Identity and access management is the discipline of making sure the right people, and only the right people, can reach the right resources, for the right reasons, at the right time. It is the control most incidents ultimately turn on, because a stolen or over-privileged identity is the key that opens every other door.
The framework rests on a simple chain: prove who someone is, decide what they may do, grant only that, and check later that the grant is still correct. Break any link and the others weaken, since strong authentication is wasted if everyone is an administrator, and least privilege is meaningless if identities are easy to impersonate.
This framework is reusable for any environment and aligns to recognized guidance, drawing on the digital identity guidance of NIST and the access control controls of established catalogs, without reproducing their text.
إدارة الهوية والصلاحيات انضباطٌ يضمن أن الأشخاص الصحيحين، وهم فقط، يصلون إلى الموارد الصحيحة، لأسبابٍ صحيحة، في الوقت الصحيح. وهي الضابط الذي تدور عليه أغلب الحوادث في النهاية، لأن هويةً مسروقة أو مفرطة الصلاحية هي المفتاح الذي يفتح كل بابٍ آخر.
يقوم الإطار على سلسلةٍ بسيطة: أثبِت من يكون الشخص، وقرّر ما يجوز له، وامنحه ذلك فقط، وتحقّق لاحقًا أن المنح ما زال صحيحًا. واكسِر أي حلقةٍ تضعف الأخرى، فالمصادقة القوية تُهدَر إن كان الجميع مسؤولًا إداريًا، وأقلّ الصلاحية بلا معنى إن كانت الهويات سهلة الانتحال.
هذا الإطار قابل لإعادة الاستخدام لأي بيئة ويتوافق مع الإرشاد المعترف به، مستندًا إلى إرشاد الهوية الرقمية من NIST وضوابط التحكّم بالوصول من الكتالوجات المعتمَدة، دون نسخ نصّها.
Every access decision starts with an identity, and every identity has a lifecycle: it is created, it changes as a person's role changes, and it must be removed when they leave. Most access problems trace back to a lifecycle step that was skipped.
The critical events are joining, moving, and leaving. When someone joins, they should receive exactly the access their role needs, no more. When they move, old access should be removed as new access is added, not simply stacked on top. When they leave, access should be revoked promptly, because a departed employee with a live account is a standing risk that guards nothing.
Accumulated access, often called privilege creep, is the silent result of many moves without cleanups. Over years, a long-tenured employee can quietly gather the combined access of every role they ever held, which is exactly the concentration an attacker hopes to hijack.
An analyst joins in finance, moves to procurement after a year, then to a systems role. If each move only added access, they now hold finance approvals, procurement authority, and system administration at once, a combination no single job needs and no reviewer would grant on purpose. A single compromised session for that one account now spans three sensitive domains. The fix is not heroic: at each move, the mover process removes what the old role required before the new access is granted, so the account always reflects the current job and nothing more.
كل قرار وصولٍ يبدأ بهوية، ولكل هويةٍ دورة حياة: تُنشَأ، وتتغيّر مع تغيّر دور الشخص، ويجب إزالتها حين يغادر. وأغلب مشكلات الوصول تعود إلى خطوة دورة حياةٍ أُغفِلت.
الأحداث الحرجة هي الالتحاق والانتقال والمغادرة. فحين يلتحق أحد، ينبغي أن ينال بالضبط ما يحتاجه دوره من وصول، لا أكثر. وحين ينتقل، يُزال القديم مع إضافة الجديد، لا أن يُكدَّس فوقه. وحين يغادر، تُسحَب الصلاحيات فورًا، لأن موظفًا مغادرًا بحسابٍ حيّ خطرٌ قائم لا يحرس شيئًا.
الوصول المتراكم، ويُسمّى غالبًا زحف الصلاحيات، هو الناتج الصامت لانتقالاتٍ كثيرة بلا تنظيف. فعبر السنين قد يجمع موظفٌ طويل الخدمة بهدوءٍ وصولَ كل دورٍ شغله يومًا، وهو بالضبط التركّز الذي يأمل المهاجم اختطافه.
محلّلٌ يلتحق في المالية، ثم ينتقل للمشتريات بعد عام، ثم لدورٍ تقني. فإن كان كل انتقالٍ يضيف وصولًا فقط، صار يحمل اعتمادات المالية وصلاحية المشتريات وإدارة الأنظمة معًا، تركيبةٌ لا تحتاجها وظيفةٌ واحدة ولا يمنحها مراجعٌ عن قصد. وجلسةٌ واحدة مخترَقة لذلك الحساب تمتدّ الآن عبر ثلاثة مجالاتٍ حسّاسة. والعلاج ليس بطوليًا: عند كل انتقال، تُزيل عملية المنتقل ما تطلّبه الدور القديم قبل منح الجديد، فيعكس الحساب دائمًا الوظيفة الحالية لا أكثر.
Authentication is proving that a person is who they claim to be. Its strength sets a ceiling on every access decision that follows, because a resource is only as protected as the login in front of it.
Proof draws on factors of different kinds: something you know such as a password, something you have such as a phone or hardware key, and something you are such as a fingerprint. Any single factor can be stolen or guessed, so combining factors, known as multi-factor authentication, is the single highest-value control most organizations can apply. It turns a stolen password from a full compromise into a failed attempt.
Passwords remain common but are the weakest factor, because people reuse them and attackers harvest them at scale. Modern guidance favors longer passphrases over forced complexity, discourages routine forced rotation that pushes people toward weak patterns, and pushes toward phishing-resistant methods where possible. The direction of travel is to lean less on the secret a user remembers and more on the device they hold.
المصادقة إثباتٌ بأن الشخص هو من يدّعي. وقوّتها تضع سقفًا لكل قرار وصولٍ يليها، لأن الموردَ محميٌ بقدر الدخول الذي أمامه فقط.
يستند الإثبات إلى عوامل من أنواعٍ مختلفة: شيءٌ تعرفه ككلمة مرور، وشيءٌ تملكه كهاتفٍ أو مفتاحٍ صلب، وشيءٌ أنت هو كبصمة. وأي عاملٍ مفرد يمكن سرقته أو تخمينه، فجمع العوامل، ويُعرَف بالمصادقة متعددة العوامل، أعلى ضابطٍ قيمةً تستطيع أغلب المنشآت تطبيقه. فهو يحوّل كلمة مرورٍ مسروقة من اختراقٍ كامل إلى محاولةٍ فاشلة.
تبقى كلمات المرور شائعة لكنها أضعف عامل، لأن الناس يُعيدون استخدامها والمهاجمين يحصدونها بالجملة. والإرشاد الحديث يفضّل عبارات المرور الأطول على التعقيد القسري، ويثبّط التدوير القسري الروتيني الذي يدفع الناس لأنماطٍ ضعيفة، ويدفع نحو طرقٍ مقاوِمة للتصيّد حيثما أمكن. واتجاه السير هو الاتّكاء أقل على السرّ الذي يحفظه المستخدم وأكثر على الجهاز الذي يحمله.
Once identity is proven, authorization decides what that identity may do. The governing principle is least privilege: grant only the access a role genuinely needs, and nothing more, because every unused permission is a risk with no benefit.
Role-based access is the practical way to apply this at scale. Instead of granting permissions to people one by one, you define roles that bundle the access a job needs, then assign people to roles. This makes access reviewable, because a reviewer can reason about a handful of roles rather than thousands of individual grants, and it makes the joiner and mover processes clean.
The most powerful accounts, administrators and service accounts, deserve the tightest control, because their compromise is the most damaging. Good practice separates everyday work from privileged work, grants elevated access only when needed and for a limited time, and records what privileged accounts do. Standing, always-on administrative rights are a large target that is rarely justified.
Service accounts deserve a special mention because they are so often forgotten. They are non-human identities that let systems talk to each other, they frequently hold broad access, and because no person logs into them, their passwords are rarely changed and their activity is rarely watched. That combination, high privilege and low scrutiny, makes them a favored path for attackers, so they need owners, rotated credentials, and monitoring just like the human accounts, and arguably more.
متى أُثبِتت الهوية، يقرّر التخويل ما يجوز لتلك الهوية فعله. والمبدأ الحاكم هو أقلّ الصلاحية: امنح فقط الوصول الذي يحتاجه الدور فعلًا، لا أكثر، لأن كل صلاحيةٍ غير مستخدَمة خطرٌ بلا فائدة.
الوصول القائم على الأدوار هو الطريقة العملية لتطبيق ذلك على نطاق. فبدل منح الصلاحيات للأشخاص واحدًا واحدًا، تعرّف أدوارًا تحزم الوصول الذي تحتاجه الوظيفة، ثم تُسنِد الأشخاص للأدوار. وهذا يجعل الوصول قابلًا للمراجعة، إذ يستطيع المراجع التفكير في حفنة أدوارٍ لا آلاف المنح الفردية، ويجعل عمليتي الملتحق والمنتقل نظيفتين.
أقوى الحسابات، المسؤولون الإداريون وحسابات الخدمة، تستحق أشدّ ضبط، لأن اختراقها الأشدّ ضررًا. والممارسة الجيدة تفصل العمل اليومي عن العمل المميَّز، وتمنح الوصول المرتفع عند الحاجة ولوقتٍ محدود، وتسجّل ما تفعله الحسابات المميَّزة. والصلاحيات الإدارية الدائمة المشتغلة دومًا هدفٌ كبير نادرًا ما يُبرَّر.
وتستحق حسابات الخدمة ذكرًا خاصًا لأنها كثيرًا ما تُنسى. فهي هويات غير بشرية تتيح للأنظمة التحادث، وتحمل غالبًا وصولًا واسعًا، ولأن لا شخص يدخل بها، نادرًا ما تُغيَّر كلمات مرورها ونادرًا ما يُراقَب نشاطها. وتلك التركيبة، صلاحيةٌ عالية وتدقيقٌ منخفض، تجعلها طريقًا مفضّلًا للمهاجمين، فتحتاج ملّاكًا وبيانات دخولٍ مُدوَّرة ومراقبةً كالحسابات البشرية تمامًا، بل أكثر.
Access granted correctly today drifts out of correctness over time. Recertification is the periodic check that every grant is still justified, and it is the control that catches the privilege creep the lifecycle process misses.
In a recertification cycle, the owner of a system or role reviews who has access and confirms, with evidence of the business need, that each grant should remain. Anything that cannot be justified is removed. The discipline that makes this real is that the reviewer must actively confirm each access, because a review where everyone clicks approve without looking is worse than none, since it launders stale access as if it were checked.
Two design choices make recertification effective rather than ritual. First, present the reviewer with the smallest useful unit, one person's access or one role's members, with enough context to judge, rather than a spreadsheet of thousands of lines that guarantees rubber-stamping. Second, make removal the easy default and retention the deliberate choice, so an access that the reviewer cannot quickly justify falls away rather than surviving by inertia. Framed this way, the review actively shrinks access over time instead of merely blessing whatever exists.
وصولٌ مُنِح صحيحًا اليوم ينحرف عن الصحّة مع الوقت. وإعادة الاعتماد هي الفحص الدوري بأن كل منحٍ ما زال مبرَّرًا، وهي الضابط الذي يلتقط زحف الصلاحيات الذي تُغفِله عملية دورة الحياة.
في دورة إعادة الاعتماد، يراجع مالك النظام أو الدور مَن لديه وصول ويؤكّد، بدليل الحاجة العملية، أن كل منحٍ ينبغي أن يبقى. وما لا يمكن تبريره يُزال. والانضباط الذي يجعل هذا حقيقيًا أن على المراجع تأكيد كل وصولٍ فعليًا، لأن مراجعةً يضغط فيها الجميع «اعتماد» دون نظرٍ أسوأ من عدمها، إذ تُبيّض وصولًا قديمًا وكأنه فُحِص.
خياران تصميميان يجعلان إعادة الاعتماد فعّالة لا طقسًا. الأول: اعرض على المراجع أصغر وحدةٍ مفيدة، وصولَ شخصٍ واحد أو أعضاء دورٍ واحد، بسياقٍ يكفي للحكم، لا جدولًا بآلاف السطور يضمن الختم الآلي. والثاني: اجعل الإزالة هي الافتراض السهل والإبقاء هو الاختيار المتعمَّد، فيسقط وصولٌ لا يستطيع المراجع تبريره سريعًا بدل أن يبقى بالقصور الذاتي. وبهذا التأطير تُقلّص المراجعة الوصول فعليًا عبر الزمن بدل مباركة ما هو قائم.
Identity controls rest on a small set of clear policies that state the rules everyone must follow. A policy is not paperwork for its own sake, it is the agreed answer to a recurring question, written down so it is applied the same way every time.
The policies most tied to access are the account and password rules, the acceptable-use rules, and the third-party access rules. Each turns a principle into a specific, enforceable requirement, and each names an owner responsible for keeping it current. A policy nobody owns is a policy that quietly goes out of date.
Policies work only when people know them, which is why awareness matters as much as the document. A rule that lives in a folder nobody opens protects nothing, so the policy has to be communicated, understood, and reinforced.
تستند ضوابط الهوية إلى مجموعةٍ صغيرة من سياساتٍ واضحة تذكر القواعد التي على الجميع اتّباعها. والسياسة ليست ورقًا لذاته، بل الجواب المتّفق عليه لسؤالٍ متكرّر، مكتوبًا ليُطبَّق بالطريقة نفسها كل مرة.
أكثر السياسات ارتباطًا بالوصول هي قواعد الحسابات وكلمات المرور، وقواعد الاستخدام المقبول، وقواعد وصول الأطراف الثالثة. وكلٌّ يحوّل مبدأً إلى متطلبٍ محدَّد قابلٍ للإنفاذ، وكلٌّ يسمّي مالكًا مسؤولًا عن إبقائه محدَّثًا. وسياسةٌ لا يملكها أحد سياسةٌ تتقادم بصمت.
لا تعمل السياسات إلا حين يعرفها الناس، ولذا تهمّ التوعية بقدر الوثيقة. فقاعدةٌ تعيش في مجلدٍ لا أحد يفتحه لا تحمي شيئًا، فيجب إبلاغ السياسة وفهمها وترسيخها.
Identity health can be measured, and a few honest metrics tell you whether the controls are actually holding or merely written down. Each should point to a specific fix rather than a general unease.
These are chosen because each reveals a real weakness when it slips. Privileged accounts without strong authentication are the highest-value targets left exposed, a slow time-to-revoke means departed people keep live keys, and overdue recertification means access is drifting unchecked. A dormant-account count is a useful fourth, since unused live accounts are pure attack surface.
يمكن قياس صحّة الهوية، وبضعة مؤشراتٍ صادقة تخبرك هل الضوابط صامدةٌ فعلًا أم مكتوبةٌ فحسب. وكلٌّ ينبغي أن يشير إلى إصلاحٍ محدَّد لا قلقٍ عام.
اختيرت لأن كلًّا يكشف ضعفًا حقيقيًا حين ينزلق. فحسابات مميَّزة بلا مصادقة قوية هي أعلى الأهداف قيمةً وقد تُركت مكشوفة، وزمن سحبٍ بطيء يعني أن مغادرين يحتفظون بمفاتيح حيّة، وإعادة اعتمادٍ متأخّرة تعني وصولًا ينحرف بلا فحص. وعدّ الحسابات الخاملة رابعٌ مفيد، إذ الحسابات الحيّة غير المستخدَمة سطح هجومٍ صرف.
Identity and access management protects everything else by ensuring only the right people reach the right resources, proven, granted least, and reviewed.
إدارة الهوية والصلاحيات تحمي كل ما عداها بضمان أن الأشخاص الصحيحين فقط يصلون إلى الموارد الصحيحة، بإثباتٍ وأقلّ صلاحية ومراجعة.