كيف تقرأ ضوابط NCA ECC؟How to read the NCA ECC
الضوابط منظّمة في مجالات رئيسية، ولكل مجال ضوابط فرعية بمستويات. لا تحاول قراءتها كوثيقة واحدة — بل ابدأ بتحديد الضوابط ذات الأولوية العالية، لأنها تمثل الوزن الأكبر في تقييم المخاطر.The controls are organised into main domains, each with sub-controls at different levels. Do not read it as a single document — start by identifying the high-priority controls, as they carry the greatest weight in the risk assessment.
المجالات الخمسة الأكثر تأثيراًThe five highest-impact domains
١) إدارة الهويات والوصول (من يدخل وماذا يرى). ٢) أمن الأصول والأجهزة. ٣) سجلات المراقبة وإدارة الأحداث. ٤) أمن الشبكات والحدود. ٥) إدارة الحوادث والاستجابة. معالجة هذه الخمسة تغطي الجزء الأكبر من المخاطر الحرجة.1) Identity and access management (who gets in and sees what). 2) Asset and endpoint security. 3) Logging and event management. 4) Network and perimeter security. 5) Incident management and response. Addressing these five covers the majority of critical risk.
قائمة تحقق تنفيذيةAn executive checklist
☐ جرد كامل للأصول والأنظمة. ☐ مصفوفة صلاحيات موثّقة ومُراجَعة. ☐ تحقق متعدد العوامل للحسابات الحساسة. ☐ سجلات مركزية محمية من التعديل. ☐ نسخ احتياطي مُختبر دورياً. ☐ سياسة كلمات مرور وإدارة حسابات. ☐ إدارة الثغرات والتحديثات. ☐ خطة استجابة للحوادث مُجرَّبة. ☐ تدريب توعوي موثّق للموظفين. ☐ اتفاقيات مع الأطراف الخارجية.☐ Complete asset and system inventory. ☐ Documented and reviewed access matrix. ☐ Multi-factor authentication for privileged accounts. ☐ Centralised, tamper-protected logging. ☐ Regularly tested backups. ☐ Password and account management policy. ☐ Vulnerability and patch management. ☐ Tested incident response plan. ☐ Documented staff awareness training. ☐ Third-party agreements.
الأدلة المطلوبة لكل ضابطEvidence required for each control
لكل ضابط: سياسة معتمدة وموقّعة، إجراء تشغيلي موثّق، وسجل تنفيذ فعلي (لقطات من الأنظمة، تقارير، سجلات جلسات). القاعدة: إذا لم يكن موثّقاً، فهو غير موجود في نظر المراجع.For each control: an approved and signed policy, a documented operating procedure, and an actual execution record (system screenshots, reports, session logs). The rule: if it is not documented, it does not exist in the auditor's view.
أخطاء تسبب فشل المراجعةMistakes that cause audit failure
أكثر خمسة أخطاء: تطبيق الضوابط دون توثيق، سجلات مراقبة غير محمية من الحذف، حسابات مشتركة بين عدة مستخدمين، خطة استجابة للحوادث موجودة لكن غير مُجرَّبة، وعدم تحديث تقييم المخاطر بعد تغييرات البنية.The five most common: applying controls without documentation, logging that is not protected from deletion, shared accounts across multiple users, an incident response plan that exists but is never tested, and a risk assessment not refreshed after infrastructure changes.
خطة 90 يوماًA 90-day plan
الأيام 1–30: جرد الأصول وتقييم الفجوات وتحديد الأولويات. الأيام 31–60: معالجة الفجوات الحرجة (الهويات، السجلات، النسخ الاحتياطي) وبناء السياسات. الأيام 61–90: التوثيق الكامل، اختبار خطة الاستجابة، وإغلاق الفجوات المتبقية. بعدها: دورة مراجعة ربع سنوية.Days 1–30: asset inventory, gap assessment and prioritisation. Days 31–60: remediate critical gaps (identity, logging, backup) and draft policies. Days 61–90: complete documentation, test the response plan, and close remaining gaps. After that: a quarterly review cycle.

