Frameworks · Middle East
DESC IoT Security Standard
The Internet of Things (IoT) Security Standard from the Dubai Electronic Security Center sets mandatory and recommended controls for securing IoT deployments. Compliance is mandatory for Dubai Government and semi-government entities.
Who it applies to
It applies to Dubai Government and semi-government entities that deploy IoT devices and platforms, and to the suppliers and integrators that provide them.
Main requirements
Device security
Devices need identity, authentication, firmware integrity and secure configuration.
Communications
Traffic between devices, gateways and platforms uses encryption, network segmentation and secure protocols.
Platform & data
The IoT platform and the data it collects are secured, including how long the data is retained.
Lifecycle
Controls cover procurement, onboarding, patching, monitoring and decommissioning.
How xmodo supports it
- 1
Mandatory and recommended controls are tracked separately. The compliance rate uses the mandatory set, and the recommended set is reported beside it.
- 2
IoT devices and platforms are recorded in the asset register, which determines the controls that apply.
- 3
Requirements map to DESC ISR 3.1 and ISO/IEC 27001, so work in your existing programme counts towards this standard.
Related frameworks
DESC IoT Security Standard shares requirements with the frameworks below. Controls you already run for any of them count towards DESC IoT Security Standard as well.
Frequently asked questions
Do the recommended controls count?
xmodo tracks and reports them separately from the mandatory set. The compliance figure you report to DESC is therefore the one DESC asks for.