الفرق في الطبيعة لا في العمق فقطA difference in nature, not just depth
تقييم الثغرات يجيب على سؤال: «ما الثغرات الموجودة؟». اختبار الاختراق يجيب على سؤال مختلف تماماً: «هل يمكن استغلالها فعلاً للوصول إلى أصولي؟». الأول أداة إدارة مستمرة، والثاني إثبات لحظي. الخلط بينهما هو السبب الأول لإهدار الميزانية الأمنية.A vulnerability assessment answers "what weaknesses exist?". A penetration test answers a completely different question: "can they actually be exploited to reach my assets?". The first is a continuous management tool; the second is point-in-time proof. Confusing the two is the leading cause of wasted security budget.
مقارنة عمليةA practical comparison
تقييم الثغرات: آلي في معظمه، يستغرق ساعات إلى أيام، تكلفة معتدلة، مخرجات قائمة مصنّفة، ويُكرَّر شهرياً أو ربع سنوياً. اختبار الاختراق: يدوي في جوهره، يستغرق أسبوعين إلى ستة أسابيع، تكلفة أعلى بمراحل، مخرجات سلسلة استغلال موثّقة، ويُكرَّر سنوياً أو عند تغيير جوهري.Vulnerability assessment: mostly automated, hours to days, moderate cost, output is a ranked list, repeated monthly or quarterly. Penetration test: fundamentally manual, two to six weeks, substantially higher cost, output is a documented exploitation chain, repeated annually or after material change.
القاعدة العملية للاختيارThe practical selection rule
استخدم القاعدة التالية: تقييم ثغرات دوري لجميع الأصول بلا استثناء، واختبار اختراق للأصول الحرجة أو المعرّضة للإنترنت أو التي تحمل بيانات حساسة. لا تختبر كل شيء بعمق، ولا تكتفِ بفحص سطحي للأصول الحرجة.Use this rule: recurring vulnerability assessment for every asset without exception, and penetration testing for critical, internet-facing or sensitive-data assets. Do not test everything deeply, and do not settle for a surface scan on critical assets.
متطلبات الامتثالCompliance requirements
ضوابط NCA ECC تشترط اختبار اختراق دوري موثّق، وليس مجرد فحص آلي. لذلك إذا كنت تخضع للضوابط، فالتقرير الآلي وحده لن يُقبل كدليل امتثال — تحتاج اختباراً يدوياً بتقرير احترافي يوثّق المنهجية والنتائج والمعالجة.The NCA ECC requires documented periodic penetration testing, not merely an automated scan. If you fall under the controls, an automated report alone will not be accepted as compliance evidence — you need a manual test with a professional report documenting methodology, findings and remediation.
كيف توفّر دون المساس بالأمان؟How to save without weakening security
ثلاث ممارسات: استخدم تقييم الثغرات المستمر (أداة داخلية أو خدمة مُدارة) لتصفية الضوضاء قبل الاختبار، وحدّد نطاق الاختبار بدقة على ما يهم فعلاً، واجمع الاختبار مع إعادة الاختبار في عقد واحد لتوفير التكلفة. بهذا تحصل على تغطية أوسع بتكلفة أقل.Three practices: use continuous vulnerability assessment (an internal tool or managed service) to filter noise before the test, scope the test precisely to what truly matters, and bundle testing with retesting into a single contract to reduce cost. This delivers broader coverage for less.

