xmodoxmodo

Frameworks · Middle East

DESC IoT Security Standard

The Internet of Things (IoT) Security Standard from the Dubai Electronic Security Center sets mandatory and recommended controls for securing IoT deployments. Compliance is mandatory for Dubai Government and semi-government entities.

Who it applies to

It applies to Dubai Government and semi-government entities that deploy IoT devices and platforms, and to the suppliers and integrators that provide them.

Main requirements

Device security

Devices need identity, authentication, firmware integrity and secure configuration.

Communications

Traffic between devices, gateways and platforms uses encryption, network segmentation and secure protocols.

Platform & data

The IoT platform and the data it collects are secured, including how long the data is retained.

Lifecycle

Controls cover procurement, onboarding, patching, monitoring and decommissioning.

How xmodo supports it

  • 1

    Mandatory and recommended controls are tracked separately. The compliance rate uses the mandatory set, and the recommended set is reported beside it.

  • 2

    IoT devices and platforms are recorded in the asset register, which determines the controls that apply.

  • 3

    Requirements map to DESC ISR 3.1 and ISO/IEC 27001, so work in your existing programme counts towards this standard.

Related frameworks

DESC IoT Security Standard shares requirements with the frameworks below. Controls you already run for any of them count towards DESC IoT Security Standard as well.

Frequently asked questions

Do the recommended controls count?

xmodo tracks and reports them separately from the mandatory set. The compliance figure you report to DESC is therefore the one DESC asks for.

See how xmodo works for your organisation

Get a demo on the frameworks that apply to you.

Get a demo