We value your privacy

We use cookies to analyse site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Compliance
  2. DESC ISR Compliance
DESC ISR compliance, Dubai

DESC ISR compliance: what the Dubai Information Security Regulation actually asks you to prove.

If you are a Dubai government entity, or you supply one, the Information Security Regulation maintained by the Dubai Electronic Security Center is not optional. It was formalised under Resolution No. 13 of 2012, version 3 strengthened the cloud, IoT and supply-chain provisions, and it aligns closely with ISO 27001 and NIST CSF. The part that catches organisations out is not the control list, it is the evidence: ISR expects you to demonstrate that controls operate, on a cadence, with records. We build and run the technical side of that.

Book a DESC ISR gap assessmentSee what is involved
Information security compliance assessment for Dubai entities
  • Resolution 13of 2012, ISR basis
  • ISR v3Cloud, IoT, supply chain
  • QuarterlyVulnerability assessment cadence
  • In-houseVAPT, not subcontracted
What DESC ISR work involves

Eight workstreams that take an organisation to defensible compliance.

ISR is a management-system regulation, not a checklist of products. That is why buying a firewall does not move you towards compliance and why organisations with good security sometimes still fail: they have the controls and not the evidence that the controls operate.

Scoping and classification

Before anything else, establish what actually applies to you. Obligations differ by entity classification and by whether you are the government body itself or a supplier to one. Getting this wrong in either direction is expensive: over-scoping wastes a year of budget, under-scoping produces a finding. This is the first conversation, and it is the one most providers skip.

Gap assessment against the control set

A structured review of current state against the applicable ISR controls, covering governance, risk management, asset management, access control, cryptography, operations security, communications, supplier relationships, incident management and continuity. Output is a gap register with severity, effort and owner rather than a generic score out of ten.

Policy and documentation set

ISR expects documented policy, and most organisations either have none or have a set downloaded years ago that describes an organisation they no longer are. We write policy that matches how you actually operate, because a policy nobody follows is worse than no policy: it converts an operational gap into a documented non-conformity.

Technical control implementation

Identity and access management with privileged access controlled and logged, encryption in transit and at rest, endpoint protection, network segmentation, logging and monitoring with retention, secure configuration baselines, and patch management with measurable currency. The engineering half of the programme.

Testing on the required cadence

Published guidance describes quarterly vulnerability assessment, annual penetration testing of external-facing services, and bi-annual comprehensive testing for critical infrastructure, with the exact obligation depending on your classification. We deliver that testing in-house on a diarised calendar, with retest letters confirming closure rather than a report full of open findings.

Cloud and supply-chain provisions

ISR v3 strengthened exactly this area, and it is where most organisations are weakest. Cloud service assessment and configuration baselines, data location mapping, shared-responsibility clarity, third-party risk assessment, and contractual security requirements flowed down to your own suppliers.

Incident response and continuity

A documented and exercised incident response plan with defined roles and escalation, plus business continuity and disaster recovery arrangements with tested recovery objectives. Exercised is the operative word: an untested plan is a document, and assessors ask when you last ran it.

Evidence pack and assessment support

The deliverable that decides the outcome. Access reviews with sign-off, patch compliance reports, test results and retests, incident log, change records, training completion, backup restore evidence, and supplier assessments, all current rather than assembled the month before. We maintain it continuously and sit with you through the assessment.

The mistake that costs a year

Three ways organisations get ISR badly wrong.

We have joined ISR programmes already in progress and inherited the results of others. The failures are consistent and all three are avoidable at the start rather than discoverable at assessment.

  • Buying products instead of building a management system. ISR is a governance regulation. A new firewall, an EDR licence and a SIEM subscription do not move you towards compliance on their own, because the regulation asks who owns the risk, how you decided that control was adequate, and where the evidence is that it operated last quarter. Organisations routinely spend heavily on tooling and then fail on documentation.
  • Writing policy that describes a different organisation. Downloading a policy set and changing the logo is worse than having nothing, because it converts an operational gap into a documented non-conformity. If your policy says access is reviewed quarterly and it is not, you have handed the assessor the finding in writing.
  • Treating it as a project with an end date. The testing cadence is periodic, access reviews are periodic, and the evidence pack has to be current on the day it is asked for rather than on the day the programme closed. The organisations that struggle at reassessment are the ones who disbanded the programme after the first pass and let eighteen months of drift accumulate.
Ask for a scoping conversation
Why organisations bring us in

Four reasons this needs an operator rather than only a consultancy.

We implement and then run it, not just advise

The common failure pattern is a consultancy delivering an excellent gap report and a policy set, then leaving. Twelve months later the controls have drifted, the testing calendar has slipped, and the evidence pack is stale. Compliance is an operating state rather than a project, so the useful provider is one who is still there in month eighteen keeping it true.

The testing is ours, so the cadence holds

Vulnerability assessment and penetration testing are delivered by our own team rather than subcontracted. When testing is a regulatory cadence rather than an occasional project, coordinating it through a third party introduces delay you do not control, and a missed quarter is a finding regardless of whose diary caused it.

We scope honestly, including scoping you out

Not every organisation touching a Dubai government contract carries the full weight of ISR, and we have told prospective clients that their obligation was lighter than they had been led to believe. That conversation costs us revenue and it is the right one. Over-scoping compliance is a real and expensive problem in this market.

One programme, not three vendors

Organisations frequently end up with a compliance consultancy, a penetration testing firm and an IT provider who each hold a piece and none of whom own the outcome. We can hold all three, which removes the coordination overhead and the gaps between them, and means one party is accountable when an assessor asks a question.

Who has to care about ISR

Six organisation types and how the obligation reaches them.

Dubai government entities

Directly in scope. The obligation is clear and the assessment regime is established. The work is usually maturity improvement rather than starting from nothing.

Suppliers to government entities

Reached through contract rather than directly by the regulation. The requirement often appears in a tender document with a deadline attached, which is when most suppliers first hear of ISR.

Critical service providers

Organisations operating services the emirate depends on. Obligations here are heavier and the testing cadence for critical infrastructure is more demanding.

Financial services with government exposure

Frequently already carrying DFSA or Central Bank obligations, so the work is mapping overlapping frameworks rather than building from zero. Considerable reuse is possible.

Healthcare providers in the public system

Health-authority requirements plus information security regulation, with patient data raising the consequence of any gap. Overlap with health-sector standards is substantial.

Technology vendors bidding for public work

Software and services companies who discover during a tender that they must demonstrate security maturity they have never documented. Usually the tightest deadlines we see.

How ISR relates to other frameworks

DESC ISR against the standards you may already hold.

If you already run ISO 27001 or align to NIST CSF, a great deal transfers, and knowing how much prevents you paying twice. This is the mapping we use to decide how much of an existing programme can be reused.
Scope
DESC ISRDubai government and critical providers
ISO 27001Any organisation, voluntary
NIST CSFAny organisation, voluntary
UAE IA Standards (NESA)UAE critical national infrastructure
Mandatory
DESC ISRYes, where in scope
ISO 27001No, unless contractually required
NIST CSFNo
UAE IA Standards (NESA)Yes, where in scope
Certifiable by an accredited body
DESC ISRAssessment regime, not ISO-style cert
ISO 27001
NIST CSF
UAE IA Standards (NESA)Compliance regime
Prescribed testing cadence
DESC ISR
ISO 27001Risk-driven
NIST CSFRisk-driven
UAE IA Standards (NESA)
Cloud-specific provisions
DESC ISRStrengthened in v3
ISO 27001Via 27017 and 27018
NIST CSFYes
UAE IA Standards (NESA)Yes
Supply-chain provisions
DESC ISRStrengthened in v3
ISO 27001
NIST CSF
UAE IA Standards (NESA)
Documented ISMS expected
DESC ISR
ISO 27001
NIST CSFRecommended
UAE IA Standards (NESA)
Reuse if you already hold ISO 27001
DESC ISRSubstantial
ISO 27001Not applicable
NIST CSFSubstantial
UAE IA Standards (NESA)Substantial
Typical first-time programme length
DESC ISR4 to 9 months
ISO 270016 to 12 months
NIST CSF3 to 6 months
UAE IA Standards (NESA)6 to 12 months
Feature
DESC ISR
ISO 27001
NIST CSF
UAE IA Standards (NESA)
Scope
Dubai government and critical providersAny organisation, voluntaryAny organisation, voluntaryUAE critical national infrastructure
Mandatory
Yes, where in scopeNo, unless contractually requiredNoYes, where in scope
Certifiable by an accredited body
Assessment regime, not ISO-style certCompliance regime
Prescribed testing cadence
Risk-drivenRisk-driven
Cloud-specific provisions
Strengthened in v3Via 27017 and 27018YesYes
Supply-chain provisions
Strengthened in v3
Documented ISMS expected
Recommended
Reuse if you already hold ISO 27001
SubstantialNot applicableSubstantialSubstantial
Typical first-time programme length
4 to 9 months6 to 12 months3 to 6 months6 to 12 months
The compliance calendar

What has to happen, and how often, once you are compliant.

This is the part organisations underestimate. Reaching compliance is a project; staying compliant is a calendar. Exact frequencies depend on your classification, and we confirm them during scoping rather than assuming the heaviest case.
ActivityTypical frequencyEvidence producedWho usually owns it
Vulnerability assessmentQuarterlyScan report and remediation trackerUs, in-house
Penetration test, external-facingAnnualTest report plus retest letterUs, in-house
Comprehensive test, critical infrastructureBi-annual where applicableFull scope report and closure evidenceUs, in-house
User access reviewQuarterlyReviewed list with sign-off, not just a listYou, we produce and chase it
Privileged access reviewQuarterlyElevation log and justification recordJoint
Backup restore testQuarterlyRestore evidence with timestampsUs
Incident response exerciseAnnual minimumTabletop record and plan revisionJoint
Business continuity testAnnualTest report against stated RPO and RTOJoint
Supplier risk assessmentAnnual, and at onboardingAssessment record per supplierYou, we provide the framework
Risk register reviewQuarterlyReviewed register with owner sign-offYou, we facilitate
Security awareness trainingAnnual, plus on joiningCompletion recordsUs
Policy reviewAnnualVersion history and approval recordJoint
How we engage

Four steps, starting with whether you are actually in scope.

The first step frequently changes the size of the engagement, sometimes substantially downwards. We would rather establish that at the start than sell a programme you did not need.
  1. 1

    Applicability review

    Week 1

    What is your classification, are you the entity or a supplier, what does your contract actually require, and what do you already hold. Output is a written applicability statement that tells you which obligations genuinely apply. Occasionally the answer is that the obligation is lighter than you were told.

  2. 2

    Gap assessment

    Weeks 2 to 4

    Structured assessment against the applicable controls with evidence gathered rather than a questionnaire filled in by the client. Output is a gap register with severity, effort and named owners, plus a reuse map against any existing ISO 27001 or NIST work.

  3. 3

    Remediation programme

    Months 2 to 7

    Governance and documentation, technical implementation, and testing, sequenced by risk. Run as a programme with a named lead, fortnightly reporting, and a visible plan rather than a stream of tickets nobody can track against the regulation.

  4. 4

    Assessment support and steady state

    Month 7 onwards

    Evidence pack validated, internal pre-assessment run, formal assessment supported, and then the compliance calendar handed into operation with the testing schedule diarised and the pack maintained continuously.

A realistic programme

What a first-time ISR programme actually looks like.

Between four and nine months for an organisation starting without a documented management system, and the variable is almost never engineering. It is decision latency: how quickly risk owners are named, policies approved, and budget released. Organisations that move fast on those three finish at the short end.
  1. 01
    Month 1· 4 weeks

    Scope, classify and assess

    Establish exactly which obligations apply to your classification, because this determines everything downstream and is the most common place to go wrong. Then a structured gap assessment against the applicable control set, covering governance through to incident management, producing a register with severity, effort and a named owner per gap. We also identify what can be reused from any existing ISO 27001 or NIST work, which frequently removes a third of the programme.

    • Applicability and scope statement
    • Gap register with severity and effort
    • Reuse map against existing certifications
    • Costed remediation plan by quarter
  2. 02
    Months 2 to 3· 8 weeks

    Governance and documentation

    Information security policy set written to match how the organisation genuinely operates rather than downloaded and renamed. Risk assessment methodology agreed and the initial risk register populated with named owners. Asset inventory built and classified. Roles defined including who is accountable when an incident happens at 3am. This phase is unglamorous and it is what assessors examine first.

    • Approved information security policy set
    • Risk register with named owners and treatment plans
    • Classified asset inventory
    • Defined roles, responsibilities and escalation
  3. 03
    Months 3 to 6· 12 weeks

    Technical remediation

    The engineering work, sequenced by risk rather than by ease. Identity and privileged access, encryption at rest and in transit, network segmentation, secure configuration baselines, logging and monitoring with appropriate retention, patch management with measurable currency, and backup with restore testing that is actually performed and evidenced. Cloud configuration and third-party risk assessment run in parallel, since ISR v3 weights both heavily.

    • Hardened identity and privileged access model
    • Logging, monitoring and retention operating
    • Configuration baselines applied and measured
    • Cloud and supplier risk assessments completed
  4. 04
    Months 5 to 7· 8 weeks

    Testing and exercising

    Vulnerability assessment across the estate, penetration testing of external-facing services, remediation of what those find, and retesting to confirm closure. In parallel, the incident response plan is exercised with a tabletop involving the people who would actually be called, and business continuity recovery objectives are tested rather than asserted. Findings from the exercise usually change the plan, which is the point of running it.

    • Vulnerability assessment and penetration test reports
    • Retest letters confirming closure
    • Incident response tabletop record and revised plan
    • Continuity and recovery test evidence
  5. 05
    Months 7 to 9· 8 weeks

    Evidence, assessment and steady state

    Assemble and validate the evidence pack, run an internal review against the control set to find anything an assessor would find first, and support the formal assessment. Then the transition that matters most: from project to operating state, with the testing calendar diarised, access reviews scheduled, and the evidence pack maintained continuously rather than rebuilt annually.

    • Complete, validated evidence pack
    • Internal pre-assessment review and closure of findings
    • Assessment support and response to queries
    • Annual compliance calendar in operation
“A tender required DESC ISR alignment and we had eleven weeks. Two firms told us it was impossible and quoted for a nine-month programme anyway. GR did the scoping first and established that as a supplier our obligations were narrower than the full entity control set, then built to that scope. We submitted on time with a documented position and a remediation plan for the remainder. The honesty in that first week is what won them the work.”
Chief Operating Officer
Executive leadership · Dubai technology services supplier
Tender submitted on time with a defensible position
DESC ISR FAQ

What organisations ask before starting.

The regulation is mandatory for Dubai government entities and critical service providers, so if you are one of those the answer is yes and the question is only which controls apply at your classification. For everyone else the obligation usually arrives through a contract rather than directly: a tender or supplier agreement requires alignment, and the scope is then whatever that contract specifies, which is frequently narrower than the full entity control set. This distinction matters enormously to cost and timeline, and it is the single most common thing we find misunderstood. We establish it in writing in the first week, and we have told organisations their obligation was lighter than they had been advised elsewhere.

A substantial amount, frequently between half and two thirds of the control work, because ISR aligns closely with ISO 27001 and NIST CSF. Your ISMS, risk methodology, policy structure, asset inventory, internal audit process and management review all carry across with mapping rather than rebuilding. What typically does not transfer cleanly is the prescribed testing cadence, since ISO takes a risk-driven approach where ISR is more specific, and some of the cloud and supply-chain provisions strengthened in version 3. We produce a reuse map during the gap assessment showing exactly which of your existing controls satisfy which ISR requirements, which usually removes a third of the expected programme cost.

Four to nine months for an organisation without a documented management system, and the variable is almost never engineering capacity. It is decision latency: how quickly risk owners are named, policies are approved, and budget is released. Organisations that assign a genuine executive sponsor and make those decisions in days rather than weeks finish near four months. Those where policy approval sits in a committee that meets monthly finish near nine. If you already hold ISO 27001, expect three to five months. If a tender deadline is shorter than that, the honest approach is a documented position plus a dated remediation plan, which is frequently acceptable and is far better than an unsupportable claim of full compliance.

Published guidance describes quarterly vulnerability assessment across systems, annual penetration testing of external-facing services, and bi-annual comprehensive testing for critical infrastructure. The important qualification is that the exact obligation depends on your classification, so we confirm what applies to you during scoping rather than assuming the heaviest case and selling you testing you do not need. We deliver all of it in-house, which matters when the cadence is a regulatory requirement: a missed quarter is a finding regardless of whether a subcontractor diary caused it. Every test comes with a retest confirming closure, because a report full of open findings evidences the opposite of compliance.

Yes, and it is common, usually at the point where a consultancy has delivered the gap assessment and policy set and the organisation realises nobody is going to implement or operate any of it. We can take the remediation and the ongoing operating state without redoing the assessment work, provided it was sound, and we will tell you honestly if it was not. The most frequent problem we inherit is a policy set that describes an organisation the client does not resemble, which has to be rewritten because it actively creates findings. Taking over mid-programme is straightforward; the awkward part is usually the conversation with the incumbent, and we are comfortable being introduced as the implementation partner rather than a replacement.

We quote after the applicability review rather than publishing a figure, because the range is genuinely enormous. A supplier with a narrow contractual obligation who already holds ISO 27001 and a critical service provider starting from no documented management system differ by more than an order of magnitude. The drivers are your classification and therefore which controls apply, how much existing certification can be reused, the size and complexity of the estate, how much technical remediation the gap assessment finds, and whether you want us to operate the compliance calendar afterwards or hand it to an internal team. The applicability review itself is a small fixed fee and it frequently reduces the total.

We deliver it ourselves. That matters more for a regulatory cadence than for a one-off test, because the schedule is not negotiable and a slipped quarter is a finding. When testing is subcontracted, the scheduling depends on a third-party diary you do not control, remediation advice comes back through an intermediary, and retesting often requires a new engagement and another wait. Doing it in-house means the test, the remediation guidance and the retest all sit with the same team who already know your estate, and the calendar is ours to hold rather than to chase.

Findings are raised with a remediation period rather than an immediate consequence in most cases, so a finding is a problem to fix rather than a catastrophe. The genuinely damaging outcome is a pattern of repeat findings across cycles, because that evidences a management system that does not work rather than a control that slipped. Practically, the more immediate risk for suppliers is commercial: a finding that surfaces during a tender or a contract review affects the relationship faster than any regulatory process. This is why we run an internal pre-assessment before the formal one, deliberately looking for what an assessor would find first, so surprises happen in a room with us rather than with them.

Less than people fear, but the right people. You need an executive sponsor who can approve policy and release budget without a committee cycle, because decision latency is the main determinant of timeline. You need named risk owners for the significant risks, which is a governance requirement rather than a formality: an assessor will ask who owns a given risk and a vague answer is itself a finding. You need someone who knows your business processes well enough to tell us when a proposed control is unworkable in practice. Beyond that we do the heavy lifting, and we deliberately design controls that do not depend on your staff performing tasks they will quietly stop doing in month four.

Yes, and version 3 strengthened this area specifically, which is why it is now one of the more common gap areas we find. The expectations cover assessing cloud service providers, understanding and documenting the shared responsibility boundary, secure configuration of the services you consume, knowing where data physically resides, and having contractual security terms in place. The most frequent finding is not a missing control but a missing understanding: organisations assume the cloud provider handles security in areas where the shared responsibility model clearly places it with the customer. We map that boundary explicitly per service and document it, because that document is what an assessor wants to see.

They are separate regimes with substantial overlap. NESA and the UAE Information Assurance Standards operate at federal level and target critical national infrastructure, while DESC ISR is the Dubai government regulation. An organisation can be in scope for both, and where that happens the sensible approach is a single control set mapped to both frameworks rather than two parallel programmes producing two sets of evidence about the same controls. We do that mapping as part of scoping. Running them separately is a genuine waste that we see reasonably often, usually because two different advisers were engaged at different times.

Yes, and for most clients this is the more valuable half of the engagement. Reaching compliance is a project with an end; staying compliant is a recurring calendar of vulnerability assessments, penetration tests, access reviews, restore tests, exercises, supplier assessments and policy reviews, each producing evidence that has to be current on the day it is requested. We run that calendar, produce the evidence, chase the items that need your sign-off, and keep the pack continuously ready. Organisations that hand this back to an already-busy internal team are the ones we later find with eighteen months of drift and a reassessment approaching.

Often the honest answer is that the full programme is not, and we will say so. A small supplier whose contractual obligation covers a defined subset of controls should implement that subset properly and document the position, not build an enterprise management system. What we would not do is help you claim alignment you cannot evidence, because that is a worse commercial risk than an honest narrower scope with a dated plan for the rest. Buyers in this market are generally more receptive to a supplier who says precisely what they have done and what they have not than to one whose claims collapse under a single follow-up question.

Establish scope, before spending anything. Find the exact clause in your contract or the classification that puts you in scope, read what it actually requires, and get a written applicability statement. An enormous amount of wasted spend in this market comes from organisations building to a standard far heavier than the one that applies to them, usually because a vendor scoped the engagement rather than the regulation. That review is a small piece of work, it is where we start every engagement, and if the outcome is that you need much less than you feared then that is a good result rather than a lost sale.
Related compliance services

What organisations usually scope alongside ISR.

VAPT testing Dubai

The testing half of the cadence, delivered in-house with retest letters confirming closure.

Learn more

NESA and UAE IA compliance

The federal regime. Where both apply, one mapped control set beats two parallel programmes.

Learn more

Cybersecurity audit and compliance

Broader posture assessment and the evidence pack that supplier assessments and banks ask for.

Learn more
Start with scope

Find out what actually applies to you before you spend anything.

Send us the clause, the tender requirement, or your classification. We will tell you in writing which ISR obligations genuinely apply, what you can reuse from any existing certification, and what a realistic timeline looks like. If the answer is that you need less than you were told, that is what we will say.

Book a DESC ISR applicability reviewCall +971 56 613 2743

Related Services

Explore more solutions that work great with this service

IT Audit Services Dubai

Assessment, technical test or certification, scoped properly

Learn more

VAPT Testing

CREST-certified vulnerability assessment and penetration testing

Learn more

NESA / IA Compliance

UAE Information Assurance Standards compliance

Learn more

Cybersecurity Audit

Security assessment and compliance audit

Learn more

Penetration Testing

Black, grey, and white-box penetration testing

Learn more

Vulnerability Assessment

Continuous vulnerability scanning and remediation

Learn more

SOC-as-a-Service

24/7 SOC on Microsoft Sentinel

Learn more
GR IT SERVICES

Leading IT services provider in Dubai,
delivering enterprise-grade solutions
for businesses across the UAE.

Microsoft CSP PartnerCISGuard

Get the Helpdesk app

Raise and track IT tickets from your phone.

Download on the App StoreGet it on Google Play
Learn more about the app

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business Manager
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support Dubai
  • IT AMC Dubai
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • Iris Bay Tower, Office 903,
    Business Bay, Dubai, UAE
  • +971 56 613 2743
  • hello@gritservices.ae
  • gritservices.ae

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie Policy