UAE · Government of Dubai

Dubai Information Security Regulation

The information security regulation applying to Dubai government entities and the organisations that serve them.

Who it applies to

Dubai government entities, and private organisations delivering services to them where the regulation is applied contractually.

What it requires

  • Control implementation across governance, technical and operational domains
  • Regular assessment against the regulation, with findings tracked to closure
  • Evidence of governance oversight rather than technical implementation alone

What preparing for it involves

Organisations bidding for Dubai government work frequently encounter this regulation through a procurement requirement rather than a regulatory notice. Preparation is most efficient when it is aligned with an existing ISO 27001 management system, so that a single control set serves both.

How it concludes

Assessed compliance, commonly evidenced during procurement and reassessed periodically.

SecureEdge Advisory prepares you and facilitates the process. The affirmation is made by an external auditor, a certification body or the regulator, never by us.

Cross-framework reuse

Control mappings for this framework are not yet published in the library. It is carried in full for assessment and preparation, and cross-framework reuse will follow as the mapping matures. We would rather state that plainly than imply reuse that does not exist.