Overview
The Information Security Regulation (ISR) is a comprehensive framework aimed at safeguarding government information by setting minimum requirements for information security controls. Applicable to all Dubai Government Entities, the ISR governs the handling of printed, electronic, and verbal information across all divisions and functions. It comprises thirteen domains categorized into Governance, Operation, and Assurance. Governance domains focus on structuring and managing information security, Operation domains cover technical and non-technical controls based on risk assessments, and Assurance domains provide quality checks for implemented solutions. The regulation also mandates the alignment of resources to achieve an optimal balance between risk management costs and protected information value. Introduced via Resolution No. 13 of 2012 and formalized under Dubai Law No. 11 of 2014, DESC is tasked with its continuous improvement to adapt to new security practices.