Frameworks · Middle East
DESC ISR 3.1
The Dubai Government Information Security Regulation (ISR) Version 3.1 is issued by the Dubai Electronic Security Center. It is the mandatory information security regulation for Dubai Government entities. It has thirteen domains, each addressing Governance, Operation or Assurance. Version 3.1 aligns the regulation more closely with ISO/IEC 27001:2022.
Who it applies to
Dubai Government entities, and anyone who handles Dubai Government information within an entity's scope, including employees, contractors, consultants and suppliers. Each entity carries out an applicability review to decide which domains and controls apply to it.
Main requirements
Governance domains
How information security is structured and managed, including policy, roles, risk and compliance reporting to DESC.
Operation domains
Technical and non-technical controls that the entity selects based on its risk assessment.
Assurance domains
Audit, review and testing that show the implemented controls work as intended.
Applicability review
A documented scope of domains and controls, reviewed again when the entity's systems or services change.
How xmodo supports it
- 1
All thirteen domains are set up with each of their controls. Each control is tagged with its Governance, Operation or Assurance class, an owner and an evidence requirement.
- 2
The applicability review is recorded as framework scope, with a justification for each excluded control, so the assessor can see the reasoning behind it.
- 3
Mapping from ISO/IEC 27001:2022 shows how much of Version 3.1 a certified ISMS already meets.
- 4
Vulnerability assessment, penetration testing and audit reports have expiry dates. xmodo raises a task when a report lapses, before it becomes a finding.
- 5
The framework details record the legal basis: Executive Council Resolution No. 13 of 2012, Dubai Law No. 11 of 2014, and Law No. 15 of 2024 concerning the Dubai Electronic Security Centre.
Related frameworks
DESC ISR 3.1 shares requirements with the frameworks below. Controls you already run for any of them count towards DESC ISR 3.1 as well.
Frequently asked questions
Which version of the ISR does xmodo model?
Version 3.1, the current published edition. Some secondary summaries refer to 3.0 and 3.1 together as "ISR v3". The instrument says 3.1, and xmodo records the version as a field on the framework.
How many domains are there?
There are thirteen. Each addresses one or more of the Governance, Operation and Assurance classes, and every domain is in the library with its controls.
Is DESC ISR the same as UAE IA?
No. DESC issues the ISR, which binds Dubai Government entities. The UAE Information Assurance Standard 2.1 is the national baseline issued by the UAE Cyber Security Council. Many Dubai entities are in scope for both, and mapping lets one control count for each.
Does an ISO/IEC 27001:2022 certificate reduce the work?
Yes, considerably. Version 3.1 was aligned more closely with ISO/IEC 27001:2022, so a certified ISMS covers a large share of the Operation domains. xmodo shows the exact share for your organisation. Most remaining gaps are DESC-specific governance and assurance documents.