Dubai’s cybersecurity landscape is evolving rapidly, and organizations operating within the emirate’s government ecosystem are expected to keep pace. The Dubai Electronic Security Centre (DESC)  Dubai’s dedicated cybersecurity authority enforces the Information Security Regulation (ISR v3.1), a comprehensive thirteen-domain framework that sets the mandatory baseline for information security governance, risk management, and control implementation across government and critical sector entities.

DESC ISR compliance, ISO 27001 to DESC ISR mapping, Cybersecurity compliance UAE

What Is DESC ISR?

The DESC Information Security Regulation (ISR), currently at version 3.1, is a mandatory information security framework issued by the Dubai Electronic Security Centre under the governance of the Dubai Government. It establishes a structured set of requirements, controls, and domains that organizations must implement to protect their information assets, systems, and services.

The ISR is built around thirteen control domains, each targeting a critical dimension of information security. These domains are structured as follows:

  1. Domain 1: Information Security Management and Governance
  2. Domain 2: Information and Information Assets Management
  3. Domain 3: Information Security Risk Management
  4. Domain 4: Incident and Problem Management
  5. Domain 5: Access Control
  6. Domain 6: Operation, Systems and Communication Management
  7. Domain 7: Business Continuity Planning
  8. Domain 8: Information Systems Acquisition, Development and Management
  9. Domain 9: Environmental and Physical Security
  10. Domain 10: Roles and Responsibilities of Human Resources
  11. Domain 11: Compliance and Audit
  12. Domain 12: Information Security Assurance and Performance Assessment
  13. Domain 13: Cloud Security

These thirteen domains reflect much of the structure and intent of international standards, making the ISR a robust, globally aligned framework tailored specifically to Dubai’s regulatory and operational context.

Who Must Comply?

DESC ISR applies to all Dubai Government Entities (DGEs) as defined in the regulation, including but not limited to authorities, departments, councils, and committees. It also applies to any third-party service provider, consultant, contractor, or vendor that processes government data, connects to government systems, or supports the delivery of public services, as the regulation extends to “employees, consultants, contractors and visitors who are not government employees but are engaged with it through various means.” Free zone entities with direct government interfaces may also fall within scope.

The practical rule is simple: if your organization holds a government contract or handles Dubai Government information, DESC ISR compliance is a legal obligation. Non-compliance carries serious consequences including contract termination, regulatory penalties, and exclusion from government procurement.

Why Does Compliance Matter?

The UAE consistently ranks among the most cyber-targeted regions globally, facing daily threats from ransomware, phishing, supply chain compromise, and state-sponsored intrusions. DESC ISR gives organizations a structured framework to address these threats systematically rather than reactively.

Beyond security, compliance delivers tangible business value. It protects sensitive government and citizen data, demonstrates a credible security posture to clients and partners, and strengthens your competitive position in government procurement. With Dubai’s Smart Government and Digital Economy agenda accelerating, the volume of organizations required to demonstrate compliance is growing  and those that cannot will find themselves increasingly sidelined from a significant market opportunity.

How DESC ISR Maps to ISO 27001:2022

One of the most common questions we hear is: “We are already ISO 27001 certified — do we automatically comply with DESC ISR?”

The answer is that ISO 27001 provides an excellent foundation, but the two frameworks are complementary rather than identical. Both are risk-based management system frameworks requiring governance commitment, risk assessment, documented controls, internal audit, and continual improvement.

The ISR’s thirteen domains map directly and closely to ISO 27001:2022 Annex A controls. For example:

  1. ISR Domain 5 (Access Control) aligns with Annex A controls 5.15–5.18.
  2. ISR Domain 4 (Incident and Problem Management) aligns with Annex A controls 5.24–5.28.
  3. ISR Domain 13 (Cloud Security) aligns with Annex A controls 5.19–5.23.

Where ISO 27001 provides a principle-based management system, DESC ISR adds Dubai-specific prescriptive requirements, reporting obligations to DESC, and locally issued policy mandates that go beyond what ISO 27001 alone covers.

Organizations already holding ISO 27001 certification typically need a targeted gap analysis and focused remediation to bridge the two, making dual compliance an efficient, high-value goal. Together, the two frameworks deliver international certification credibility and local regulatory standing in a single, integrated security programme.

How MAST Consulting Can Help

Achieving DESC ISR compliance and ISO 27001:2022 certification is not simply a documentation exercise — it requires deep regulatory knowledge, structured methodology, and experienced professionals who understand both the technical and governance dimensions of information security. MAST Consulting brings all three. Our team of certified ISO 27001 Lead Implementers, Lead Auditors, CISAs, and information security specialists work as an extension of your team, guiding your organization from initial assessment through to sustained compliance. Here is how we do it:

DESC ISR & ISO 27001 Gap Assessment

MAST Consulting conducts a comprehensive gap assessment benchmarked simultaneously against all thirteen DESC ISR v3.1 domains and ISO 27001:2022 Annex A controls. We review your existing policies, procedures, technical controls, governance structures, and documentation against both frameworks, producing a detailed gap register with RAG status.

ISMS Design and Implementation

MAST Consulting designs and implements a management system that satisfies both DESC ISR and ISO 27001:2022 requirements within a single, integrated programme. We define the ISMS scope and boundaries, establish governance structures, assign roles and responsibilities, and build the processes and controls needed to operate a compliant and effective information security programme. Our approach eliminates the duplication of effort that comes from treating DESC ISR and ISO 27001 as separate workstreams, delivering dual compliance efficiently and cost-effectively.

Policy and Documentation Development

MAST Consulting develops the full suite of mandatory documentation: Information Security Policy, topic-specific policies covering access control, cryptography, incident management, and supplier security, SOPs, work instructions, and the Monitoring, Measurement, Analysis and Evaluation (MMAE) Matrix.

Risk Assessment and Treatment

MAST Consulting facilitates structured risk workshops with your asset owners, process owners, and department heads, guiding your teams through the identification, classification, and scoring of information security risks across your organization.

Internal Audit and Compliance Monitoring

MAST Consulting conducts rigorous internal audits covering all ISO 27001:2022 clauses and all thirteen DESC ISR domains, providing your organization with an independent, evidence-based view of its compliance status.

DESC ISR Compliance Assessment Support

MAST Consulting prepares your organization thoroughly — reviewing all evidence, conducting pre-assessment walkthroughs with department heads, briefing stakeholders on what to expect, and standing alongside your team throughout the assessment.

ISO 27001 Certification Audit Support

For organizations pursuing ISO 27001:2022 certification with an accredited Certification Body, MAST Consulting provides end-to-end support through Stage 1 and Stage 2 audits.

Ongoing Compliance and Retained Advisory

The DESC ISR evolves, the threat landscape changes, and your organization grows — your ISMS must grow with it. MAST Consulting offers retained advisory services to keep your compliance programme current and effective.

The MAST Consulting Difference

What sets MAST Consulting apart is not just our technical expertise  it is our commitment to making compliance practical, sustainable, and valuable for your organisation. We do not deliver generic frameworks and walk away. We build compliance programmes that your teams understand, own, and can operate independently. We combine the rigour of internationally recognized methodologies with the pragmatism of practitioners who have sat on both sides of the audit table. Our clients across government, financial services, technology, and critical infrastructure in the UAE trust us to guide them through complex regulatory landscapes and to stand with them when it matters most.

Contact MAST Consulting today for a complimentary DESC ISR readiness consultation. Let us show you exactly where you stand and the most efficient path to where you need to be.

Contact Us for More details