Frameworks · Middle East
DESC CSP Security Standard
The Cloud Service Provider (CSP) Security Standard from the Dubai Electronic Security Center sets mandatory requirements for cloud providers serving Dubai Government and semi-government entities. It also gives guidance to the entities that buy from them. It draws on ISO/IEC 27001, 27002 and 27017, the ISR and the Cloud Security Alliance Cloud Controls Matrix. Compliance is verified through DESC certification.
Who it applies to
Infrastructure, platform and software-as-a-service providers offering cloud services to Dubai Government and semi-government entities. The government customers of those providers receive guidance under the same standard.
Main requirements
Security management system
An information security management system aligned to ISO/IEC 27001, with the cloud provider's scope defined.
Cloud-specific controls
Tenant isolation, data location, virtualisation security, service termination and data return, drawn from ISO/IEC 27017 and the CSA Cloud Controls Matrix.
Government-customer requirements
Contract, access, incident notification and audit provisions that the Dubai Government customer relies on.
Certification evidence
Existing ISO/IEC 27001 certification and CSA STAR Level 2 are acknowledged for the parts of the standard they cover.
How xmodo supports it
- 1
The standard is set up with each of its requirements and mapped to ISO/IEC 27001, so a certified ISMS is credited before the DESC audit begins.
- 2
Cloud-specific controls have their own evidence requirements, stored with their validity tracked.
- 3
The DESC certification audit runs as an engagement, with scoped evidence requests sent through the auditor portal.
- 4
Dubai Government customers can run the standard's customer guidance as a checklist inside their ISR programme. Provider assurance and the entity's own compliance are then kept on one record.
Related frameworks
DESC CSP Security Standard shares requirements with the frameworks below. Controls you already run for any of them count towards DESC CSP Security Standard as well.
Frequently asked questions
Is this the "DESC Cloud Security Standard"?
The official title is the Cloud Service Provider (CSP) Security Standard. xmodo uses the official title and also recognises the shorter name.
We hold ISO/IEC 27001. Does that count?
Yes. DESC acknowledges a current ISO/IEC 27001 certification for the part of the standard it covers, so that part does not need a second audit. xmodo shows which controls remain.
Does a SaaS vendor need this to sell to Dubai Government?
Compliance with the standard is mandatory for cloud service providers offering services to Dubai Government and semi-government entities. If you deliver your product as a cloud service to such an entity, plan for certification.