الطلبThe request
الصلاحية تُمنح بطلب مبرر ومحدد لا بمكالمة. الطلب المكتوب يُنشئ مسؤولية واضحة لمن منح ومتى.Access is granted on a justified, specific request, not a phone call. A written request creates clear responsibility for who granted it and when.
مبدأ الحد الأدنىLeast privilege
امنح ما يكفي للمهمة لا أكثر. الصلاحية الواسعة «للاحتياط» تُنتج مخاطرة دائمة مقابل راحة مؤقتة.Grant enough for the task, no more. Broad access "just in case" creates permanent risk for temporary convenience.
المراجعةReview
مراجعة دورية لمن يملك ماذا، بموافقة المدير على قائمة فريقه. المراجعة التي لا يُطلب فيها إلغاء شيء تُنفَّذ شكلاً.A periodic review of who holds what, with the manager approving their team's list. A review where nothing is revoked is performed in form only.
الإلغاءRevocation
عند النقل أو الخروج، الإلغاء فوري. الفترة بين الخروج والإلغاء هي نافذة خطر حقيقية.On transfer or exit, revocation is immediate. The period between exit and revocation is a real risk window.
الحسابات المميزةPrivileged accounts
منفصلة عن الحساب اليومي وبمراجعة أضيق وتكرار أعلى. استخدام حساب واحد للمهام اليومية والإدارية يُضاعف أثر أي تصيّد.Separate from the daily account, with tighter review and higher frequency. Using one account for daily and administrative work multiplies the effect of any phishing.
الأدلةEvidence
احتفظ بسجلات المنح والإلغاء والمراجعات. عند أي حادثة، هذه السجلات هي ما يحدد المسؤولية.Keep records of grants, revocations and reviews. In any incident, these records determine responsibility.

