HomeFrameworksNational Cyber & Cloud SchemesDESC

Framework  National Cyber & Cloud Schemes

DESC

The Dubai Electronic Security Center (DESC) is the Dubai government's cybersecurity authority.

Two DESC instruments matter for compliance: the Information Security Regulation (ISR), a control standard mandatory for Dubai government and semi-government entities and their key suppliers (version 3 added cloud, IoT, and supply chain controls and aligns with ISO/IEC 27001 and NIST CSF), and the Cloud Service Provider Security Standard, which any cloud provider must be certified against before offering cloud services to Dubai government entities.

The CSP Security Standard layers DESC's own requirements on top of ISO/IEC 27001, 27002, and 27017 and the CSA STAR Level 2 model, and adds Dubai-specific requirements on data residency, incident reporting to DESC, and regulatory access.

In writing, a government entity under the ISR needs an information security policy set approved by senior management, a risk assessment, asset classification, and documented controls for each ISR domain, plus annual compliance reporting to DESC.

A cloud provider seeking CSP certification needs an ISO/IEC 27001-style management system scoped to the Dubai services, a control matrix covering the DESC additions, data location and segregation evidence, incident notification procedures to DESC, and the certification body's audit reports.

Certification follows the ISO/IEC 27001 pattern: initial audit, annual surveillance, recertification every three years.

AI-compiled
Share
Sponsored
DESC
help
Consultants  Assessors  Quotes
Matched3 quotesread by a human
The Shortlist is Yoursfrom this directory
Comply the Modern WayFind help with DESC
01
Verified listings first
Unverified ones follow, labeled
02
Published prices where they exist
“Quote only” where we confirmed it, “Not published” where we have not
03
Up to three quotes, one form
Firms don’t see you until you choose
House ad. This slot is open to firms listed for this page. Get help Advertise here

Who has to comply

ISR: Dubai government and semi-government entities and, through contracts, their key suppliers. CSP Security Standard: any cloud service provider, local or foreign, that wishes to sell cloud services to Dubai government or semi-government entities. Private companies elsewhere in the UAE may adopt DESC standards voluntarily or face them via customer contracts.

What the assessor asks to see

Information security policy set and management approval; risk assessment and treatment; asset inventory and classification; control implementation evidence for each ISR domain or CSP requirement; data residency and segregation evidence for Dubai government data; access management and privileged access records; logging and monitoring; incident response procedures and notification records to DESC; business continuity and disaster recovery tests; supplier and subcontractor management; internal audit and management review; certification body audit reports and corrective actions.

Assessors

Who assesses DESC

For CSP certification, certification bodies approved by DESC that operate under the ISO/IEC 27001 certification scheme; DESC itself reviews ISR compliance reporting and can audit government entities. Verify the current list of DESC-approved certification bodies on the DESC certifications page.

Accredited by DESC approves certification bodies for its schemes; those bodies typically also hold accreditation from a national accreditation body for ISO/IEC 27001 (for example the Emirates International Accreditation Centre or UKAS).

Public register of assessors: https://www.desc.gov.ae/regulations/certifications/

No firm has claimed a DESC assessor listing yet. Claim yours →

Consultants

Who helps with DESC

UAE-based consultancies and the regional arms of global firms offer ISR gap assessments and CSP certification readiness; several certification bodies operate in Dubai. Readiness for CSP certification typically takes three to nine months for a provider that already holds ISO/IEC 27001.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

No firm has claimed a DESC consultant listing yet. Claim yours →

Software

Tools for DESC

Tools that name this framework in their own material.

No firm has claimed a DESC tool listing yet. Claim yours →

Related reading

  1. DESC CSP security standard certificationExplains the separate cloud provider standard a CSP must hold before serving Dubai government entities, and how it is certified.Amazon Web Services

Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.

Need a hand implementing it?

Find a Consultant for DESC

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

Not sure where to start?

Get Help with DESC

Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

corrections@policyandcompliance.com
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

ads@policyandcompliance.com
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.