Frameworks · Middle East
DESC DC Security Standard
The Data Center (DC) Security Standard is a Dubai Electronic Security Center standard aligned with the Dubai Cyber Security Strategy. It sets security requirements for data centres that serve Dubai Government and semi-government entities. DESC certification verifies compliance with it, separately from the cloud-provider standard.
Who it applies to
It applies to data-centre operators that host Dubai Government and semi-government workloads, and to the government entities that rely on them.
Main requirements
Physical & environmental
Controls cover the site, perimeter, access, power, cooling and fire protection.
Operations
The operator manages change, capacity, monitoring and maintenance of the facility.
Access & personnel
Access for visitors, contractors and staff is granted, recorded and reviewed.
Continuity
Resilience, redundancy and recovery are tested on a regular schedule, with evidence kept.
How xmodo supports it
- 1
The standard is set up with each of its requirements. Facility evidence, including physical access logs and test reports, carries expiry dates.
- 2
Requirements map to ISO/IEC 27001 physical controls, and to the DESC CSP standard for operators that are also cloud providers.
- 3
The DESC certification audit runs as an engagement through the auditor portal.
Related frameworks
DESC DC Security Standard shares requirements with the frameworks below. Controls you already run for any of them count towards DESC DC Security Standard as well.
Frequently asked questions
Is this the same as the DESC cloud standard?
No. The CSP Security Standard covers cloud service providers, and the DC Security Standard covers the data-centre facility. An operator that is both follows both standards, and implements shared controls once.