Blog Category

DESC ISR v3 in Dubai: What the Information Security Regulation Requires

What DESC's Information Security Regulation (ISR v3) requires, who is in scope, and why it matters commercially in Dubai.

Any organisation that works with the Dubai Government — as an entity, a partner or a supplier — will sooner or later meet the Information Security Regulation (ISR) issued by the Dubai Electronic Security Center (DESC). The current version, ISR v3, raised the bar, and compliance is mandatory for those in scope. This guide explains what ISR v3 is and who it affects.

What DESC and the ISR are

The Dubai Electronic Security Center is the government body responsible for cybersecurity in the Emirate of Dubai, and the Information Security Regulation is its mandatory standard. DESC released ISR Version 3.0, building on the earlier v2, to reflect a tougher threat landscape and modern technology use. It applies to Dubai government entities and, importantly, to the contractors, partners and suppliers that connect to or handle their information. ITSEC's DESC cybersecurity practice helps organisations meet it.

What ISR v3 covers

ISR v3 is organised across a set of security domains spanning governance, asset management, access control, cryptography, physical security, secure development, supplier risk, incident management, business continuity, cloud security and security operations. The emphasis is on a managed, evidenced programme — not a one-time checklist. For organisations already aligned to ISO/IEC 27001, much of the groundwork carries over, but ISR adds Dubai-specific expectations that have to be met on their own terms.

Why it matters commercially

ISR compliance is often a condition of doing business with the Dubai Government: non-compliance can mean exclusion from procurement and contract termination. For suppliers, treating ISR as a sales enabler rather than a burden is the right framing — being demonstrably compliant opens doors that closed ones. Testing the controls with independent penetration testing and VAPT is part of proving that compliance is real.

Talk to ITSEC

If your organisation works with the Dubai Government, ISR v3 is not optional. ITSEC runs ISR gap assessments, remediation and the testing that evidences compliance. Visit our DESC cybersecurity page to get started.

ITSEC UAE cybersecurity coverage map

Ready to Secure Your Digital Assets?

Get a comprehensive security assessment from our expert team. Protecting businesses since 2011.

Consult Cyber Experts
NDA Protected
24hr Response
Global Coverage
×

ITSEC Security Agent

AI-Powered • 24/7 Active

👋 Welcome to ITSEC – UAE's first AI-augmented cybersecurity firm.

I'm your AI Security Agent. How can I assist you with your cybersecurity needs today?
ITSEC AI
Secured by ITSEC AI • ISO 27001 Certified