DESC ISR compliance: what the Dubai Information Security Regulation actually asks you to prove.
If you are a Dubai government entity, or you supply one, the Information Security Regulation maintained by the Dubai Electronic Security Center is not optional. It was formalised under Resolution No. 13 of 2012, version 3 strengthened the cloud, IoT and supply-chain provisions, and it aligns closely with ISO 27001 and NIST CSF. The part that catches organisations out is not the control list, it is the evidence: ISR expects you to demonstrate that controls operate, on a cadence, with records. We build and run the technical side of that.

- Resolution 13of 2012, ISR basis
- ISR v3Cloud, IoT, supply chain
- QuarterlyVulnerability assessment cadence
- In-houseVAPT, not subcontracted
Eight workstreams that take an organisation to defensible compliance.
Scoping and classification
Before anything else, establish what actually applies to you. Obligations differ by entity classification and by whether you are the government body itself or a supplier to one. Getting this wrong in either direction is expensive: over-scoping wastes a year of budget, under-scoping produces a finding. This is the first conversation, and it is the one most providers skip.
Gap assessment against the control set
A structured review of current state against the applicable ISR controls, covering governance, risk management, asset management, access control, cryptography, operations security, communications, supplier relationships, incident management and continuity. Output is a gap register with severity, effort and owner rather than a generic score out of ten.
Policy and documentation set
ISR expects documented policy, and most organisations either have none or have a set downloaded years ago that describes an organisation they no longer are. We write policy that matches how you actually operate, because a policy nobody follows is worse than no policy: it converts an operational gap into a documented non-conformity.
Technical control implementation
Identity and access management with privileged access controlled and logged, encryption in transit and at rest, endpoint protection, network segmentation, logging and monitoring with retention, secure configuration baselines, and patch management with measurable currency. The engineering half of the programme.
Testing on the required cadence
Published guidance describes quarterly vulnerability assessment, annual penetration testing of external-facing services, and bi-annual comprehensive testing for critical infrastructure, with the exact obligation depending on your classification. We deliver that testing in-house on a diarised calendar, with retest letters confirming closure rather than a report full of open findings.
Cloud and supply-chain provisions
ISR v3 strengthened exactly this area, and it is where most organisations are weakest. Cloud service assessment and configuration baselines, data location mapping, shared-responsibility clarity, third-party risk assessment, and contractual security requirements flowed down to your own suppliers.
Incident response and continuity
A documented and exercised incident response plan with defined roles and escalation, plus business continuity and disaster recovery arrangements with tested recovery objectives. Exercised is the operative word: an untested plan is a document, and assessors ask when you last ran it.
Evidence pack and assessment support
The deliverable that decides the outcome. Access reviews with sign-off, patch compliance reports, test results and retests, incident log, change records, training completion, backup restore evidence, and supplier assessments, all current rather than assembled the month before. We maintain it continuously and sit with you through the assessment.
Three ways organisations get ISR badly wrong.
We have joined ISR programmes already in progress and inherited the results of others. The failures are consistent and all three are avoidable at the start rather than discoverable at assessment.
- Buying products instead of building a management system. ISR is a governance regulation. A new firewall, an EDR licence and a SIEM subscription do not move you towards compliance on their own, because the regulation asks who owns the risk, how you decided that control was adequate, and where the evidence is that it operated last quarter. Organisations routinely spend heavily on tooling and then fail on documentation.
- Writing policy that describes a different organisation. Downloading a policy set and changing the logo is worse than having nothing, because it converts an operational gap into a documented non-conformity. If your policy says access is reviewed quarterly and it is not, you have handed the assessor the finding in writing.
- Treating it as a project with an end date. The testing cadence is periodic, access reviews are periodic, and the evidence pack has to be current on the day it is asked for rather than on the day the programme closed. The organisations that struggle at reassessment are the ones who disbanded the programme after the first pass and let eighteen months of drift accumulate.
Four reasons this needs an operator rather than only a consultancy.
We implement and then run it, not just advise
The common failure pattern is a consultancy delivering an excellent gap report and a policy set, then leaving. Twelve months later the controls have drifted, the testing calendar has slipped, and the evidence pack is stale. Compliance is an operating state rather than a project, so the useful provider is one who is still there in month eighteen keeping it true.
The testing is ours, so the cadence holds
Vulnerability assessment and penetration testing are delivered by our own team rather than subcontracted. When testing is a regulatory cadence rather than an occasional project, coordinating it through a third party introduces delay you do not control, and a missed quarter is a finding regardless of whose diary caused it.
We scope honestly, including scoping you out
Not every organisation touching a Dubai government contract carries the full weight of ISR, and we have told prospective clients that their obligation was lighter than they had been led to believe. That conversation costs us revenue and it is the right one. Over-scoping compliance is a real and expensive problem in this market.
One programme, not three vendors
Organisations frequently end up with a compliance consultancy, a penetration testing firm and an IT provider who each hold a piece and none of whom own the outcome. We can hold all three, which removes the coordination overhead and the gaps between them, and means one party is accountable when an assessor asks a question.
Six organisation types and how the obligation reaches them.
Dubai government entities
Directly in scope. The obligation is clear and the assessment regime is established. The work is usually maturity improvement rather than starting from nothing.
Suppliers to government entities
Reached through contract rather than directly by the regulation. The requirement often appears in a tender document with a deadline attached, which is when most suppliers first hear of ISR.
Critical service providers
Organisations operating services the emirate depends on. Obligations here are heavier and the testing cadence for critical infrastructure is more demanding.
Financial services with government exposure
Frequently already carrying DFSA or Central Bank obligations, so the work is mapping overlapping frameworks rather than building from zero. Considerable reuse is possible.
Healthcare providers in the public system
Health-authority requirements plus information security regulation, with patient data raising the consequence of any gap. Overlap with health-sector standards is substantial.
Technology vendors bidding for public work
Software and services companies who discover during a tender that they must demonstrate security maturity they have never documented. Usually the tightest deadlines we see.
DESC ISR against the standards you may already hold.
| Feature | DESC ISR | ISO 27001 | NIST CSF | UAE IA Standards (NESA) |
|---|---|---|---|---|
Scope | Dubai government and critical providers | Any organisation, voluntary | Any organisation, voluntary | UAE critical national infrastructure |
Mandatory | Yes, where in scope | No, unless contractually required | No | Yes, where in scope |
Certifiable by an accredited body | Assessment regime, not ISO-style cert | Compliance regime | ||
Prescribed testing cadence | Risk-driven | Risk-driven | ||
Cloud-specific provisions | Strengthened in v3 | Via 27017 and 27018 | Yes | Yes |
Supply-chain provisions | Strengthened in v3 | |||
Documented ISMS expected | Recommended | |||
Reuse if you already hold ISO 27001 | Substantial | Not applicable | Substantial | Substantial |
Typical first-time programme length | 4 to 9 months | 6 to 12 months | 3 to 6 months | 6 to 12 months |
What has to happen, and how often, once you are compliant.
| Activity | Typical frequency | Evidence produced | Who usually owns it | |
|---|---|---|---|---|
| Vulnerability assessment | Quarterly | Scan report and remediation tracker | Us, in-house | |
| Penetration test, external-facing | Annual | Test report plus retest letter | Us, in-house | |
| Comprehensive test, critical infrastructure | Bi-annual where applicable | Full scope report and closure evidence | Us, in-house | |
| User access review | Quarterly | Reviewed list with sign-off, not just a list | You, we produce and chase it | |
| Privileged access review | Quarterly | Elevation log and justification record | Joint | |
| Backup restore test | Quarterly | Restore evidence with timestamps | Us | |
| Incident response exercise | Annual minimum | Tabletop record and plan revision | Joint | |
| Business continuity test | Annual | Test report against stated RPO and RTO | Joint | |
| Supplier risk assessment | Annual, and at onboarding | Assessment record per supplier | You, we provide the framework | |
| Risk register review | Quarterly | Reviewed register with owner sign-off | You, we facilitate | |
| Security awareness training | Annual, plus on joining | Completion records | Us | |
| Policy review | Annual | Version history and approval record | Joint |
Four steps, starting with whether you are actually in scope.
- 1
Applicability review
Week 1
What is your classification, are you the entity or a supplier, what does your contract actually require, and what do you already hold. Output is a written applicability statement that tells you which obligations genuinely apply. Occasionally the answer is that the obligation is lighter than you were told.
- 2
Gap assessment
Weeks 2 to 4
Structured assessment against the applicable controls with evidence gathered rather than a questionnaire filled in by the client. Output is a gap register with severity, effort and named owners, plus a reuse map against any existing ISO 27001 or NIST work.
- 3
Remediation programme
Months 2 to 7
Governance and documentation, technical implementation, and testing, sequenced by risk. Run as a programme with a named lead, fortnightly reporting, and a visible plan rather than a stream of tickets nobody can track against the regulation.
- 4
Assessment support and steady state
Month 7 onwards
Evidence pack validated, internal pre-assessment run, formal assessment supported, and then the compliance calendar handed into operation with the testing schedule diarised and the pack maintained continuously.
What a first-time ISR programme actually looks like.
- 01Month 1· 4 weeks
Scope, classify and assess
Establish exactly which obligations apply to your classification, because this determines everything downstream and is the most common place to go wrong. Then a structured gap assessment against the applicable control set, covering governance through to incident management, producing a register with severity, effort and a named owner per gap. We also identify what can be reused from any existing ISO 27001 or NIST work, which frequently removes a third of the programme.
- Applicability and scope statement
- Gap register with severity and effort
- Reuse map against existing certifications
- Costed remediation plan by quarter
- 02Months 2 to 3· 8 weeks
Governance and documentation
Information security policy set written to match how the organisation genuinely operates rather than downloaded and renamed. Risk assessment methodology agreed and the initial risk register populated with named owners. Asset inventory built and classified. Roles defined including who is accountable when an incident happens at 3am. This phase is unglamorous and it is what assessors examine first.
- Approved information security policy set
- Risk register with named owners and treatment plans
- Classified asset inventory
- Defined roles, responsibilities and escalation
- 03Months 3 to 6· 12 weeks
Technical remediation
The engineering work, sequenced by risk rather than by ease. Identity and privileged access, encryption at rest and in transit, network segmentation, secure configuration baselines, logging and monitoring with appropriate retention, patch management with measurable currency, and backup with restore testing that is actually performed and evidenced. Cloud configuration and third-party risk assessment run in parallel, since ISR v3 weights both heavily.
- Hardened identity and privileged access model
- Logging, monitoring and retention operating
- Configuration baselines applied and measured
- Cloud and supplier risk assessments completed
- 04Months 5 to 7· 8 weeks
Testing and exercising
Vulnerability assessment across the estate, penetration testing of external-facing services, remediation of what those find, and retesting to confirm closure. In parallel, the incident response plan is exercised with a tabletop involving the people who would actually be called, and business continuity recovery objectives are tested rather than asserted. Findings from the exercise usually change the plan, which is the point of running it.
- Vulnerability assessment and penetration test reports
- Retest letters confirming closure
- Incident response tabletop record and revised plan
- Continuity and recovery test evidence
- 05Months 7 to 9· 8 weeks
Evidence, assessment and steady state
Assemble and validate the evidence pack, run an internal review against the control set to find anything an assessor would find first, and support the formal assessment. Then the transition that matters most: from project to operating state, with the testing calendar diarised, access reviews scheduled, and the evidence pack maintained continuously rather than rebuilt annually.
- Complete, validated evidence pack
- Internal pre-assessment review and closure of findings
- Assessment support and response to queries
- Annual compliance calendar in operation
“A tender required DESC ISR alignment and we had eleven weeks. Two firms told us it was impossible and quoted for a nine-month programme anyway. GR did the scoping first and established that as a supplier our obligations were narrower than the full entity control set, then built to that scope. We submitted on time with a documented position and a remediation plan for the remainder. The honesty in that first week is what won them the work.”
What organisations ask before starting.
What organisations usually scope alongside ISR.
VAPT testing Dubai
The testing half of the cadence, delivered in-house with retest letters confirming closure.
NESA and UAE IA compliance
The federal regime. Where both apply, one mapped control set beats two parallel programmes.
Cybersecurity audit and compliance
Broader posture assessment and the evidence pack that supplier assessments and banks ask for.
Find out what actually applies to you before you spend anything.
Send us the clause, the tender requirement, or your classification. We will tell you in writing which ISR obligations genuinely apply, what you can reuse from any existing certification, and what a realistic timeline looks like. If the answer is that you need less than you were told, that is what we will say.
Related Services
Explore more solutions that work great with this service
IT Audit Services Dubai
Assessment, technical test or certification, scoped properly
VAPT Testing
CREST-certified vulnerability assessment and penetration testing
NESA / IA Compliance
UAE Information Assurance Standards compliance
Cybersecurity Audit
Security assessment and compliance audit
Penetration Testing
Black, grey, and white-box penetration testing
Vulnerability Assessment
Continuous vulnerability scanning and remediation
SOC-as-a-Service
24/7 SOC on Microsoft Sentinel