ما الفرق بين تقييم الثغرات واختبار الاختراق؟What is the difference between a vulnerability assessment and a penetration test?

تقييم الثغرات عملية آلية واسعة: يفحص الأنظمة بحثاً عن ثغرات معروفة ويصنّفها حسب الخطورة، لكنه لا يثبت قابليتها للاستغلال. اختبار الاختراق عملية يدوية عميقة: يحاول مهندس أمني فعلياً استغلال الثغرات وتجاوز الضوابط والوصول لبيانات حقيقية. الأول يعطيك قائمة، والثاني يعطيك دليلاً.A vulnerability assessment is a broad automated sweep: it scans systems for known weaknesses and ranks them by severity, but it does not prove exploitability. A penetration test is a deep manual effort: a security engineer actually attempts to exploit flaws, bypass controls and reach real data. The first gives you a list; the second gives you proof.

المنهجيات المعتمدةRecognised methodologies

الاختبار الاحترافي يتبع منهجية موثّقة لا اجتهاداً شخصياً: OWASP Testing Guide لتطبيقات الويب، PTES لمراحل الاختبار، MITRE ATT&CK لمحاكاة سلوك المهاجمين الحقيقيين، وNIST SP 800-115 للاختبار التقني. اطالب المورّد بذكر المنهجية في العرض — غيابها مؤشر على عمل غير منهجي.A professional test follows a documented methodology rather than improvisation: the OWASP Testing Guide for web applications, PTES for test phases, MITRE ATT&CK for emulating real adversary behaviour, and NIST SP 800-115 for technical testing. Ask the vendor to name the methodology — its absence signals an unstructured engagement.

أنواع الاختباراتTypes of testing

خمسة أنواع أساسية: اختبار الشبكة الخارجية (ما يراه مهاجم من الإنترنت)، الشبكة الداخلية (ما يستطيع موظف مخترق فعله)، تطبيقات الويب، تطبيقات الجوال، والهندسة الاجتماعية (اختبار الوعي البشري). لكل نوع نطاق وقواعد اشتباك مختلفة، والأخطاء الشائعة هي اختبار الخارج فقط وإهمال الداخل.Five core types: external network testing (what an internet-based attacker sees), internal network testing (what a compromised employee could do), web application testing, mobile application testing, and social engineering (testing human awareness). Each has a different scope and rules of engagement; the common mistake is testing only the outside and ignoring the inside.

ماذا يجب أن يحتوي التقرير؟What should the report contain?

تقرير ضعيف يعرض قائمة أدوات ونتائج مخرجات آلية. تقرير احترافي يحتوي: ملخصاً تنفيذياً بلغة الإدارة بلا مصطلحات، سلسلة الاستغلال خطوة بخطوة، الأدلة (لقطات وسجلات)، تقييم الأثر على الأعمال لا التقني فقط، وخطة معالجة مرتّبة حسب الخطورة مع تقدير الجهد.A weak report lists tools and raw scanner output. A professional report contains an executive summary in business language, the exploitation chain step by step, evidence (screenshots and logs), a business-impact rating rather than purely technical, and a remediation plan ranked by severity with effort estimates.

قواعد الاشتباك قبل البدءRules of engagement before you start

قبل أي اختبار يجب توثيق: النطاق بالضبط (ما يُختبر وما يُستثنى)، النافذة الزمنية، جهات الاتصال للطوارئ، الإذن الكتابي الموقّع، وما يُسمح به (هل يُسمح بالهندسة الاجتماعية؟ هل يُسمح بتعطيل خدمة؟). اختبار بلا قواعد اشتباك موثّقة قد يتحول إلى حادث حقيقي.Before any test, document the exact scope (what is in and out), the time window, emergency contacts, signed written authorisation, and what is permitted (is social engineering allowed? is denial of service allowed?). A test without documented rules of engagement can turn into a real incident.

من التقرير إلى الحماية الفعليةFrom report to real protection

الخطأ الأكثر شيوعاً هو تسلّم التقرير وأرشفته. المعالجة الفعّالة تمر بأربع خطوات: تصنيف النتائج حسب المخاطر، إصلاح الثغرات الحرجة خلال أيام لا أشهر، إعادة اختبار للتأكد من الإغلاق الفعلي، ثم معالجة السبب الجذري لا العَرَض. الاختبار الذي لا يتبعه إصلاح لا قيمة له.The most common mistake is receiving the report and filing it. Effective remediation has four steps: rank findings by risk, fix critical issues within days not months, retest to confirm real closure, then address the root cause rather than the symptom. A test not followed by remediation has no value.

الارتباط بالأنظمة السعوديةLink to Saudi regulations

ضوابط الهيئة الوطنية للأمن السيبراني (NCA ECC) تشترط إجراء اختبارات اختراق دورية على الأنظمة والخدمات، وتوثيق النتائج والمعالجة كأدلة. لذلك الاختبار ليس مبادرة اختيارية بل متطلب امتثال — وتقريره جزء من ملف الأدلة الذي يطلبه المراجع.The NCA Essential Cybersecurity Controls require periodic penetration testing of systems and services, with documented findings and remediation as evidence. Testing is therefore not an optional initiative but a compliance requirement — and its report forms part of the evidence file an auditor requests.