Dubai

Cyber governance in Dubai: DESC ISR and the UAE IA Standards

May 2026 · 6 min read

Dubai has built one of the region's most structured approaches to information security governance. For entities serving the Dubai government — and the companies that supply them — the Dubai Electronic Security Center's Information Security Regulation (ISR) is the reference point.

The role of DESC

DESC was established to protect Dubai's information assets and elevate the emirate's cyber resilience. Its ISR sets information security controls that Dubai government bodies are expected to adopt, with assurance activities to confirm compliance.

Suppliers and partners frequently inherit these expectations contractually, making ISR-awareness a commercial requirement, not just a public-sector one.

Aligning with national standards

At the federal level, the UAE Information Assurance Standards provide a national baseline for entities linked to critical information infrastructure. Dubai's regulation operates within that broader context, so well-run programs treat the two as complementary layers.

The practical implication: a control library that maps both ISR and UAE IA lets a Dubai entity report once and satisfy multiple stakeholders.

Governance first

As with KSA's ECC, the emphasis is on governance: clear ownership, documented policies, risk management, and oversight of third parties. Technology controls follow from that structure rather than substituting for it.

Entities should validate current ISR requirements with DESC, as versions and scope are periodically updated.

This article is general guidance, not legal advice. Regulations evolve — confirm current requirements with the relevant authority (NCA / SDAIA in KSA; DESC / the UAE Data Office in the UAE). Questions? info@grclens.net.