CybersecurityRegulation

Dubai ISR

Dubai Government Information Security Regulation

The Dubai Government Information Security Regulation (ISR) provides standards to ensure the continuity of critical business processes and minimize information security risks for Dubai Government Entities. It defines minimum requirements for information security controls and aims to maintain confidentiality, integrity, and availability of government information.

Overview

The Information Security Regulation (ISR) is a comprehensive framework aimed at safeguarding government information by setting minimum requirements for information security controls. Applicable to all Dubai Government Entities, the ISR governs the handling of printed, electronic, and verbal information across all divisions and functions. It comprises thirteen domains categorized into Governance, Operation, and Assurance. Governance domains focus on structuring and managing information security, Operation domains cover technical and non-technical controls based on risk assessments, and Assurance domains provide quality checks for implemented solutions. The regulation also mandates the alignment of resources to achieve an optimal balance between risk management costs and protected information value. Introduced via Resolution No. 13 of 2012 and formalized under Dubai Law No. 11 of 2014, DESC is tasked with its continuous improvement to adapt to new security practices.

Related in Cybersecurity

CybersecurityGuideline

NIST SP 800-172 — Enhanced Security Requirements for Protecting Controlled Unclassified Information: A Supplement to NIST Special Publication 800-171

NIST SP 800-172 elaborates enhanced security requirements for protecting Controlled Unclassified Information (CUI) in nonfederal systems and organizations. It aims to mitigate risks posed by Advanced Persistent Threats (APT) through a defense-in-depth approach, building on the foundational requirements in NIST SP 800-171.

National Institute of Standards and Technology (NIST) • United States

View details
CybersecurityFramework

DSPF — Defence Security Principles Framework

The Defence Security Principles Framework (DSPF) is the Australian Department of Defence's principles-based security framework that provides governance, security principles, and controls to help Defence personnel manage risks and protect Defence people, information, assets, and operations in alignment with the PSPF.

Australian Government • Australian • v2 July 2018

View details
CybersecurityStandard

FedRAMP Controls — FedRAMP Security Controls Baseline rev 5

The FedRAMP Security Controls Baseline is a standardized set of cloud security requirements based on NIST SP 800-53 that defines the minimum security controls cloud service providers must implement to protect federal data and achieve FedRAMP authorization.

US Government • USA • vrev 5

View details
CybersecurityFramework

CPG 1.0 — Cross-Sector Cybersecurity Performance Goals

The Cross-Sector Cybersecurity Performance Goals (CPGs) are a set of baseline cybersecurity practices developed by CISA to help organizations of all sizes and sectors strengthen their resilience against common cyber threats. They provide prioritized, actionable measures that align with the NIST Cybersecurity Framework and are designed to be achievable, cost-effective, and impactful.

Cybersecurity and Infrastructure Security Agency (CISA) • United States • v1.0.1

View details

Ready to manage these frameworks?

6clicks maps regulations to controls, evidence and risks — automatically.

Book your strategy call