. Does ISR apply to cloud providers?
A cloud provider is not automatically treated as a Government Entity because it provides cloud services to the Dubai Government. Its obligations can depend on the Government Entity it works with and the security requirements set for that relationship.
5. How many domains does ISR have?
ISR has 13 domains, grouped under Governance, Operation and Assurance.
6. What changed in ISR Version 3?
Version 3 introduced changes covering information-security leadership, data residency, third-party security, data-centre security, cyber resilience and problem management.
7. Is ISR the same as ISO 27001?
No. ISO/IEC 27001 is an international management-system standard, while ISR sets information-security requirements for organisations and relationships covered by Dubai’s electronic-security rules. ISO 27001 certification does not automatically prove ISR compliance.
8. Is ISR compliance mandatory?
For organisations within the applicable scope, compliance with the requirements that apply to them is mandatory. Government Entities and Critical Non-government Entities have obligations under Dubai Law No. 15 of 2024, while other Non-government Entities may have security requirements set by the Government Entity overseeing their activities.







