تحديد النطاق بدقةDefining scope precisely

النطاق يجب أن يكون قائمة صريحة: عناوين IP أو النطاقات أو التطبيقات المشمولة، وما هو **مستثنى** صراحة. الاستثناءات لا تقل أهمية — أجهزة طبية، أنظمة تحكم صناعي، بيئات مرتبطة بأطراف خارجية. نطاق مكتوب بوضوح يمنع النزاعات ويحمي الأنظمة الحساسة.Scope must be an explicit list: included IP ranges, domains or applications, and what is explicitly excluded. Exclusions matter as much — medical devices, industrial control systems, environments tied to third parties. A clearly written scope prevents disputes and protects sensitive systems.

قواعد الاشتباك (RoE)Rules of engagement (RoE)

وثيقة قواعد الاشتباك تحدّد: النافذة الزمنية المسموح بها، ما يُسمح به (هل يُسمح بالهندسة الاجتماعية؟ بالهجمات الحقيقية؟ بالتصعيد؟)، كيف تُبلَّغ الثغرات الحرجة فوراً، ومسارات التصعيد عند وقوع حادث غير مقصود. لا تبدأ اختباراً بدونها.The RoE document defines the permitted time window, what is allowed (is social engineering permitted? real exploitation? privilege escalation?), how critical findings are reported immediately, and escalation paths if an unintended incident occurs. Never start a test without it.

الإذن الكتابي — الحماية القانونيةWritten authorisation — your legal protection

بدون إذن كتابي موقّع من مفوّض، فإن اختبار الاختراق قانونياً يشبه الهجوم. الإذن يجب أن يذكر النطاق، والمدة، والمخوّلين بالتوقيع، ويُحفظ لدى الطرفين. في بيئات متعددة الأطراف (مزوّد سحابي، طرف ثالث)، تأكد من موافقة كل الأطراف قبل البدء.Without signed authorisation from an empowered signatory, a penetration test is legally indistinguishable from an attack. The authorisation must state scope, duration and authorised signatories, and be retained by both parties. In multi-party environments (cloud provider, third party), secure every party's consent before starting.

التنسيق مع فرق التشغيلCoordinating with operations teams

أخبر فريق الشبكة ومركز العمليات (SOC) بموعد الاختبار وعنوان IP المصدر، وإلا فقد يقطع الفريق الاتصال بالمختبر أو يُطلق استجابة حادث كاملة. التنسيق يشمل أيضاً أنظمة النسخ الاحتياطي والمراقبة، وأي أدوات حماية قد تُشوّش النتائج.Tell the network team and the SOC the test window and the source IP, otherwise they may block the tester or trigger a full incident response. Coordination also covers backup and monitoring systems, and any protective tooling that could distort the results.

تجنّب تعطيل الإنتاجAvoiding production disruption

اطلب دائماً اختباراً «آمناً» على بيئات الإنتاج، أو اختباراً كاملاً على بيئة اختبار مطابقة. أدوات استغلال بعض الثغرات قد تسبب توقفاً أو فقدان بيانات. القاعدة: إذا لم يُوثّق أثر الاختبار على الاستمرارية، فلا تسمح به في الإنتاج.Always require "safe" testing on production environments, or full testing on a matching staging environment. Exploitation tooling for some vulnerabilities can cause outages or data loss. The rule: if the test's impact on availability is not documented, do not allow it in production.

الاستفادة القصوى من النافذةGetting the most from the window

جهّز قبل البدء: حسابات اختبار بصلاحيات محددة، بيانات وهمية واقعية، وثائق معمارية للنظام، ووصولاً للبيئة من نقاط محددة. كل ساعة يستهلكها المختبر في فهم البنية هي ساعة لم تُستثمر في الاختبار الفعلي.Prepare in advance: test accounts with defined privileges, realistic dummy data, system architecture documentation, and environment access from defined points. Every hour the tester spends understanding the architecture is an hour not invested in actual testing.