التصنيفClassification
ليس كل مورد بنفس المخاطرة. صنّف بحسب الوصول: بيانات حساسة، أنظمة تشغيلية، أو خدمات عادية.Not every supplier carries the same risk. Classify by access: sensitive data, operational systems, or ordinary services.
التقييمAssessment
قبل التعاقد: ضوابط أمنية، تعامل مع الحوادث، نسخ احتياطي، وخطة خروج. الاستبيان المكتوب أفضل من الطمأنينة الشفهية.Before contracting: security controls, incident handling, backup and exit plan. A written questionnaire beats verbal reassurance.
العقدThe contract
بنود أساسية: الإشعار بالحوادث، الحق في التدقيق، حدود المسؤولية، وملكية البيانات. العقد الذي لا يذكرها يتركك بلا أداة.Essential clauses: incident notification, audit rights, liability limits and data ownership. A contract omitting them leaves you without leverage.
الوصولAccess
وصول المورد يجب أن يكون محدوداً ومسجّلاً وبموافقتك، لا دائماً. الوصول الدائم للمورد يوسّع سطح المخاطرة بلا حاجة.Supplier access should be limited, logged and subject to your approval, not standing. Permanent supplier access expands the risk surface without need.
المراقبةMonitoring
راجع الموردين دورياً: حوادث، تغييرات، وشهادات. المراجعة عند التعاقد فقط تُنتج صورة قديمة.Review suppliers periodically: incidents, changes and certificates. Reviewing only at contracting produces an outdated picture.
الخروجExit
لكل مورد حرج خطة بديل: كيف نستخرج بياناتنا؟ من يخلفه؟ متى تُحذف نسخه؟ الخروج غير المخطط يعيدك إلى نقطة الصفر.Every critical supplier needs an alternative plan: how do we extract data, who replaces them, when are their copies deleted? An unplanned exit returns you to zero.

