إدارة الوصولAccess management
أربعة اختبارات: هل لكل مستخدم حساب شخصي (لا حسابات مشتركة)؟ هل الصلاحيات مبنية على الدور ومُعتمدة؟ هل تُزال صلاحيات المنقولين والمستقيلين فوراً؟ هل الحسابات ذات الصلاحيات العالية محدودة ومُراجَعة؟Four tests: does every user have a personal account (no shared accounts)? Are permissions role-based and approved? Are permissions removed immediately for transfers and leavers? Are privileged accounts limited and reviewed?
إدارة التغييرChange management
ثلاثة أسئلة: هل كل تغيير على النظام مُصرَّح به قبل التنفيذ؟ هل يُختبر في بيئة منفصلة قبل الإنتاج؟ هل يوجد فصل بين من يطوّر ومن ينشر التغيير؟ التغيير المباشر على الإنتاج بلا اختبار هو أخطر ملاحظة تدقيق.Three questions: is every system change authorised before deployment? Is it tested in a separate environment before production? Is there separation between who develops and who deploys? A direct production change without testing is the most serious audit finding.
إدارة العملياتOperations management
أربعة عناصر: جدولة المهام الآلية ومراقبتها، مراقبة الأداء والاستخدام، إدارة الأخطاء والحوادث، والنسخ الاحتياطي المُختبر. العنصر الأخير الأهم: نسخة احتياطية لم تُجرَّب استعادتها ليست ضابطاً.Four elements: scheduling and monitoring automated jobs, monitoring performance and utilisation, error and incident management, and tested backups. The last is the most important: a backup whose restore has never been tested is not a control.
الفصل بين المهامSegregation of duties
القاعدة: لا يجمع شخص واحد بين تطوير النظام، نشره في الإنتاج، والوصول لبيانات الإنتاج. في المنشآت الصغيرة قد يكون الفصل مستحيلاً — عندها تُستخدم ضوابط تعويضية: مراجعة مستقلة، سجلات مراجعة، ومراجعة دورية للأنشطة.The rule: no single person should combine developing the system, deploying to production, and accessing production data. In small organizations separation may be impossible — compensating controls are then used: independent review, audit logs, and periodic activity review.
سجلات المراجعةAudit logs
سجلات المراجعة يجب أن: تُسجَّل لكل الأنشطة الحساسة، وتُحفظ مدة كافية، وتُحمى من التعديل أو الحذف، وتُراجَع دورياً. السجل الذي يمكن للمستخدم حذفه ليس سجلاً — بل مصدر ثقة زائفة.Audit logs must: capture all sensitive activity, be retained long enough, be protected from modification or deletion, and be reviewed periodically. A log the user can delete is not a log — it is a source of false confidence.
الاستعداد العمليPractical preparation
قبل أي تدقيق، جهّز أربع حزم: مصفوفة الصلاحيات الحالية، سجلات التغييرات للسنة، نتائج آخر اختبار استعادة، وتقارير الحوادث. هذه الأربع تُغطي معظم ما يطلبه المدقق — والجاهزية تخفض عدد الملاحظات بشكل كبير.Before any audit, prepare four packs: the current access matrix, the year's change logs, the last restore test results, and incident reports. These four cover most of what an auditor requests — and readiness significantly reduces findings.

