Saif Ali AlghamdiTransformation & Growth Advisor
تواصل
LibraryمكتبتيDigital & Technologyرقمي وتقنية
CYBERSECURITY · OPERATIONAL FRAMEWORKالأمن السيبراني · إطار تشغيلي

Identity, Access & Security Policiesالهوية والصلاحيات والسياسات الأمنية

SectionالقسمDigital & Technologyرقمي وتقنية
Reading timeزمن القراءة8 min٨ دقيقة
ByإعدادSaif Alghamdiسيف الغامدي
One

Overview

Field: Identity & access management
Scope: Who can access what, proven, granted least, and reviewed
Owner role: Identity & access owner, with system owners
Review cadence: Access recertified at planned intervals, at least yearly
By: Saif Alghamdi

Identity and access management is the discipline of making sure the right people, and only the right people, can reach the right resources, for the right reasons, at the right time. It is the control most incidents ultimately turn on, because a stolen or over-privileged identity is the key that opens every other door.

The framework rests on a simple chain: prove who someone is, decide what they may do, grant only that, and check later that the grant is still correct. Break any link and the others weaken, since strong authentication is wasted if everyone is an administrator, and least privilege is meaningless if identities are easy to impersonate.

This framework is reusable for any environment and aligns to recognized guidance, drawing on the digital identity guidance of NIST and the access control controls of established catalogs, without reproducing their text.

Note: Identity is the new perimeter. As systems move outside the office network, the question shifts from where you are connecting to who you are and what you are allowed to do.
الأول

نظرة عامة

المجال: إدارة الهوية والصلاحيات
النطاق: مَن يصل إلى ماذا، بإثباتٍ وأقلّ صلاحية ومراجعة
دور المالك: مالك الهوية والصلاحيات، مع ملّاك الأنظمة
دورية المراجعة: إعادة اعتماد الصلاحيات على فترات مخطّطة، سنويًا على الأقل
إعداد: سيف الغامدي

إدارة الهوية والصلاحيات انضباطٌ يضمن أن الأشخاص الصحيحين، وهم فقط، يصلون إلى الموارد الصحيحة، لأسبابٍ صحيحة، في الوقت الصحيح. وهي الضابط الذي تدور عليه أغلب الحوادث في النهاية، لأن هويةً مسروقة أو مفرطة الصلاحية هي المفتاح الذي يفتح كل بابٍ آخر.

يقوم الإطار على سلسلةٍ بسيطة: أثبِت من يكون الشخص، وقرّر ما يجوز له، وامنحه ذلك فقط، وتحقّق لاحقًا أن المنح ما زال صحيحًا. واكسِر أي حلقةٍ تضعف الأخرى، فالمصادقة القوية تُهدَر إن كان الجميع مسؤولًا إداريًا، وأقلّ الصلاحية بلا معنى إن كانت الهويات سهلة الانتحال.

هذا الإطار قابل لإعادة الاستخدام لأي بيئة ويتوافق مع الإرشاد المعترف به، مستندًا إلى إرشاد الهوية الرقمية من NIST وضوابط التحكّم بالوصول من الكتالوجات المعتمَدة، دون نسخ نصّها.

ملاحظة: الهوية هي المحيط الجديد. فمع خروج الأنظمة عن شبكة المكتب، ينتقل السؤال من أين تتّصل إلى مَن أنت وما المسموح لك فعله.
Two

Identity & Its Lifecycle

Every access decision starts with an identity, and every identity has a lifecycle: it is created, it changes as a person's role changes, and it must be removed when they leave. Most access problems trace back to a lifecycle step that was skipped.

The critical events are joining, moving, and leaving. When someone joins, they should receive exactly the access their role needs, no more. When they move, old access should be removed as new access is added, not simply stacked on top. When they leave, access should be revoked promptly, because a departed employee with a live account is a standing risk that guards nothing.

  • Joiner: provision access from a defined role, so a new hire starts with a known, minimal set.
  • Mover: adjust access on role change, removing what is no longer needed rather than accumulating.
  • Leaver: revoke access promptly on departure, across every system the identity touched.

Accumulated access, often called privilege creep, is the silent result of many moves without cleanups. Over years, a long-tenured employee can quietly gather the combined access of every role they ever held, which is exactly the concentration an attacker hopes to hijack.

Worked example

An analyst joins in finance, moves to procurement after a year, then to a systems role. If each move only added access, they now hold finance approvals, procurement authority, and system administration at once, a combination no single job needs and no reviewer would grant on purpose. A single compromised session for that one account now spans three sensitive domains. The fix is not heroic: at each move, the mover process removes what the old role required before the new access is granted, so the account always reflects the current job and nothing more.

Note: The leaver process is the one most often neglected and most dangerous when it fails. Time-to-revoke on departure is a metric worth watching closely.
الثاني

الهوية ودورة حياتها

كل قرار وصولٍ يبدأ بهوية، ولكل هويةٍ دورة حياة: تُنشَأ، وتتغيّر مع تغيّر دور الشخص، ويجب إزالتها حين يغادر. وأغلب مشكلات الوصول تعود إلى خطوة دورة حياةٍ أُغفِلت.

الأحداث الحرجة هي الالتحاق والانتقال والمغادرة. فحين يلتحق أحد، ينبغي أن ينال بالضبط ما يحتاجه دوره من وصول، لا أكثر. وحين ينتقل، يُزال القديم مع إضافة الجديد، لا أن يُكدَّس فوقه. وحين يغادر، تُسحَب الصلاحيات فورًا، لأن موظفًا مغادرًا بحسابٍ حيّ خطرٌ قائم لا يحرس شيئًا.

  • الملتحق: امنح الوصول من دورٍ محدَّد، فيبدأ الجديد بمجموعةٍ معلومة دنيا.
  • المنتقل: عدّل الوصول عند تغيّر الدور، بإزالة ما لم يعُد لازمًا لا بمراكمته.
  • المغادر: اسحب الوصول فورًا عند المغادرة، عبر كل نظامٍ مسّته الهوية.

الوصول المتراكم، ويُسمّى غالبًا زحف الصلاحيات، هو الناتج الصامت لانتقالاتٍ كثيرة بلا تنظيف. فعبر السنين قد يجمع موظفٌ طويل الخدمة بهدوءٍ وصولَ كل دورٍ شغله يومًا، وهو بالضبط التركّز الذي يأمل المهاجم اختطافه.

مثال محلول

محلّلٌ يلتحق في المالية، ثم ينتقل للمشتريات بعد عام، ثم لدورٍ تقني. فإن كان كل انتقالٍ يضيف وصولًا فقط، صار يحمل اعتمادات المالية وصلاحية المشتريات وإدارة الأنظمة معًا، تركيبةٌ لا تحتاجها وظيفةٌ واحدة ولا يمنحها مراجعٌ عن قصد. وجلسةٌ واحدة مخترَقة لذلك الحساب تمتدّ الآن عبر ثلاثة مجالاتٍ حسّاسة. والعلاج ليس بطوليًا: عند كل انتقال، تُزيل عملية المنتقل ما تطلّبه الدور القديم قبل منح الجديد، فيعكس الحساب دائمًا الوظيفة الحالية لا أكثر.

ملاحظة: عملية المغادر أكثرها إهمالًا وأخطرها عند الفشل. وزمن السحب عند المغادرة مؤشرٌ يستحق مراقبةً دقيقة.
Three

Authentication

Authentication is proving that a person is who they claim to be. Its strength sets a ceiling on every access decision that follows, because a resource is only as protected as the login in front of it.

Proof draws on factors of different kinds: something you know such as a password, something you have such as a phone or hardware key, and something you are such as a fingerprint. Any single factor can be stolen or guessed, so combining factors, known as multi-factor authentication, is the single highest-value control most organizations can apply. It turns a stolen password from a full compromise into a failed attempt.

Beyond the password

Passwords remain common but are the weakest factor, because people reuse them and attackers harvest them at scale. Modern guidance favors longer passphrases over forced complexity, discourages routine forced rotation that pushes people toward weak patterns, and pushes toward phishing-resistant methods where possible. The direction of travel is to lean less on the secret a user remembers and more on the device they hold.

Assurance rises with independent factors: knowledge + possession + inherence, each hard to steal together
Note: Apply the strongest authentication to the highest-value access first. Requiring a hardware key for administrators buys more safety than tightening every ordinary login.
الثالث

المصادقة

المصادقة إثباتٌ بأن الشخص هو من يدّعي. وقوّتها تضع سقفًا لكل قرار وصولٍ يليها، لأن الموردَ محميٌ بقدر الدخول الذي أمامه فقط.

يستند الإثبات إلى عوامل من أنواعٍ مختلفة: شيءٌ تعرفه ككلمة مرور، وشيءٌ تملكه كهاتفٍ أو مفتاحٍ صلب، وشيءٌ أنت هو كبصمة. وأي عاملٍ مفرد يمكن سرقته أو تخمينه، فجمع العوامل، ويُعرَف بالمصادقة متعددة العوامل، أعلى ضابطٍ قيمةً تستطيع أغلب المنشآت تطبيقه. فهو يحوّل كلمة مرورٍ مسروقة من اختراقٍ كامل إلى محاولةٍ فاشلة.

ما بعد كلمة المرور

تبقى كلمات المرور شائعة لكنها أضعف عامل، لأن الناس يُعيدون استخدامها والمهاجمين يحصدونها بالجملة. والإرشاد الحديث يفضّل عبارات المرور الأطول على التعقيد القسري، ويثبّط التدوير القسري الروتيني الذي يدفع الناس لأنماطٍ ضعيفة، ويدفع نحو طرقٍ مقاوِمة للتصيّد حيثما أمكن. واتجاه السير هو الاتّكاء أقل على السرّ الذي يحفظه المستخدم وأكثر على الجهاز الذي يحمله.

يرتفع التوكيد بالعوامل المستقلّة: معرفة + حيازة + سمة ذاتية، يصعب سرقتها معًا
ملاحظة: طبّق أقوى مصادقةٍ على أعلى وصولٍ قيمةً أولًا. فاشتراط مفتاحٍ صلب للمسؤولين الإداريين يشتري أمانًا أكثر من تشديد كل دخولٍ عادي.
Four

Authorization & Least Privilege

Once identity is proven, authorization decides what that identity may do. The governing principle is least privilege: grant only the access a role genuinely needs, and nothing more, because every unused permission is a risk with no benefit.

Role-based access is the practical way to apply this at scale. Instead of granting permissions to people one by one, you define roles that bundle the access a job needs, then assign people to roles. This makes access reviewable, because a reviewer can reason about a handful of roles rather than thousands of individual grants, and it makes the joiner and mover processes clean.

Privileged access

The most powerful accounts, administrators and service accounts, deserve the tightest control, because their compromise is the most damaging. Good practice separates everyday work from privileged work, grants elevated access only when needed and for a limited time, and records what privileged accounts do. Standing, always-on administrative rights are a large target that is rarely justified.

Service accounts deserve a special mention because they are so often forgotten. They are non-human identities that let systems talk to each other, they frequently hold broad access, and because no person logs into them, their passwords are rarely changed and their activity is rarely watched. That combination, high privilege and low scrutiny, makes them a favored path for attackers, so they need owners, rotated credentials, and monitoring just like the human accounts, and arguably more.

  • Least privilege: the default is no access, and each grant is justified by need.
  • Role-based access: permissions bundled into roles, people assigned to roles.
  • Separation of duties: no single person can both perform and approve a sensitive action.
  • Just-in-time elevation: raise privilege only when needed, then lower it again.
Note: Separation of duties is a control against both fraud and error. When one person can request, approve, and execute, a single mistake or bad actor has nothing to stop it.
الرابع

التخويل وأقلّ الصلاحية

متى أُثبِتت الهوية، يقرّر التخويل ما يجوز لتلك الهوية فعله. والمبدأ الحاكم هو أقلّ الصلاحية: امنح فقط الوصول الذي يحتاجه الدور فعلًا، لا أكثر، لأن كل صلاحيةٍ غير مستخدَمة خطرٌ بلا فائدة.

الوصول القائم على الأدوار هو الطريقة العملية لتطبيق ذلك على نطاق. فبدل منح الصلاحيات للأشخاص واحدًا واحدًا، تعرّف أدوارًا تحزم الوصول الذي تحتاجه الوظيفة، ثم تُسنِد الأشخاص للأدوار. وهذا يجعل الوصول قابلًا للمراجعة، إذ يستطيع المراجع التفكير في حفنة أدوارٍ لا آلاف المنح الفردية، ويجعل عمليتي الملتحق والمنتقل نظيفتين.

الوصول المميَّز

أقوى الحسابات، المسؤولون الإداريون وحسابات الخدمة، تستحق أشدّ ضبط، لأن اختراقها الأشدّ ضررًا. والممارسة الجيدة تفصل العمل اليومي عن العمل المميَّز، وتمنح الوصول المرتفع عند الحاجة ولوقتٍ محدود، وتسجّل ما تفعله الحسابات المميَّزة. والصلاحيات الإدارية الدائمة المشتغلة دومًا هدفٌ كبير نادرًا ما يُبرَّر.

وتستحق حسابات الخدمة ذكرًا خاصًا لأنها كثيرًا ما تُنسى. فهي هويات غير بشرية تتيح للأنظمة التحادث، وتحمل غالبًا وصولًا واسعًا، ولأن لا شخص يدخل بها، نادرًا ما تُغيَّر كلمات مرورها ونادرًا ما يُراقَب نشاطها. وتلك التركيبة، صلاحيةٌ عالية وتدقيقٌ منخفض، تجعلها طريقًا مفضّلًا للمهاجمين، فتحتاج ملّاكًا وبيانات دخولٍ مُدوَّرة ومراقبةً كالحسابات البشرية تمامًا، بل أكثر.

  • أقلّ الصلاحية: الافتراض لا وصول، وكل منحٍ تبرّره الحاجة.
  • الوصول بالأدوار: صلاحيات محزومة في أدوار، وأشخاص مُسنَدون لأدوار.
  • فصل المهام: لا يستطيع شخصٌ واحد أداء إجراءٍ حسّاس واعتماده معًا.
  • الرفع عند الحاجة: ارفع الصلاحية عند الحاجة فقط، ثم اخفضها ثانيةً.
ملاحظة: فصل المهام ضابطٌ ضد الاحتيال والخطأ معًا. فحين يستطيع شخصٌ الطلب والاعتماد والتنفيذ، لا شيء يوقف خطأً واحدًا أو فاعلًا سيئًا.
Five

Access Review & Recertification

Access granted correctly today drifts out of correctness over time. Recertification is the periodic check that every grant is still justified, and it is the control that catches the privilege creep the lifecycle process misses.

In a recertification cycle, the owner of a system or role reviews who has access and confirms, with evidence of the business need, that each grant should remain. Anything that cannot be justified is removed. The discipline that makes this real is that the reviewer must actively confirm each access, because a review where everyone clicks approve without looking is worse than none, since it launders stale access as if it were checked.

Two design choices make recertification effective rather than ritual. First, present the reviewer with the smallest useful unit, one person's access or one role's members, with enough context to judge, rather than a spreadsheet of thousands of lines that guarantees rubber-stamping. Second, make removal the easy default and retention the deliberate choice, so an access that the reviewer cannot quickly justify falls away rather than surviving by inertia. Framed this way, the review actively shrinks access over time instead of merely blessing whatever exists.

  • Scope: the accounts, roles, and privileged access to be reviewed each cycle.
  • Reviewer: the owner who genuinely knows whether the access is still needed.
  • Evidence: the justification retained, so the decision can be audited later.
  • Action: prompt removal of anything not reconfirmed.
Note: Focus the deepest reviews on privileged and sensitive access. A yearly full review plus more frequent reviews of the riskiest access is a practical balance.
الخامس

مراجعة الوصول وإعادة الاعتماد

وصولٌ مُنِح صحيحًا اليوم ينحرف عن الصحّة مع الوقت. وإعادة الاعتماد هي الفحص الدوري بأن كل منحٍ ما زال مبرَّرًا، وهي الضابط الذي يلتقط زحف الصلاحيات الذي تُغفِله عملية دورة الحياة.

في دورة إعادة الاعتماد، يراجع مالك النظام أو الدور مَن لديه وصول ويؤكّد، بدليل الحاجة العملية، أن كل منحٍ ينبغي أن يبقى. وما لا يمكن تبريره يُزال. والانضباط الذي يجعل هذا حقيقيًا أن على المراجع تأكيد كل وصولٍ فعليًا، لأن مراجعةً يضغط فيها الجميع «اعتماد» دون نظرٍ أسوأ من عدمها، إذ تُبيّض وصولًا قديمًا وكأنه فُحِص.

خياران تصميميان يجعلان إعادة الاعتماد فعّالة لا طقسًا. الأول: اعرض على المراجع أصغر وحدةٍ مفيدة، وصولَ شخصٍ واحد أو أعضاء دورٍ واحد، بسياقٍ يكفي للحكم، لا جدولًا بآلاف السطور يضمن الختم الآلي. والثاني: اجعل الإزالة هي الافتراض السهل والإبقاء هو الاختيار المتعمَّد، فيسقط وصولٌ لا يستطيع المراجع تبريره سريعًا بدل أن يبقى بالقصور الذاتي. وبهذا التأطير تُقلّص المراجعة الوصول فعليًا عبر الزمن بدل مباركة ما هو قائم.

  • النطاق: الحسابات والأدوار والوصول المميَّز الذي يُراجَع كل دورة.
  • المراجع: المالك الذي يعرف حقًا هل ما زال الوصول لازمًا.
  • الدليل: المبرّر محفوظًا، ليُدقَّق القرار لاحقًا.
  • الإجراء: إزالةٌ فورية لكل ما لم يُعَد تأكيده.
ملاحظة: ركّز أعمق المراجعات على الوصول المميَّز والحسّاس. فمراجعةٌ كاملة سنوية مع مراجعاتٍ أكثر تكرارًا لأخطر الوصول توازنٌ عملي.
Six

Supporting Security Policies

Identity controls rest on a small set of clear policies that state the rules everyone must follow. A policy is not paperwork for its own sake, it is the agreed answer to a recurring question, written down so it is applied the same way every time.

The policies most tied to access are the account and password rules, the acceptable-use rules, and the third-party access rules. Each turns a principle into a specific, enforceable requirement, and each names an owner responsible for keeping it current. A policy nobody owns is a policy that quietly goes out of date.

  • Access & password policy: how accounts are created, secured, and closed, and the authentication required.
  • Acceptable use: what users may and may not do with the access they are given.
  • Privileged access policy: the stricter rules for administrative and service accounts.
  • Third-party access: how external parties are granted, monitored, and removed.

Policies work only when people know them, which is why awareness matters as much as the document. A rule that lives in a folder nobody opens protects nothing, so the policy has to be communicated, understood, and reinforced.

Note: Keep policies short and specific enough to be followed. A policy that is too long to read is a policy that will be ignored precisely when it is needed.
السادس

السياسات الأمنية المساندة

تستند ضوابط الهوية إلى مجموعةٍ صغيرة من سياساتٍ واضحة تذكر القواعد التي على الجميع اتّباعها. والسياسة ليست ورقًا لذاته، بل الجواب المتّفق عليه لسؤالٍ متكرّر، مكتوبًا ليُطبَّق بالطريقة نفسها كل مرة.

أكثر السياسات ارتباطًا بالوصول هي قواعد الحسابات وكلمات المرور، وقواعد الاستخدام المقبول، وقواعد وصول الأطراف الثالثة. وكلٌّ يحوّل مبدأً إلى متطلبٍ محدَّد قابلٍ للإنفاذ، وكلٌّ يسمّي مالكًا مسؤولًا عن إبقائه محدَّثًا. وسياسةٌ لا يملكها أحد سياسةٌ تتقادم بصمت.

  • سياسة الوصول وكلمات المرور: كيف تُنشَأ الحسابات وتُؤمَّن وتُغلَق، والمصادقة المطلوبة.
  • الاستخدام المقبول: ما يجوز وما لا يجوز للمستخدمين فعله بما مُنِحوه من وصول.
  • سياسة الوصول المميَّز: القواعد الأشدّ للحسابات الإدارية وحسابات الخدمة.
  • وصول الأطراف الثالثة: كيف يُمنَح الخارجيون ويُراقَبون ويُزالون.

لا تعمل السياسات إلا حين يعرفها الناس، ولذا تهمّ التوعية بقدر الوثيقة. فقاعدةٌ تعيش في مجلدٍ لا أحد يفتحه لا تحمي شيئًا، فيجب إبلاغ السياسة وفهمها وترسيخها.

ملاحظة: أبقِ السياسات قصيرة ومحدَّدة بما يكفي لاتّباعها. فسياسةٌ أطول من أن تُقرَأ ستُتجاهَل في اللحظة التي تُحتاج فيها بالضبط.
Seven

Metrics & Assurance

Identity health can be measured, and a few honest metrics tell you whether the controls are actually holding or merely written down. Each should point to a specific fix rather than a general unease.

%
Privileged accounts with multi-factor
Hrs
Mean time to revoke on departure
%
Access recertified on schedule

These are chosen because each reveals a real weakness when it slips. Privileged accounts without strong authentication are the highest-value targets left exposed, a slow time-to-revoke means departed people keep live keys, and overdue recertification means access is drifting unchecked. A dormant-account count is a useful fourth, since unused live accounts are pure attack surface.

Bottom line: get identity right and most other controls get easier, because the attacker's favorite path, a trusted account doing untrusted things, is the one you have closed.
السابع

المؤشرات والضمان

يمكن قياس صحّة الهوية، وبضعة مؤشراتٍ صادقة تخبرك هل الضوابط صامدةٌ فعلًا أم مكتوبةٌ فحسب. وكلٌّ ينبغي أن يشير إلى إصلاحٍ محدَّد لا قلقٍ عام.

%
حسابات مميَّزة بمصادقة متعددة
ساعات
متوسط زمن السحب عند المغادرة
%
وصولٌ أُعيد اعتماده في موعده

اختيرت لأن كلًّا يكشف ضعفًا حقيقيًا حين ينزلق. فحسابات مميَّزة بلا مصادقة قوية هي أعلى الأهداف قيمةً وقد تُركت مكشوفة، وزمن سحبٍ بطيء يعني أن مغادرين يحتفظون بمفاتيح حيّة، وإعادة اعتمادٍ متأخّرة تعني وصولًا ينحرف بلا فحص. وعدّ الحسابات الخاملة رابعٌ مفيد، إذ الحسابات الحيّة غير المستخدَمة سطح هجومٍ صرف.

الخلاصة: أتقِن الهوية تسهُل أغلب الضوابط الأخرى، لأن طريق المهاجم المفضّل، حسابٌ موثوق يفعل أشياء غير موثوقة، هو الذي أغلقته.
Eight

Key Takeaways & References

Identity and access management protects everything else by ensuring only the right people reach the right resources, proven, granted least, and reviewed.

  • Manage the identity lifecycle end to end, and make the leaver process fast and complete.
  • Require strong, phishing-resistant authentication, hardest on the highest-value access.
  • Grant least privilege through roles, and tightly control privileged access.
  • Recertify access on a cadence, with reviewers who actively confirm each grant.
  • Back it all with short, owned policies and a few honest metrics.

References

الثامن

الخلاصات والمراجع

إدارة الهوية والصلاحيات تحمي كل ما عداها بضمان أن الأشخاص الصحيحين فقط يصلون إلى الموارد الصحيحة، بإثباتٍ وأقلّ صلاحية ومراجعة.

  • أدِر دورة حياة الهوية من طرفٍ لطرف، واجعل عملية المغادر سريعة كاملة.
  • اشترِط مصادقةً قوية مقاوِمة للتصيّد، أشدّها على أعلى وصولٍ قيمةً.
  • امنح أقلّ صلاحيةٍ عبر الأدوار، واضبط الوصول المميَّز بإحكام.
  • أعِد اعتماد الوصول بدورية، بمراجعين يؤكّدون كل منحٍ فعليًا.
  • اسنِد ذلك كله بسياساتٍ قصيرة مملوكة وبضعة مؤشراتٍ صادقة.

المراجع