Framework B.12 · Dubai Electronic Security Center

DESC ISR - Dubai Information Security Regulation and penetration testing.

The Dubai Electronic Security Center (DESC) Information Security Regulation (ISR) requires Dubai government entities - and many of their suppliers - to run a managed security programme with regular technical assessment. CyberFortify's web application and network testing produces evidence mapped to the ISR controls.

Maintainer: Dubai Electronic Security Center Scope: Dubai government entities & suppliers Driver: Information Security Regulation (ISR)
ISR
The regulation
Gov +
Suppliers in scope
Testing
Technical assessment
Mapped
Report to ISR
DESC ISR: Managed Security Programme · Regular Technical Assessment · VAPT · Findings Tracked to Closure · Applies to Government & Suppliers · Report Mapped to ISR DESC ISR: Managed Security Programme · Regular Technical Assessment · VAPT · Findings Tracked to Closure · Applies to Government & Suppliers · Report Mapped to ISR
// Executive summary

The DESC Information Security Regulation (ISR) requires Dubai government entities and many of their suppliers to operate a managed information security programme that includes regular technical assessment of systems - in practice, periodic vulnerability assessment and penetration testing with findings tracked to closure and reported against the ISR controls. CyberFortify maps every engagement to the ISR, remediates and retests.

// 01 What the DESC ISR is

// DefinitionDESC ISR

The Information Security Regulation issued by the Dubai Electronic Security Center - the emirate body responsible for cyber security across Dubai. The ISR sets the information security controls that Dubai government entities, and organisations serving them, must implement.

It frames security as a managed programme (an ISMS-style approach) with regular technical assessment of systems among its controls - which is where periodic vulnerability assessment and penetration testing fit.

The ISR is the standard most Dubai buyers ask about, and it reaches beyond government into the supply chain. For the practitioner view, see our DESC penetration testing requirements guide and the Dubai services overview.

// 02 The testing expectation in practice

01Programme

Managed security programme

An ISMS-style programme with defined controls - testing sits within it, not as a one-off.

02Assessment

Regular technical assessment

Periodic vulnerability assessment and penetration testing of in-scope systems. Our manual-led testing satisfies the intent.

03Closure

Findings tracked to closure

Findings must be remediated and closed - our retest is included to evidence it.

04Mapping

Reported against ISR

The report maps findings and coverage to the ISR controls a Dubai assessor checks.

// 03 Who is in scope - including suppliers

The ISR applies to Dubai government entities and, crucially, to many of the private-sector organisations that serve them. Suppliers and service providers handling Dubai government data or systems are frequently required to demonstrate ISR compliance as a condition of doing business - so the regulation reaches well beyond government into the supply chain. That is why a wide range of Dubai organisations, not just public bodies, need to be able to show ISR-aligned security testing. Financial firms in the DIFC additionally answer to the DFSA, personal data falls under the UAE PDPL, and federal government and critical sectors follow the UAE IA standard.

The ISR is not only a government obligation - it flows down to suppliers. A Dubai vendor that can show an ISR-mapped test wins and keeps government work; one that cannot, stalls. We produce exactly that evidence.

CyberFortify DESC-facing reporting

// 04 Running the programme

Because the ISR frames testing as part of a managed programme, the discipline is to run it on a regular cadence tied to your risk and to any assessment or renewal dates, rather than as a one-off. Book ahead of any DESC assessment or contract milestone so findings can be remediated and retested before you need to show closure. A typical engagement is one to three weeks of active testing (about four to six weeks total). Map it alongside the wider region with the GCC compliance calendar, and compare providers with the best pentest companies in the UAE.

// 05 Frequently asked questions

Does the DESC ISR require penetration testing?

The ISR requires in-scope organisations to run a managed information security programme that includes regular technical assessment of systems - in practice periodic VAPT with findings tracked to closure and reported against ISR controls. It's framed as security testing within an ISMS rather than a standalone item, but penetration testing is the recognised way to satisfy the technical assessment expectation.

Who must comply?

Dubai government entities and, importantly, many private-sector organisations that serve them. Suppliers handling Dubai government data or systems are frequently required to demonstrate ISR compliance as a condition of doing business, so the regulation reaches into the supply chain - a wide range of Dubai organisations need ISR-aligned testing.

How does the ISR relate to UAE IA and the PDPL?

They're distinct regimes that can apply together. The DESC ISR is Dubai's emirate-level regulation; the UAE IA standard (historically NESA) is a federal standard for government and critical sectors; the UAE PDPL governs personal data federally; and the DIFC has its own data-protection regime. A Dubai organisation may need to satisfy several, so engagements map evidence to those that apply.

How does CyberFortify produce DESC-aligned evidence?

We scope to the in-scope systems and deliver a report mapping findings and coverage to the ISR controls, so a Dubai assessor or the entity's compliance team sees the technical assessment satisfied. Findings are remediated and retested to show closure, and reporting is framed for the ISR. For suppliers, this provides the evidence to demonstrate compliance to the government entity they serve.

Ready for a DESC ISR-aligned engagement?

Schedule a 30-minute scoping call. We'll scope your in-scope systems, map the report to the ISR controls, and give you the evidence to satisfy DESC or the government entity you serve.

Schedule scoping call → Back to CyberFortify home →