ما هي ضوابط NCA ECC؟What is the NCA ECC?
الضوابط الأساسية للأمن السيبراني (ECC) هي إطار وطني يحدد الحد الأدنى من المتطلبات لحماية الأنظمة والبيانات. تُنظَّم في محاور تشمل حوكمة الأمن، أمن الأصول، أمن العمليات، أمن الشبكات، وإدارة الحوادث.The Essential Cybersecurity Controls (ECC) are a national framework defining the minimum requirements to protect systems and data. They are organised into domains covering security governance, asset security, operations security, network security and incident management.
الخطوة الأولى: تحديد النطاقStep one: define scope
لا يمكن تطبيق الضوابط على كل شيء في آن واحد. ابدأ بتحديد الأصول الحرجة والأنظمة التي تحمل بيانات حساسة، ووثّق حدود الشبكة والأنظمة المرتبطة. النطاق الواضح يمنع هدر الجهد.You cannot apply controls to everything at once. Start by identifying critical assets and systems holding sensitive data, and document network boundaries and connected systems. Clear scoping prevents wasted effort.
الخطوة الثانية: تقييم الفجواتStep two: gap assessment
قيّم كل ضابط مقابل الوضع الحالي بتصنيف: مُطبّق، مُطبّق جزئياً، غير مُطبّق. مخرجات هذه المرحلة هي سجل فجوات موثّق بالأدلة، وهو الأساس الذي تُبنى عليه خطة المعالجة.Assess each control against the current state as implemented, partially implemented or not implemented. The output is a documented gap register with evidence — the basis for the remediation plan.
الخطوة الثالثة: خطة معالجة مرتّبة بالمخاطرStep three: a risk-ranked remediation plan
رتّب الفجوات حسب الخطورة وتأثير الأعمال، لا حسب سهولة التنفيذ. الفجوات الحرجة (مثل إدارة الهويات والوصول، وسجلات المراقبة) تُعالَج أولاً لأنها الأكثر استغلالاً في الهجمات.Rank gaps by severity and business impact, not by ease of implementation. Critical gaps — such as identity and access management and logging — come first because they are the most exploited in attacks.
الخطوة الرابعة: التوثيق والأدلةStep four: documentation and evidence
الامتثال ليس ما تفعله فقط، بل ما يمكنك إثباته. لكل ضابط يجب وجود سياسة معتمدة، إجراء مُوثّق، وسجل تنفيذ. كثير من الجهات تُطبّق الضوابط لكنها تفشل في المراجعة بسبب نقص الأدلة.Compliance is not only what you do, but what you can prove. Every control needs an approved policy, a documented procedure and an execution record. Many organizations apply controls but fail audits due to missing evidence.
الخطوة الخامسة: المراقبة المستمرةStep five: continuous monitoring
الامتثال حالة متغيرة لا مشروع منتهٍ. أنشئ دورة مراجعة دورية، واربط سجلات الأنظمة بمركز مراقبة، وحدّث تقييم المخاطر كل ربع سنة أو عند أي تغيير جوهري في البنية.Compliance is a moving state, not a finished project. Establish a periodic review cycle, connect system logs to a monitoring centre, and refresh the risk assessment quarterly or upon any material change to the environment.

