أربعة مستويات لا أكثرFour levels, no more
عام، داخلي، سري، سري للغاية. كل مستوى إضافي يُقلّل احتمال الاستخدام الصحيح. أربعة مستويات يفهمها الموظف ويتذكرها.Public, internal, confidential, highly confidential. Every extra level reduces the chance of correct use. Four levels can be understood and remembered.
لكل مستوى قاعدة واحدةOne rule per level
عام: لا قيود. داخلي: الموظفون. سري: من يحتاج للعمل مع صلاحية محددة. سري للغاية: صلاحية خاصة وتسجيل وصول. القاعدة الواضحة هي ما يُطبَّق.Public: no restriction. Internal: employees. Confidential: need-to-know with defined access. Highly confidential: special approval and access logging. A clear rule is what gets applied.
اربطه بالصلاحيات تقنياًLink it to access technically
التصنيف بلا ربط تقني يبقى نصيحة. اجعل مستوى التصنيف يحدد مجلد التخزين أو مجموعة الصلاحيات، بحيث يُطبَّق تلقائياً.Classification without technical linkage remains advice. Have the level determine the storage folder or access group so it is applied automatically.
الأخطاء الشائعةCommon errors
تصنيف كل شيء «سري» (فيُهمل التصنيف)، وترك المستويات بلا قواعد، وعدم مراجعة التصنيف عند تغيّر الاستخدام. الثلاثة تُنتج تصنيفاً معطلاً.Classifying everything confidential (so classification is ignored), leaving levels without rules, and never reviewing classification when use changes. All three disable it.
البيانات الشخصية حالة خاصةPersonal data is a special case
التصنيف لا يغني عن متطلبات الخصوصية. بيانات العملاء الشخصية قد تكون «سرياً» في التصنيف، لكن لها التزامات إضافية في الغرض والحفظ والحقوق.Classification does not replace privacy requirements. Customer personal data may be confidential by classification yet carry extra obligations in purpose, retention and rights.
المراجعةReview
راجع التصنيف سنوياً: هل ما زال البند بحاجة إلى مستواه؟ البيانات التي فقدت حساسيتها تُخفَّض، والتي زادت تُرفع. التصنيف الثابت بلا مراجعة يصبح غير دقيق.Review annually: does the item still need its level? Data that lost sensitivity is downgraded, and data that gained it is raised. Static classification without review becomes inaccurate.

