DESC ISR Compliance Consulting Services

Strengthen Information Security and Achieve DESC ISR v3.1 Compliance

Dubai’s rapid digital transformation requires government entities to maintain strong information security governance, cybersecurity controls and operational resilience.

The Dubai Electronic Security Center (DESC) Information Security Regulation (ISR) establishes minimum information security requirements for Dubai Government Entities to protect government information and maintain the confidentiality, integrity and availability of information and critical business processes. The regulation applies to government information regardless of its format and extends to employees, consultants, contractors and other parties interacting with government information and systems.

MAST Consulting helps organizations assess, implement and maintain compliance with DESC ISR Version 3, providing end-to-end support from initial gap assessment through control implementation, audit readiness and continual compliance improvement.

What is DESC ISR? (Dubai Electronic Security Center (DESC) Information Security Regulation (ISR))

The Information Security Regulation (ISR) is an information security framework maintained by the Dubai Electronic Security Center. It provides Dubai Government Entities with minimum requirements for establishing and maintaining appropriate information security controls.

DESC describes ISR as a technology-neutral and risk-based framework. Organizations are expected to conduct an applicability review to determine relevant domains and controls and implement appropriate measures considering their information security risks.

The regulation is structured across 13 information security domains, covering three broad control classes:

Governance – requirements for establishing, governing and managing information security.

Operation – technical and non-technical controls implemented based on organizational risks and requirements.

Assurance – mechanisms for verifying that implemented security controls are operating effectively.

Our DESC ISR Consulting Services

MAST Consulting provides a structured approach to help organizations understand their current compliance position, address identified gaps and establish sustainable information security practices.

DESC ISR Gap Assessment

We conduct a detailed assessment of existing policies, processes, technologies and security controls against applicable DESC ISR requirements.

Our assessment provides management with a clear view of:

DESC ISR Requirement → Existing Control → Compliance Status → Identified Gap → Risk → Recommended Action

The assessment forms the foundation for developing a prioritized compliance roadmap.

Applicability & Scope Assessment

Not every control necessarily requires identical implementation across every organization. DESC requires Dubai Government Entities to perform an applicability review of ISR domains and controls.

MAST Consulting supports organizations in identifying applicable requirements based on their business operations, information assets, technology environment, third parties and information security risks.

Information Security Risk Assessment

We perform structured information security risk assessments to identify threats, vulnerabilities and potential impacts affecting critical information assets and services.

The assessment supports risk-based control implementation and development of an appropriate Risk Treatment Plan.

Policies, Procedures & Governance Framework

MAST Consulting helps organizations establish and enhance the governance documentation required to support ISR implementation.

This may include information security policies, risk management procedures, asset management requirements, access-control procedures, incident management, supplier security, vulnerability management, secure development, business continuity, information classification, acceptable use and supporting standards and operating procedures.

Technical & Operational Control Assessment

Our consultants work with IT and cybersecurity teams to assess the implementation and effectiveness of technical security controls.

Depending on the environment, this can include identity and access management, privileged access, endpoint protection, network security, logging and monitoring, vulnerability management, patch management, backup, encryption, configuration management and other relevant cybersecurity controls.

Third-Party & Supplier Security

Third-party relationships can introduce significant information security risks.

MAST Consulting helps organizations establish supplier security requirements, conduct third-party risk assessments, review contractual security obligations and establish mechanisms for monitoring supplier compliance.

Incident Management & Cyber Resilience

We assess and strengthen the organization’s capability to identify, report, respond to and recover from information security incidents.

This includes reviewing incident response processes, escalation mechanisms, responsibilities, incident records and lessons-learned processes.

Business Continuity & Disaster Recovery

We support the integration of information security requirements into business continuity and disaster recovery arrangements to help maintain critical services during disruptive events.

Why MAST Consulting?

MAST Consulting brings together expertise in information security governance, cybersecurity, risk management, regulatory compliance and international standards.

Our consultants take a practical implementation-focused approach, working alongside management, information security, IT, risk, HR, procurement, legal, business continuity and other stakeholders to embed security requirements into day-to-day operations.

Where organizations maintain multiple compliance programs, our approach can also help align DESC ISR requirements with frameworks such as ISO/IEC 27001, ISO 22301, ISO 20000-1 and other applicable regulatory requirements, reducing duplication and creating a more integrated governance environment.

Get started with a DESC ISR Gap Assessment and understand your organization's current compliance position, key risks and priority actions.

Talk to Our DESC ISR Experts

    Fill out the form, and one of our experts will get in touch with you shortly.

    Frequently Asked Questions (FAQ)

    What is the latest version of DESC ISR?
    The currently published regulation on DESC's official website is Information Security Regulation – Version 3. DESC has also publicly discussed its 2026 roadmap toward Version 4. Organizations should monitor DESC's official publications for the formal release and transition requirements for any new version.
    Is DESC ISR mandatory?
    DESC states that the Information Security Regulation provides the minimum information security requirements applicable to Dubai Government Entities and government information.
    Does DESC ISR apply to third parties?
    The regulation's scope extends beyond government employees and includes parties such as consultants and contractors engaged with government entities, while its requirements apply to government information regardless of its medium. The exact obligations of a particular supplier should be determined based on scope, contractual requirements and applicable controls.
    Can MAST Consulting support the entire implementation?
    Yes. MAST Consulting can support the journey from gap assessment and risk assessment through documentation, control implementation, evidence collection, internal assessment, remediation and external-assessment readiness.
    Can DESC ISR be integrated with ISO 27001?
    Yes. There are overlapping information security governance and control areas, so organizations operating an ISO/IEC 27001 ISMS can use an integrated implementation approach while separately demonstrating compliance with applicable DESC ISR requirements.
    x

    Get Started with a Free 30mins Consultation

    Not sure where to begin? Our experts will assess your readiness and provide a step-by-step plan tailored to your business.

      Privacy Notice: Your information is safe with us. The details you provide in this form will be used solely to connect you with one of our consultants. We do not share your data with third parties, and all information will be handled in accordance with our privacy policy

      Email : info@mastcgroup.com
      Connect with us