
The Dubai Electronic Security Center (DESC) Cloud Service Provider (CSP) security
In 2014, the Dubai Electronic Security Centre (DESC) was established in the United Arab Emirates (UAE) to create and implement policies for information security throughout the Dubai Emirates. DESC launched the Cloud Service Provider (CSP) Security Standard, which offers guidance and recommendations for CSPs as well as businesses that use cloud services. All CSPs wishing to provide cloud services to government and semi-government entities in Dubai must comply with these standards.
The CSP Security Standard references the following criteria:
- ISO/IEC 27001:2013
- ISO/IEC 27002:2013
- ISO/IEC 27017:2015
- The Information Security Regulation (ISR) 2017 set forth by the Dubai Government
- Cloud Controls Matrix (CCM) 3.0.1 created by the Cloud Security Alliance (CSA)
The CSP Security Standard specifies the essential requirements for CSPs serving Dubai’s government and semi-government organizations. It also offers advice for the clients of these CSPs. Organizations within the Dubai government and semi-government sectors must ensure their selected CSP adheres to these standards.
In drafting the CSP Security Standard, DESC focused on aligning closely with recognized international standards to ease the certification process. As a result, if a CSP possesses a certification for ISO/IEC 27001:2013, there will not be a need for an additional audit in that portion of the CSP Security Standard; the current ISO/IEC 27001:2013 certification would be acknowledged. This concept is similarly applicable to other recognized standards that form the basis of the CSP Security Standard. For instance, a CSP certified at CSA STAR Level 2 would not require a further audit for acknowledgment.
To make this process easier, DESC has released a list of standards geared towards certification bodies seeking DESC accreditation to conduct certifications concerning the CSP Security Standard. An organization that is endorsed by DESC can verify the credentials of CSPs and relay the information to DESC. Once all required steps are finalized, the certification body should notify DESC regarding the appropriateness of the certification. An extra audit might be requested from the certifying body, which may necessitate a compulsory physical examination of the data center facilities as specified by DESC.
- Trust
- Data protection
- Business continuity
- Data protection
- Mitigate compliance risks.
- Safeguard sensitive data against emerging threats