In 2014, the Dubai Electronic Security Centre (DESC) was established in the United Arab Emirates (UAE) with the goal of creating and implementing information security procedures throughout the Dubai Emirate. DESC created the Cloud Service Provider (CSP) Security Standard, which lays forth specifications and recommendations for CSPs and businesses utilising any cloud services. All CSPs who want to provide cloud services to Dubai government and semi-government organisations must adhere to these criteria.
The following standards serve as the foundation for the DESC CSP Security Standard:
- ISO/IEC 27001:2013
- ISO/IEC 27002:2013
- ISO/IEC 27017:2015
- The Information Security Regulation (ISR) 2017 of the Dubai Government
- Cloud Controls Matrix (CCM) 3.0.1 from the Cloud Security Alliance (CSA)
Mandatory standards for CSPs providing services to Dubai's government and semi-government entities are outlined in the CSP Security Standard. It also offers advice to these CSPs' clients. Dubai's government and semi-government entities are required to make sure that the CSP they use conforms with this criteria.
DESC aimed for close alignment with well-known worldwide standards during the CSP Security Standard's development in order to expedite the certification procedure. Therefore, this section of the CSP Security Standard would not be audited again if a CSP is already certified against ISO/IEC 27001:2013; rather, the ISO/IEC 27001:2013 certificate would be accepted. The same reasoning holds true for other current standards that serve as the foundation for the CSP Security Standard. For instance, a CSP's certification against CSA STAR Level 2 would be recognised without the need for an additional audit.
DESC has released a list of standards for certifying bodies looking to obtain DESC accreditation to carry out certification work against the CSP Security Standard in order to streamline this process. The validity of CSPs' current certifications can then be verified by a DESC-approved certifying organisation, which will then notify DESC of the results. After finishing all necessary tasks, the certifying body should notify DESC if certification is warranted. Additional audit work by a certification organisation might be required, such as a DESC-mandated physical on-site inspection of datacentre facilities.