xmodoxmodo

Frameworks · Middle East

DESC ISR 3.1

The Dubai Government Information Security Regulation (ISR) Version 3.1 is issued by the Dubai Electronic Security Center. It is the mandatory information security regulation for Dubai Government entities. It has thirteen domains, each addressing Governance, Operation or Assurance. Version 3.1 aligns the regulation more closely with ISO/IEC 27001:2022.

Who it applies to

Dubai Government entities, and anyone who handles Dubai Government information within an entity's scope, including employees, contractors, consultants and suppliers. Each entity carries out an applicability review to decide which domains and controls apply to it.

Main requirements

Governance domains

How information security is structured and managed, including policy, roles, risk and compliance reporting to DESC.

Operation domains

Technical and non-technical controls that the entity selects based on its risk assessment.

Assurance domains

Audit, review and testing that show the implemented controls work as intended.

Applicability review

A documented scope of domains and controls, reviewed again when the entity's systems or services change.

How xmodo supports it

  • 1

    All thirteen domains are set up with each of their controls. Each control is tagged with its Governance, Operation or Assurance class, an owner and an evidence requirement.

  • 2

    The applicability review is recorded as framework scope, with a justification for each excluded control, so the assessor can see the reasoning behind it.

  • 3

    Mapping from ISO/IEC 27001:2022 shows how much of Version 3.1 a certified ISMS already meets.

  • 4

    Vulnerability assessment, penetration testing and audit reports have expiry dates. xmodo raises a task when a report lapses, before it becomes a finding.

  • 5

    The framework details record the legal basis: Executive Council Resolution No. 13 of 2012, Dubai Law No. 11 of 2014, and Law No. 15 of 2024 concerning the Dubai Electronic Security Centre.

Related frameworks

DESC ISR 3.1 shares requirements with the frameworks below. Controls you already run for any of them count towards DESC ISR 3.1 as well.

Frequently asked questions

Which version of the ISR does xmodo model?

Version 3.1, the current published edition. Some secondary summaries refer to 3.0 and 3.1 together as "ISR v3". The instrument says 3.1, and xmodo records the version as a field on the framework.

How many domains are there?

There are thirteen. Each addresses one or more of the Governance, Operation and Assurance classes, and every domain is in the library with its controls.

Is DESC ISR the same as UAE IA?

No. DESC issues the ISR, which binds Dubai Government entities. The UAE Information Assurance Standard 2.1 is the national baseline issued by the UAE Cyber Security Council. Many Dubai entities are in scope for both, and mapping lets one control count for each.

Does an ISO/IEC 27001:2022 certificate reduce the work?

Yes, considerably. Version 3.1 was aligned more closely with ISO/IEC 27001:2022, so a certified ISMS covers a large share of the Operation domains. xmodo shows the exact share for your organisation. Most remaining gaps are DESC-specific governance and assurance documents.

See how xmodo works for your organisation

Get a demo on the frameworks that apply to you.

Get a demo