لماذا فشل نموذج المحيط؟Why did the perimeter model fail?

النموذج التقليدي يفترض أن داخل الشبكة آمن وأن الخارج خطر. لكن اليوم: الموظفون يعملون من المنزل، الأنظمة في السحابة، الموردون يحتاجون وصولاً، والأجهزة مختلطة. النتيجة أن الحدود صارت ثقوباً، وأن أي اختراق واحد يمنح المهاجم ثقة كاملة داخل الشبكة.The traditional model assumes inside the network is safe and outside is dangerous. But today: employees work from home, systems live in the cloud, suppliers need access, and devices are mixed. The perimeter has become porous, and a single breach grants the attacker full trust inside.

المبادئ الثلاثة الأساسيةThe three core principles

١) لا تثق ضمنياً بأي طلب بناءً على موقعه في الشبكة. ٢) تحقق من كل وصول صراحةً (من؟ ماذا؟ من أي جهاز؟ ما حالة الجهاز؟). ٣) افترض الاختراق وقلّل الصلاحيات إلى الحد الأدنى الضروري. هذه المبادئ تُطبَّق تدريجياً لا دفعة واحدة.1) Never implicitly trust a request based on its network location. 2) Verify every access explicitly (who? what? from which device? what is the device's health?). 3) Assume breach and reduce privileges to the minimum necessary. These principles are applied gradually, not all at once.

الركائز التقنيةThe technical pillars

الهوية أولاً: مصدر واحد للهوية مع تحقق متعدد العوامل. ثم الجهاز: تقييم حالة الجهاز قبل منح الوصول. ثم الشبكة: تقسيم دقيق ومنع الحركة الجانبية. ثم التطبيقات والبيانات: صلاحيات دقيقة لكل تطبيق وبيانات مشفّرة. الهوية هي نقطة البداية دائماً.Identity first: a single source of identity with multi-factor authentication. Then device: assessing device health before granting access. Then network: fine-grained segmentation and blocking lateral movement. Then applications and data: least privilege per application and encrypted data. Identity is always the starting point.

خطة تطبيق مرحليةA phased adoption plan

المرحلة الأولى (0-3 أشهر): جرد الهويات والأجهزة، وتفعيل التحقق متعدد العوامل لكل وصول عن بُعد. المرحلة الثانية (3-9 أشهر): تقسيم الشبكة، وتقليل الصلاحيات المرتفعة، وإدارة الأجهزة. المرحلة الثالثة (9-18 شهراً): وصول قائم على السياق، وتشفير البيانات، ومراقبة مستمرة.Phase one (0–3 months): inventory identities and devices, and enforce multi-factor authentication on all remote access. Phase two (3–9 months): network segmentation, reduce privileged access, and device management. Phase three (9–18 months): context-based access, data encryption, and continuous monitoring.

ما لا تفعلهWhat not to do

لا تشترِ «حل Zero Trust» كمنتج جاهز — لا يوجد منتج واحد يحققها. لا تبدأ بالتقنية قبل الهوية والصلاحيات. ولا تحاول تطبيقها كلها في سنة واحدة — فهي رحلة متعددة السنوات، والفشل يأتي من محاولة القفز للمرحلة الأخيرة.Do not buy "a Zero Trust solution" as an off-the-shelf product — no single product delivers it. Do not start with technology before identity and privileges. And do not attempt it all in one year — it is a multi-year journey, and failure comes from trying to jump to the final stage.

الارتباط بضوابط NCALink to NCA controls

كثير من مبادئ الثقة الصفرية تتقاطع مباشرة مع ضوابط الهيئة الوطنية للأمن السيبراني — خصوصاً إدارة الهويات والوصول، وأمن الأصول، وتقسيم الشبكات. لذلك تطبيقها يخدم هدفين: تقوية الأمن الحقيقي، وإثبات الامتثال التنظيمي.Many Zero Trust principles map directly onto NCA Essential Cybersecurity Controls — particularly identity and access management, asset security, and network segmentation. Adopting them therefore serves two goals: strengthening real security and demonstrating regulatory compliance.