Framework · Last verified

Information Security Regulation

DESC's Information Security Regulation sets minimum security controls for all Dubai Government Entities, formalized under Resolution No. 13 of 2012. Dubai Law No. 11 of 2014 gives DESC responsibility for maintaining and updating the Regulation, which is organized into thirteen control domains.

Class
Framework
Owner
Dubai Electronic Security Center (DESC)
Last verified

What it is

DESC's own purpose statement: "The purpose of the Information Security Regulation is to provide all Dubai Government Entities with the standards to ensure continuity of critical business processes, and minimize information security related risks and damages by preventing and/or minimizing information security incidents."

The Regulation does not prescribe technology: "The Information Security Regulation is a technology neutral framework and will not handle any technological implementation."

Scope, in DESC's own words: "The Information Security Regulation presents the minimum requirements for information security controls and is applicable to all Dubai Government Entities, including but not limited to employees, consultants, contractors and visitors who are not government employees but are engaged with it through various means."

Structure: "The information Security Regulation is broken down into thirteen domains. Each domain takes into consideration one or more major classes of information security: Governance, Operation, and Assurance."

Who owns it

DESC's own account of its legal basis: "Dubai Government Information Security Regulation was formalized pursuant to Resolution No. 13 of 2012 based on leading information security regulations, frameworks, policies and practices. Further, based on Dubai Law No. 11 of 2014, DESC has the responsibility of maintaining and continuously improving the Information Security Regulation (ISR)."

Who asks for it

Statutory (scoped). The mandate applies to Dubai Government Entities only — the source page names no UAE federal-level or private-sector obligation. DESC and the ISR are a Dubai emirate-level instrument, distinct from federal UAE regulation such as TDRA's IA Regulation.

Sources

Last verified:

This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.

Cite this page

Attributing this record helps other researchers verify it independently.

"Information Security Regulation." Certifidex, FutureTechnologies. Last verified 1 September 2026. https://certifidex.com/frameworks/desc-isr

All frameworks & audits →