ما يُعد حادثةWhat counts as a breach
الوصول غير المصرح، الفقد، التعديل، أو الإفصاح — بما في ذلك الإرسال إلى مستلم خطأ. ليست الحادثة اختراقاً فقط؛ الخطأ البشري أكثر شيوعاً.Unauthorised access, loss, alteration or disclosure — including sending to the wrong recipient. A breach is not only a hack; human error is more common.
خطة بثلاث مراحلA three-stage plan
احتواء، ثم تقييم، ثم إشعار. الاحتواء يوقف التوسع، والتقييم يحدد الأثر، والإشعار يفي بالالتزام. الخلط بينها يُنتج قرارات متسرّعة.Contain, assess, notify. Containment stops spread, assessment determines impact, and notification meets the duty. Blurring them produces rushed decisions.
الأدلةEvidence
سجلات الوصول، الرسائل، أجهزة، وشهادات. بلا أدلة محفوظة، يصعب تحديد ما خرج فعلاً — ويصبح الإشعار تخميناً.Access logs, messages, devices and statements. Without preserved evidence it is hard to establish what actually left — and the notification becomes a guess.
من يقرر الإشعارWho decides on notification
حدّد سلطة القرار مسبقاً: من يقيّم، من يوافق، ومن يخاطب الجهة وأصحاب البيانات. قرار جماعي بلا مالك يُنتج تأخيراً.Define the decision authority in advance: who assesses, who approves, and who contacts the authority and the data subjects. A collective decision with no owner produces delay.
التوازي مع الأمن السيبرانيParallel to cybersecurity
الاستجابة التقنية والالتزام النظامي مساران متوازيان لا مسار واحد. الفريق التقني يعالج النظام، والمسؤول يوثّق ويقيّم ويشعر.Technical response and statutory duty are parallel tracks, not one. The technical team handles the system while the responsible person documents, assesses and notifies.
التمرينExercise it
نفّذ تمريناً ورقياً مرة كل سنة على سيناريو واقعي. التمرين يكشف الفجوات في القائمة والصلاحيات والاتصال بأقل تكلفة ممكنة.Run a tabletop exercise once a year on a realistic scenario. It reveals gaps in the list, authorities and contacts at the lowest possible cost.

