Cyber governance in Dubai: DESC ISR and the UAE IA Standards
May 2026 · 6 min read
Dubai has built one of the region's most structured approaches to information security governance. For entities serving the Dubai government — and the companies that supply them — the Dubai Electronic Security Center's Information Security Regulation (ISR) is the reference point.
The role of DESC
DESC was established to protect Dubai's information assets and elevate the emirate's cyber resilience. Its ISR sets information security controls that Dubai government bodies are expected to adopt, with assurance activities to confirm compliance.
Suppliers and partners frequently inherit these expectations contractually, making ISR-awareness a commercial requirement, not just a public-sector one.
Aligning with national standards
At the federal level, the UAE Information Assurance Standards provide a national baseline for entities linked to critical information infrastructure. Dubai's regulation operates within that broader context, so well-run programs treat the two as complementary layers.
The practical implication: a control library that maps both ISR and UAE IA lets a Dubai entity report once and satisfy multiple stakeholders.
Governance first
As with KSA's ECC, the emphasis is on governance: clear ownership, documented policies, risk management, and oversight of third parties. Technology controls follow from that structure rather than substituting for it.
Entities should validate current ISR requirements with DESC, as versions and scope are periodically updated.
This article is general guidance, not legal advice. Regulations evolve — confirm current requirements with the relevant authority (NCA / SDAIA in KSA; DESC / the UAE Data Office in the UAE). Questions? info@grclens.net.
Keep reading
Cyber governance in the Gulf: how KSA and the UAE set the pace
A regional map of the regulators and frameworks shaping cybersecurity governance across Saudi Arabia and the UAE — and what they have in common.
Security assurance in Saudi Arabia: making NCA-ECC stick
Implementing the Essential Cybersecurity Controls is only half the job. Sustaining assurance — proving controls keep working — is where programs succeed or fail.
Data protection across the Gulf: KSA PDPL and the UAE compared
Saudi Arabia's PDPL and the UAE's federal data protection law share DNA with global privacy regimes — but the details differ. A side-by-side orientation.