Dubai ISR Compliance

ISR intends to ensure appropriate level of Confidentiality, Integrity and Availability for information handled within Dubai Government Entities

What is Dubai ISR

The Dubai Information Security Regulation (ISR) is a comprehensive and mandatory regulation that provides a framework for information security management within Dubai.

 

Developed and enforced by the Dubai Electronic Security Center (DESC), the ISR aims to ensure a high level of confidentiality, integrity, and availability for information handled by government entities and critical service providers.

 

ISR outlines a set of essential security controls and requirements designed to minimize information security risks, prevent incidents, and ensure the continuity of critical business processes in Dubai's digital environment.

 

The latest version of the regulation is ISR V3.0, building upon previous versions to address the evolving threat landscape.

Key Domains of ISR

 

The Dubai Information Security Regulation (ISR) is structured into thirteen domains, categorized under three main classes: Governance, Operation, and Assurance. This provides a comprehensive framework covering various aspects of information security:

 

  • Governance Domains: Set high-level requirements for structuring and managing information security, including aspects like Information Security Strategy, Policy, Organization, and Risk Management.
  • Operation Domains: Detail technical and non-technical controls for implementing security measures in day-to-day operations, covering areas like Asset Management, Access Control, Cryptography, Physical Security, and Operations Security.
  • Assurance Domains: Focus on activities that provide confidence in the effectiveness of implemented controls, including Compliance, Audit, Incident Management, and Business Continuity Management.

 

Each domain contains specific objectives and detailed controls that organizations must implement based on their applicability and risk assessment.

Who Should Comply With Dubai's ISR?

Compliance with the Dubai ISR is mandatory for specific types of organizations operating within the Emirate. This includes:

 

  • All Dubai Government Entities (DGEs): Ministries, departments, authorities, and all other government bodies in Dubai are required to fully comply with the ISR.

  • Entities Identified as Critical Information Infrastructure (CII) Operators: Organizations operating in sectors deemed critical to Dubai's functioning (such as energy, water, transport, telecommunications, finance, and health) are also mandated to comply with the ISR to protect the essential services they provide.

 

Furthermore, organizations providing services to Dubai Government entities or CII operators may also be required through contractual agreements to demonstrate compliance with relevant aspects of the ISR.

Need more details? Review the Dubai's ISR:

Review Dubai's ISR

If you cannot find what you want, please visit the DESC website