Dubai DESC ISR Audit
DESC ISR readiness for Dubai government entities and sector-specific operators.
Full Dubai Electronic Security Centre Information Security Regulation audit — applicability mapping, control families across governance, asset, HR, access, operations, communications, acquisition, incident management and compliance. Sequenced for the DESC audit cycle and the Dubai Government Information Security Maturity model.
- DESC Information Security Regulation v1.0 (2017) and v2.0 (2023)
- Dubai Cyber Security Strategy
- Dubai Government Information Security Maturity model
- Smart Dubai / Digital Dubai security directives
- UAE Information Assurance Standards (overlay)
- ISO 27001:2022 (mapped)
- NIST CSF (mapped)
What is DESC ISR compliance?
The Dubai Electronic Security Center's Information Security Regulation (ISR) mandates security controls for Dubai government entities and their service partners. Macksofy assesses and implements DESC ISR controls for organizations operating with the Dubai government.
DESC ISR is leverage, not paperwork.
The Dubai Electronic Security Centre's Information Security Regulation (DESC ISR v1.0 in 2017, updated to v2.0 in 2023) is the mandatory baseline for Dubai government entities and a growing set of sector-specific operators. DESC operates a regular audit cycle that grades entities against the ISR control set and the broader Dubai Cyber Security Strategy maturity model. Macksofy's DESC ISR audit is run the way DESC examiners read it — control mapping, sampled evidence and a clean closure pack.
- Dubai government entities (departments, authorities, councils)
- Government-owned enterprises and free-zone authorities in Dubai
- Sector-specific operators designated by DESC (utilities, transport, real estate, smart-city)
- Strategic suppliers and managed-service providers to Dubai government
- Smart-Dubai and digital-government platform operators
- Major private-sector entities adopting ISR voluntarily as the emirate baseline
Aligned to the regulations that matter.
How we run a DESC ISR engagement.
Interactive walkthrough — every phase clickable, every activity documented, every artefact regulator-ready.
1 · Applicability + scoping
- Entity classification under DESC ISR
- Sector-specific overlay mapping
- Crown-jewel + critical-service identification
What your DESC ISR engagement puts on the table.
- DESC ISR applicability + scoping memo
- Control-by-control compliance register
- Maturity heatmap against Dubai Govt model
- Technical validation report (VAPT + config audit)
- Incident-response + supplier-risk pack
- DESC submission pack + examiner Q&A deck
- Annual recertification + closure tracker
DESC ISR audit + Dubai Govt maturity uplift
Outcome: Maturity score lifted by two grades inside one audit cycle; closure achieved without follow-up DESC visit
ISR + ISO 27001 unified program
Outcome: Single evidence pack satisfied both regimes; supplier-risk review cycle automated for 90+ suppliers
The shape of a DESC ISR engagement.
Every number below is grounded in how Macksofy actually runs the engagement — not aspirational marketing copy.
What we actually examine.
Each pillar is a distinct workstream inside the engagement — scoped, evidenced, and signed off independently before the audit pack is assembled.
- Applicability & scoping3 pts
- Governance & policy3 pts
- Access control & operations3 pts
- Smart-Dubai integration3 pts
- Incident response & continuity3 pts
- DESC audit-cycle pack3 pts
DESC ISR coverage varies by entity classification — scoping defines audit cost and depth.
- Entity-classification under ISR
- Sector-overlay + free-zone scoping
- Critical-service inventory
DESC examiners open every audit with policy currency and board accountability.
- Information-security policy library
- Security-committee charter + cadence
- Risk-register + board reporting
Identity, privileged access and operational security tested against ISR clauses.
- Identity + MFA on citizen services
- Privileged-access + admin controls
- Operations + change-management evidence
The control set where Dubai-specific examiners increasingly focus.
- API + integration security with Dubai-Now / DubaiPulse
- Cloud + data-residency posture
- Citizen-data classification + protection
Detection, escalation and recovery with emirate-level coordination expectations.
- Incident-detection + DESC notification SOP
- Tabletop drill (citizen-service scenario)
- BCP / DR with declared RTO + RPO
Artefacts assembled exactly the way DESC examiners consume them.
- Control-statement to evidence map
- Maturity-heatmap deck
- Examiner Q&A walk-through
From kick-off to regulator-ready report.
The horizontal flow below shows the typical week-by-week shape of a DESC ISR engagement. Click any station for detail in the methodology section above.
Rated 4.9 ★ from 612 client reviews.
“We've worked with three Big 4 firms before Macksofy. None found what their team did in our payments stack. The most actionable report we've received in a decade.”
“The CHFI training Macksofy delivered for our cyber cell raised investigation quality measurably. Practical, India-context-aware, and respectful of our operational realities.”
“Came in with zero security background. 5 weeks later I was running Burp Suite and Metasploit confidently. Cleared CEH on the first attempt.”
DESC ISR — what compliance leads ask before signing.
Saudi NCA ECC-2:2024 Audit
NCA ECC-2:2024 audit — baseline cybersecurity for all organisations in KSA.
Learn moreADHICS Compliance Audit
Full ADHICS readiness for Abu Dhabi healthcare providers, payers and Malaffi participants.
Learn moreSAMA Cyber Security Framework Audit
End-to-end SAMA CSF audit — control assessment, maturity scoring, submission pack.
Learn moreDESC ISR evidence starts with hands-on testing.
A clean DESC ISR report rests on real technical assurance. These Macksofy assessments generate the vulnerability, penetration and control-effectiveness evidence your auditor expects to see.
Penetration Testing
Find what attackers will. Before they do.
Explore serviceVulnerability Assessment & Penetration Testing (VAPT)
VAPT done properly — not a scan with a cover page.
Explore serviceWeb Application Security Testing
Test web apps the way attackers (and bug bounty hunters) do.
Explore serviceMacksofy delivers this work to the following standards and regulator requirements. Definitions and controls are sourced from the issuing bodies below.
Get a fixed-price proposal in 48 hours.
Tell us about your security need — pentest, audit, training or a wider engagement. A senior consultant will reply within a few business hours.
- CERT-In Empanelled
- EC-Council ATC · CompTIA Authorized
- 20,000+ professionals trained
- India + UAE engagements
