Executive Council Resolution No. (13) of 2012
Concerning
Information Security at the Government of Dubai[1]
ـــــــــــــــــــــــــــــــــــــــــ
We, Hamdan bin Mohammed bin Rashid Al Maktoum, Crown Prince of Dubai, Chairman of the Executive Council,
After perusal of:
Federal Law No. (3) of 1987 Issuing the Penal Code and its amendments;
Federal Law No. (7) of 2002 Concerning Copyright and Related Rights and its amendments;
Federal Law No. (1) of 2006 Concerning Electronic Transactions and e-Commerce;
Federal Law No. (2) of 2006 Concerning Combating Information Technology Crime;
Law No. (2) of 2002 Concerning Electronic Transactions and e-Commerce;
Law No. (3) of 2003 Establishing the Executive Council of the Emirate of Dubai;
Law No. (27) of 2006 Concerning Management of the Government of Dubai Human Resources and its amendments;
Law No. (7) of 2009 Establishing the Dubai eGovernment; and
Law No. (8) of 2010 Concerning the Financial Audit Department and its amendments,
© 2014 The Supreme Legislation Committee in the Emirate of Dubai
[1]Every effort has been made to produce an accurate and complete English version of this legislation. However, for the purposes of its interpretation and application, reference must be made to the original Arabic text. In case of conflict the Arabic text will prevail.
Definitions
Article (1)
The following words and expressions, wherever mentioned in this Resolution, will have the meaning indicated opposite each of them unless the context implies otherwise:
Emirate: | The Emirate of Dubai. |
Government: | The Government of Dubai. |
Government Entities: | Government departments, agencies, public corporations, councils, and authorities, including free zone authorities, and any other entity affiliated to the Government. |
DeG: | The Dubai eGovernment Department. |
Information: | The information, data, documents, and information resources whether printed, written on paper, electronically saved, processed, sent by post or electronic media, appearing in video or audio recordings, or disclosed during face to face conversations or in any other means of communication. |
Information Systems: | Any computerised or manual system used by Government Entities for the purpose of information management and processing. |
Information Security: | Any procedure or measure taken to protect Information Systems or Information against unauthorised access, use, disclosure, disabling, variation, destruction, cancelling, or deletion. |
Information Security Governance: | A branch of corporate governance which comprises strategic orientation, regulatory structure, and the procedures required for the security and confidentiality of vital Information resources. |
Information Security System: | The general Information Security framework adopted by the Committee. |
Committee: | The Information Security Committee formed pursuant to this Resolution. |
Objectives of the Information Security System
Article (2)
The Information Security System will have the objectives to:
Scope of Application of the Information Security System
Article (3)
Components of the Information Security System
Article (4)
The Information Security System will be comprised of:
Obligations of the DeG
Article (5)
For purposes of this Resolution, the DeG must:
Formation of the Committee
Article (6)
Committee Meetings
Article (7)
Functions of the Committee
Article (8)
The Committee will:
Obligations of Government Entities
Article (9)
A Government Entity must:
Obligations of the Financial Audit Department
Article (10)
The Financial Audit Department must monitor the application of the Information Security System by Government Entities, prepare the reports required in this regard, and provide the Committee with copies of these reports.
Obligations of Employees of Government Entities
Article (11)
Employees of Government Entities must:
Measures and Procedures
Article (12)
Without prejudice to any applicable civil or criminal liability he may incur, an employee of a Government Entity who violates the security and safety measures adopted by the Government Entity in relation to Information Security in a manner that causes change, modification, destruction, damage, deletion, cancellation, or loss of Information will be subject to disciplinary action.
Obligations of Persons Dealing with Government Entities
Article (13)
Subject to the liability stipulated in the legislation in force, persons and entities conducting activities which, by their nature, require access to the Information Systems adopted by Government Entities must:
Ownership of the Information Security System
Article (14)
The Information Security System and all its components, including data, Information, and software, are property of the Government. The Government will be exclusively authorised to dispose of the Information Security System by any means.
Modification of the Information Security System
Article (15)
Upon the recommendation of the Committee, the Director General of the DeG may modify any of the domains and objectives of the Information Security System and the controls for achieving these objectives in order for the system to fulfil its purposes, and notify the Government Entities which implement the system of this modification upon its approval by the Committee.
Time Limit for Preparation of the Information Security System
Article (16)
No later than three (3) months from the date on which this Resolution comes into force, the DeG must prepare the Information Security System, present it to the Committee for approval, and send it after approval to Government Entities for implementation and adoption.
Implementing Bylaws
Article (17)
The Director General of the DeG will issue the bylaws and instructions required for the implementation of the provisions of this Resolution.
Repeals
Article (18)
Any provision in any other resolution will be repealed to the extent that it contradicts the provisions of this Resolution.
Publication and Commencement
Article (19)
This Resolution will be published in the Official Gazette, and will come into force on the day on which it is published.
Hamdan bin Mohammed bin Rashid Al Maktoum
Crown Prince of Dubai
Chairman of the Executive Council
Issued in Dubai on 11 April 2012
Corresponding to 19 Jumada al-Ula 1433 A.H.