Strengthen Information Security and Achieve DESC ISR v3.1 Compliance
Dubai’s rapid digital transformation requires government entities to maintain strong information security governance, cybersecurity controls and operational resilience.
The Dubai Electronic Security Center (DESC) Information Security Regulation (ISR) establishes minimum information security requirements for Dubai Government Entities to protect government information and maintain the confidentiality, integrity and availability of information and critical business processes. The regulation applies to government information regardless of its format and extends to employees, consultants, contractors and other parties interacting with government information and systems.
MAST Consulting helps organizations assess, implement and maintain compliance with DESC ISR Version 3, providing end-to-end support from initial gap assessment through control implementation, audit readiness and continual compliance improvement.
What is DESC ISR? (Dubai Electronic Security Center (DESC) Information Security Regulation (ISR))
The Information Security Regulation (ISR) is an information security framework maintained by the Dubai Electronic Security Center. It provides Dubai Government Entities with minimum requirements for establishing and maintaining appropriate information security controls.
DESC describes ISR as a technology-neutral and risk-based framework. Organizations are expected to conduct an applicability review to determine relevant domains and controls and implement appropriate measures considering their information security risks.
The regulation is structured across 13 information security domains, covering three broad control classes:
Governance – requirements for establishing, governing and managing information security.
Operation – technical and non-technical controls implemented based on organizational risks and requirements.
Assurance – mechanisms for verifying that implemented security controls are operating effectively.
Our DESC ISR Consulting Services
MAST Consulting provides a structured approach to help organizations understand their current compliance position, address identified gaps and establish sustainable information security practices.
DESC ISR Gap Assessment
We conduct a detailed assessment of existing policies, processes, technologies and security controls against applicable DESC ISR requirements.
Our assessment provides management with a clear view of:
DESC ISR Requirement → Existing Control → Compliance Status → Identified Gap → Risk → Recommended Action
The assessment forms the foundation for developing a prioritized compliance roadmap.
Applicability & Scope Assessment
Not every control necessarily requires identical implementation across every organization. DESC requires Dubai Government Entities to perform an applicability review of ISR domains and controls.
MAST Consulting supports organizations in identifying applicable requirements based on their business operations, information assets, technology environment, third parties and information security risks.
Information Security Risk Assessment
We perform structured information security risk assessments to identify threats, vulnerabilities and potential impacts affecting critical information assets and services.
The assessment supports risk-based control implementation and development of an appropriate Risk Treatment Plan.
Policies, Procedures & Governance Framework
MAST Consulting helps organizations establish and enhance the governance documentation required to support ISR implementation.
This may include information security policies, risk management procedures, asset management requirements, access-control procedures, incident management, supplier security, vulnerability management, secure development, business continuity, information classification, acceptable use and supporting standards and operating procedures.
Technical & Operational Control Assessment
Our consultants work with IT and cybersecurity teams to assess the implementation and effectiveness of technical security controls.
Depending on the environment, this can include identity and access management, privileged access, endpoint protection, network security, logging and monitoring, vulnerability management, patch management, backup, encryption, configuration management and other relevant cybersecurity controls.
Third-Party & Supplier Security
Third-party relationships can introduce significant information security risks.
MAST Consulting helps organizations establish supplier security requirements, conduct third-party risk assessments, review contractual security obligations and establish mechanisms for monitoring supplier compliance.
Incident Management & Cyber Resilience
We assess and strengthen the organization’s capability to identify, report, respond to and recover from information security incidents.
This includes reviewing incident response processes, escalation mechanisms, responsibilities, incident records and lessons-learned processes.
Business Continuity & Disaster Recovery
We support the integration of information security requirements into business continuity and disaster recovery arrangements to help maintain critical services during disruptive events.
Why MAST Consulting?
MAST Consulting brings together expertise in information security governance, cybersecurity, risk management, regulatory compliance and international standards.
Our consultants take a practical implementation-focused approach, working alongside management, information security, IT, risk, HR, procurement, legal, business continuity and other stakeholders to embed security requirements into day-to-day operations.
Where organizations maintain multiple compliance programs, our approach can also help align DESC ISR requirements with frameworks such as ISO/IEC 27001, ISO 22301, ISO 20000-1 and other applicable regulatory requirements, reducing duplication and creating a more integrated governance environment.
Talk to Our DESC ISR Experts
Fill out the form, and one of our experts will get in touch with you shortly.