{
  "dataset": "kw-nbcc",
  "title": "Kuwait National Basic Cybersecurity Controls, machine readable corpus",
  "titleAr": "الضوابط الوطنية الأساسية للأمن السيبراني، مدونة مقروءة آليا",
  "sourceVersion": "0.20.3",
  "extracted": "2026-09-04",
  "licence": "MIT",
  "provenance": {
    "note": "Fields under official are quoted from the Annex. Fields under editorial are this project's own analysis and carry no official standing.",
    "noteAr": "الحقول تحت official منقولة من الملحق، أما الحقول تحت editorial فهي تحليل خاص بهذا المشروع ولا تحمل أي صفة رسمية."
  },
  "regulation": {
    "id": "KW-NBCC-2026",
    "decision": "Decision No. 2 of 2026",
    "decisionAr": "قرار رقم (2) لسنة 2026",
    "title": "Kuwait National Basic Cybersecurity Controls",
    "titleAr": "الضوابط الوطنية الأساسية للأمن السيبراني",
    "shortName": "NBCC",
    "authority": "National Cyber Security Center (NCSC)",
    "authorityAr": "المركز الوطني للأمن السيبراني",
    "gazette": "Kuwait Al Youm, issue 1785, year 72",
    "gazetteAr": "جريدة الكويت اليوم، العدد 1785، السنة الثانية والسبعون",
    "signedOn": "2026-03-31",
    "publishedOn": "2026-04-05",
    "complianceWindowMonths": 18,
    "deadline": "2027-10-05",
    "enablingDecree": "Amiri Decree No. 37 of 2022",
    "relatedInstruments": [
      "Decision No. 35 of 2023 (National Cybersecurity Governance Framework)",
      "Decision No. 1 of 2025 (National Data Classification Framework)"
    ],
    "alignedWith": [
      "NIST CSF 2.0",
      "CIS Controls v8.1 Implementation Group 1"
    ],
    "selfAssessmentCadenceMonths": 12,
    "recordRetentionYears": 3,
    "policyReviewYears": 2
  },
  "functions": [
    {
      "id": "GOV",
      "name": "Govern",
      "nameAr": "الحوكمة",
      "blurb": "Establish and monitor the cybersecurity risk management strategy, expectations and policy.",
      "blurbAr": "وضع استراتيجية إدارة مخاطر الأمن السيبراني والتطلعات والسياسات ومتابعتها.",
      "color": "#7c5cff"
    },
    {
      "id": "ID",
      "name": "Identify",
      "nameAr": "التحديد",
      "blurb": "Determine the current cybersecurity risk to the entity.",
      "blurbAr": "تحديد مخاطر الأمن السيبراني الحالية على الجهة.",
      "color": "#0ea5a4"
    },
    {
      "id": "PR",
      "name": "Protect",
      "nameAr": "الحماية",
      "blurb": "Prevent or reduce cybersecurity risks.",
      "blurbAr": "منع مخاطر الأمن السيبراني أو الحد منها.",
      "color": "#2563eb"
    },
    {
      "id": "DE",
      "name": "Detect",
      "nameAr": "الكشف",
      "blurb": "Find and analyze possible cybersecurity attacks and compromise.",
      "blurbAr": "اكتشاف الهجمات السيبرانية المحتملة وحالات الاختراق وتحليلها.",
      "color": "#d97706"
    },
    {
      "id": "RS",
      "name": "Respond",
      "nameAr": "الاستجابة",
      "blurb": "Take action regarding a detected cybersecurity incident.",
      "blurbAr": "اتخاذ الإجراءات اللازمة حيال أي حادث سيبراني مكتشف.",
      "color": "#dc2626"
    },
    {
      "id": "RC",
      "name": "Recover",
      "nameAr": "التعافي",
      "blurb": "Restore assets and operations impacted by a cybersecurity incident.",
      "blurbAr": "استعادة الأصول والعمليات المتأثرة بالحادث السيبراني.",
      "color": "#059669"
    },
    {
      "id": "CLD",
      "name": "Cloud",
      "nameAr": "الحوسبة السحابية",
      "blurb": "Appendix A minimum controls for entities consuming public cloud services.",
      "blurbAr": "الحد الأدنى من ضوابط الملحق أ للجهات التي تستخدم خدمات الحوسبة السحابية العامة.",
      "color": "#0891b2"
    }
  ],
  "frameworks": {
    "csf": {
      "key": "csf",
      "name": "NIST Cybersecurity Framework 2.0",
      "shortName": "NIST CSF 2.0",
      "unit": "subcategory",
      "unitPlural": "subcategories",
      "official": true,
      "note": "Named in Section 1 of the Annex as an alignment reference. Section 5 groups the baseline by CSF function."
    },
    "cis": {
      "key": "cis",
      "name": "CIS Controls v8.1, Implementation Group 1",
      "shortName": "CIS v8.1 IG1",
      "unit": "safeguard",
      "unitPlural": "safeguards",
      "official": true,
      "note": "Named in Section 1 of the Annex as an alignment reference."
    },
    "iso": {
      "key": "iso",
      "name": "ISO/IEC 27001:2022 Annex A",
      "shortName": "ISO 27001:2022",
      "unit": "control",
      "unitPlural": "controls",
      "official": false,
      "note": "Added by this project as a convenience mapping. Not referenced by the Decision."
    }
  },
  "counts": {
    "controls": 44,
    "byFunction": {
      "GOV": 6,
      "ID": 3,
      "PR": 13,
      "DE": 2,
      "RS": 2,
      "RC": 2,
      "CLD": 16
    },
    "withCsf": 44,
    "withCis": 44,
    "withIso": 44,
    "officialPurpose": 28,
    "editorialPurpose": 16
  },
  "controls": [
    {
      "id": "GOV-1",
      "function": "GOV",
      "official": {
        "title": "Governance & Roles",
        "titleAr": "الحوكمة والأدوار",
        "requirement": "The entity MUST designate an employee at manager level or above with overall responsibility for cybersecurity. Define and document roles and responsibilities for information security, IT operations, risk management, data classification, and incident response. Review and update this structure at least annually or when major organizational changes occur.",
        "requirementAr": "على الجهة أن تعين موظفا بدرجة مدير فما فوق يتولى المسؤولية الشاملة عن الأمن السيبراني، وأن تحدد وتوثق الأدوار والمسؤوليات الخاصة بأمن المعلومات وعمليات تقنية المعلومات وإدارة المخاطر وتصنيف البيانات والاستجابة للحوادث، ثم تراجع هذا الهيكل وتحدثه سنويا على الأقل أو عند وقوع تغييرات تنظيمية جوهرية.",
        "purpose": "Establish clear accountability for cybersecurity.",
        "purposeAr": "ترسيخ مساءلة واضحة عن الأمن السيبراني."
      },
      "editorial": {
        "purpose": null,
        "purposeAr": null,
        "checks": [
          "An employee at manager level or above is formally designated with overall responsibility for cybersecurity.",
          "The designation is documented and traceable to a signed appointment or equivalent record.",
          "Roles and responsibilities are documented for information security.",
          "Roles and responsibilities are documented for IT operations.",
          "Roles and responsibilities are documented for risk management.",
          "Roles and responsibilities are documented for data classification.",
          "Roles and responsibilities are documented for incident response.",
          "The role structure is reviewed and updated at least annually.",
          "The role structure is reviewed after any major organizational change."
        ],
        "checksAr": [
          "يعين موظف بدرجة مدير فما فوق تعيينا رسميا ليتولى المسؤولية الشاملة عن الأمن السيبراني.",
          "التعيين موثق ويمكن تتبعه إلى كتاب تكليف موقع أو ما يقوم مقامه.",
          "الأدوار والمسؤوليات موثقة لأمن المعلومات.",
          "الأدوار والمسؤوليات موثقة لعمليات تقنية المعلومات.",
          "الأدوار والمسؤوليات موثقة لإدارة المخاطر.",
          "الأدوار والمسؤوليات موثقة لتصنيف البيانات.",
          "الأدوار والمسؤوليات موثقة للاستجابة للحوادث.",
          "هيكل الأدوار يراجع ويحدث سنويا على الأقل.",
          "هيكل الأدوار يراجع عقب أي تغيير تنظيمي جوهري."
        ],
        "evidence": [
          "Signed appointment letter or decision naming the cybersecurity lead",
          "RACI matrix or roles and responsibilities document",
          "Organizational chart showing the reporting line of the cybersecurity function",
          "Dated record of the most recent annual review"
        ],
        "evidenceAr": [
          "كتاب تكليف أو قرار موقع يسمي المسؤول عن الأمن السيبراني",
          "مصفوفة مسؤوليات أو وثيقة أدوار ومسؤوليات",
          "هيكل تنظيمي يبين خط ارتباط وظيفة الأمن السيبراني",
          "محضر مؤرخ لآخر مراجعة سنوية"
        ],
        "cadence": "annual",
        "effort": "low",
        "phase": 1,
        "beyondAnnex": [
          1
        ]
      },
      "appliesWhen": [],
      "crosswalk": {
        "csf": [
          "GV.RR-01",
          "GV.RR-02"
        ],
        "cis": [
          "17.1"
        ],
        "iso": [
          "A.5.2",
          "A.5.4"
        ]
      }
    },
    {
      "id": "GOV-2",
      "function": "GOV",
      "official": {
        "title": "Policies & Exception Management",
        "titleAr": "السياسات وإدارة الاستثناءات",
        "requirement": "Maintain core written policies that, at minimum, cover: acceptable use, Secure Configuration, data classification, access control, backup & recovery, incident response, and third-party / service provider security. Policies SHOULD be approved by management and reviewed at least every two years. Any deviations MUST follow a simple exception process with documented risk acceptance and an expiry date.",
        "requirementAr": "تحفظ الجهة سياسات مكتوبة أساسية تغطي كحد أدنى الاستخدام المقبول والتهيئة الآمنة وتصنيف البيانات والتحكم في الوصول والنسخ الاحتياطي والاستعادة والاستجابة للحوادث وأمن الأطراف الثالثة ومزودي الخدمة، وينبغي أن تعتمد هذه السياسات من الإدارة وأن تراجع كل سنتين على الأقل، أما أي خروج عنها فيجب أن يمر بآلية استثناء مبسطة تتضمن قبولا موثقا للمخاطر وتاريخ انتهاء.",
        "purpose": "Ensure behavior and decisions are guided by documented, approved rules.",
        "purposeAr": "ضمان استناد السلوكيات والقرارات إلى قواعد موثقة ومعتمدة."
      },
      "editorial": {
        "purpose": null,
        "purposeAr": null,
        "checks": [
          "A written acceptable use policy exists.",
          "A written secure configuration policy exists.",
          "A written data classification policy exists.",
          "A written access control policy exists.",
          "A written backup and recovery policy exists.",
          "A written incident response policy exists.",
          "A written third party and service provider security policy exists.",
          "Policies are approved by management.",
          "Policies are reviewed at least every two years.",
          "A documented exception process exists for deviations from policy.",
          "Every recorded exception carries a documented risk acceptance.",
          "Every recorded exception carries an expiry date."
        ],
        "checksAr": [
          "توجد سياسة مكتوبة للاستخدام المقبول.",
          "توجد سياسة مكتوبة للتهيئة الآمنة.",
          "توجد سياسة مكتوبة لتصنيف البيانات.",
          "توجد سياسة مكتوبة للتحكم في الوصول.",
          "توجد سياسة مكتوبة للنسخ الاحتياطي والاستعادة.",
          "توجد سياسة مكتوبة للاستجابة للحوادث.",
          "توجد سياسة مكتوبة لأمن الأطراف الثالثة ومزودي الخدمة.",
          "السياسات معتمدة من الإدارة.",
          "تراجع السياسات كل سنتين على الأقل.",
          "توجد آلية موثقة للاستثناء من السياسات.",
          "يحمل كل استثناء مسجل قبولا موثقا للمخاطر.",
          "يحمل كل استثناء مسجل تاريخ انتهاء."
        ],
        "evidence": [
          "Policy set with version history and approval signatures",
          "Policy review calendar showing the two year cycle",
          "Exception register listing scope, owner, risk acceptance and expiry",
          "Compensating control notes attached to open exceptions"
        ],
        "evidenceAr": [
          "حزمة السياسات مع سجل الإصدارات وتواقيع الاعتماد",
          "جدول مراجعة السياسات يبين دورة السنتين",
          "سجل الاستثناءات يبين النطاق والمسؤول وقبول المخاطر وتاريخ الانتهاء",
          "ملاحظات الضوابط التعويضية المرفقة بالاستثناءات المفتوحة"
        ],
        "cadence": "biennial",
        "effort": "medium",
        "phase": 1,
        "beyondAnnex": []
      },
      "appliesWhen": [],
      "crosswalk": {
        "csf": [
          "GV.PO-01",
          "GV.PO-02"
        ],
        "cis": [
          "4.1",
          "14.1"
        ],
        "iso": [
          "A.5.1",
          "A.5.37"
        ]
      }
    },
    {
      "id": "GOV-3",
      "function": "GOV",
      "official": {
        "title": "Data Classification & Sovereignty",
        "titleAr": "تصنيف البيانات وسيادتها",
        "requirement": "Implement a data classification program aligned with the National Data Classification Framework, using at least Sensitive, Restricted, and Public categories, with clear criteria and examples. Issue a Data Classification Policy/Document approved by senior management and submitted to NCSC for approval, in accordance with Decision No. 1 of 2025. Tag or label data (and related systems/records) with its classification and ensure protection measures increase with sensitivity (for example: stronger access controls and encryption for Sensitive data). Storing or processing Sensitive data outside Kuwait MUST follow the national approval process and receive explicit NCSC approval before use (per applicable regulations).",
        "requirementAr": "تطبق الجهة برنامجا لتصنيف البيانات موائما للإطار الوطني لتصنيف البيانات يستخدم فئات حساس ومقيد وعام على الأقل بمعايير وأمثلة واضحة، وتصدر سياسة أو وثيقة لتصنيف البيانات معتمدة من الإدارة العليا ومرفوعة إلى المركز لاعتمادها وفقا للقرار رقم 1 لسنة 2025، ثم توسم البيانات والأنظمة والسجلات المرتبطة بها بتصنيفها وتضمن تصاعد تدابير الحماية مع درجة الحساسية، ومن ذلك مثلا ضوابط وصول وتشفير أقوى للبيانات الحساسة، أما حفظ البيانات الحساسة أو معالجتها خارج الكويت فيجب أن يتبع آلية الاعتماد الوطنية وأن يحصل على موافقة صريحة من المركز قبل الاستخدام وفق اللوائح المعمول بها.",
        "purpose": "Ensure data is handled according to its sensitivity and legal requirements.",
        "purposeAr": "ضمان التعامل مع البيانات وفق درجة حساسيتها ومتطلباتها القانونية."
      },
      "editorial": {
        "purpose": null,
        "purposeAr": null,
        "checks": [
          "A data classification program is implemented and aligned with the National Data Classification Framework.",
          "The scheme uses at least the Sensitive, Restricted and Public categories.",
          "Classification criteria and worked examples are documented.",
          "A Data Classification Policy or Document is approved by senior management.",
          "The Data Classification Document has been submitted to NCSC for approval under Decision No. 1 of 2025.",
          "Data is tagged or labelled with its classification.",
          "Related systems and records carry the classification of the data they hold.",
          "Protection measures demonstrably increase with sensitivity.",
          "Sensitive data receives stronger access controls and encryption than lower tiers.",
          "Any storage or processing of Sensitive data outside Kuwait has explicit prior NCSC approval."
        ],
        "checksAr": [
          "يطبق برنامج لتصنيف البيانات موائم للإطار الوطني لتصنيف البيانات.",
          "يستخدم التصنيف فئات حساس ومقيد وعام على الأقل.",
          "معايير التصنيف وأمثلته العملية موثقة.",
          "سياسة أو وثيقة تصنيف البيانات معتمدة من الإدارة العليا.",
          "وثيقة تصنيف البيانات مرفوعة إلى المركز لاعتمادها وفق القرار رقم 1 لسنة 2025.",
          "البيانات موسومة بتصنيفها.",
          "تحمل الأنظمة والسجلات المرتبطة تصنيف البيانات التي تحتويها.",
          "تتصاعد تدابير الحماية بوضوح مع درجة الحساسية.",
          "تحظى البيانات الحساسة بضوابط وصول وتشفير أقوى من الفئات الأدنى.",
          "أي حفظ أو معالجة للبيانات الحساسة خارج الكويت له موافقة مسبقة صريحة من المركز."
        ],
        "evidence": [
          "Approved Data Classification Policy with senior management signature",
          "Proof of submission to NCSC and any approval response",
          "Sample labelled records, file shares or database catalogues",
          "Control matrix showing measures applied per classification tier",
          "Approval file for every offshore location holding Sensitive data"
        ],
        "evidenceAr": [
          "سياسة تصنيف البيانات المعتمدة بتوقيع الإدارة العليا",
          "ما يثبت الرفع إلى المركز وأي رد بالاعتماد",
          "عينات من سجلات أو مجلدات أو فهارس قواعد بيانات موسومة",
          "مصفوفة ضوابط تبين التدابير المطبقة لكل فئة تصنيف",
          "ملف الموافقة لكل موقع خارج الكويت يحتفظ ببيانات حساسة"
        ],
        "cadence": "annual",
        "effort": "high",
        "phase": 1,
        "beyondAnnex": []
      },
      "appliesWhen": [],
      "crosswalk": {
        "csf": [
          "ID.AM-07",
          "GV.PO-01"
        ],
        "cis": [
          "3.1",
          "3.2",
          "3.7"
        ],
        "iso": [
          "A.5.12",
          "A.5.13",
          "A.5.34"
        ]
      }
    },
    {
      "id": "GOV-4",
      "function": "GOV",
      "official": {
        "title": "Kuwaitization & Vetting for Cyber Roles",
        "titleAr": "التكويت والمسح الأمني للأدوار السيبرانية",
        "requirement": "For key cybersecurity roles (e.g., SOC analysts, administrators, incident responders), prioritize qualified Kuwaiti nationals where feasible and consistent with national HR frameworks and local laws and regulations. For staff in such sensitive roles, perform basic pre-employment screening (e.g., identity verification, employment history, conflict-of-interest checks) in line with applicable laws and HR policies. Maintain a simple list of designated \"sensitive cyber roles\" and ensure screening is documented.",
        "requirementAr": "في الأدوار السيبرانية الرئيسية، ومنها مثلا محللو مركز العمليات الأمنية ومسؤولو الأنظمة والمستجيبون للحوادث، تعطى الأولوية للكوادر الكويتية المؤهلة متى كان ذلك ممكنا وبما يتسق مع أطر الموارد البشرية الوطنية والقوانين واللوائح المحلية، ويجرى للعاملين في هذه الأدوار الحساسة مسح أمني أساسي قبل التعيين يشمل مثلا التحقق من الهوية والتاريخ الوظيفي وتعارض المصالح بما يتفق مع القوانين وسياسات الموارد البشرية السارية، كما تحفظ قائمة مبسطة بالأدوار السيبرانية الحساسة المحددة مع توثيق عمليات المسح الأمني.",
        "purpose": "Support national capacity building and reduce insider risk in critical cyber roles.",
        "purposeAr": "دعم بناء القدرات الوطنية والحد من مخاطر التهديد الداخلي في الأدوار السيبرانية الحرجة."
      },
      "editorial": {
        "purpose": null,
        "purposeAr": null,
        "checks": [
          "Qualified Kuwaiti nationals are prioritized for key cybersecurity roles where feasible.",
          "The prioritization approach is consistent with national HR frameworks and local law.",
          "A list of designated sensitive cyber roles is maintained.",
          "Identity verification is performed before hire into sensitive cyber roles.",
          "Employment history is verified before hire into sensitive cyber roles.",
          "Conflict of interest checks are performed before hire into sensitive cyber roles.",
          "Screening outcomes are documented and retained."
        ],
        "checksAr": [
          "تعطى الكوادر الكويتية المؤهلة الأولوية في الأدوار السيبرانية الرئيسية متى أمكن.",
          "نهج الأولوية متسق مع أطر الموارد البشرية الوطنية والقوانين المحلية.",
          "تحفظ قائمة بالأدوار السيبرانية الحساسة المحددة.",
          "يجرى مسح أمني للهوية قبل التعيين في الأدوار السيبرانية الحساسة.",
          "يجرى مسح أمني للتاريخ الوظيفي قبل التعيين في الأدوار السيبرانية الحساسة.",
          "يجرى مسح أمني لتعارض المصالح قبل التعيين في الأدوار السيبرانية الحساسة.",
          "نتائج المسح الأمني موثقة ومحفوظة."
        ],
        "evidence": [
          "Register of designated sensitive cyber roles",
          "Screening records held per role holder in line with HR policy",
          "Recruitment policy clause covering national prioritization",
          "Hiring file samples showing completed checks"
        ],
        "evidenceAr": [
          "سجل الأدوار السيبرانية الحساسة المحددة",
          "سجلات المسح الأمني المحفوظة لكل شاغل دور وفق سياسة الموارد البشرية",
          "بند في سياسة التوظيف يغطي أولوية الكوادر الوطنية",
          "عينات من ملفات التعيين تبين استكمال عمليات المسح الأمني"
        ],
        "cadence": "per hire",
        "effort": "low",
        "phase": 2,
        "beyondAnnex": []
      },
      "appliesWhen": [],
      "crosswalk": {
        "csf": [
          "GV.RR-04",
          "PR.AA-01"
        ],
        "cis": [
          "14.1"
        ],
        "iso": [
          "A.6.1",
          "A.6.2",
          "A.6.6"
        ]
      }
    },
    {
      "id": "GOV-5",
      "function": "GOV",
      "official": {
        "title": "Periodic Self-Assessment & Continuous Improvement",
        "titleAr": "التقييم الذاتي الدوري والتحسين المستمر",
        "requirement": "At least once per year, complete a self-assessment against this baseline using an NCSC-issued or NCSC-approved checklist. Document the results, key gaps, actions, and target dates. Retain the record for at least three years and make it available to NCSC upon request. Use major incidents or audits to update priorities.",
        "requirementAr": "تستكمل الجهة مرة واحدة سنويا على الأقل تقييما ذاتيا مقابل هذه الضوابط باستخدام قائمة تحقق صادرة عن المركز أو معتمدة منه، وتوثق النتائج والفجوات الرئيسية والإجراءات والتواريخ المستهدفة، ثم تحفظ السجل ثلاث سنوات على الأقل وتتيحه للمركز عند الطلب، وتستفيد من الحوادث الكبرى وعمليات التدقيق في تحديث الأولويات.",
        "purpose": "Provide a minimal mechanism to measure implementation of this baseline.",
        "purposeAr": "توفير آلية بسيطة لقياس مدى تطبيق هذه الضوابط."
      },
      "editorial": {
        "purpose": null,
        "purposeAr": null,
        "checks": [
          "A self assessment against the baseline is completed at least once per year.",
          "The self assessment uses an NCSC issued or NCSC approved checklist.",
          "Results are documented.",
          "Key gaps are documented.",
          "Remediation actions are documented.",
          "Target dates are recorded against each action.",
          "Assessment records are retained for at least three years.",
          "Records can be produced for NCSC on request.",
          "Major incidents and audit findings feed back into assessment priorities."
        ],
        "checksAr": [
          "يستكمل تقييم ذاتي مقابل الضوابط مرة واحدة سنويا على الأقل.",
          "يستخدم التقييم الذاتي قائمة تحقق صادرة عن المركز أو معتمدة منه.",
          "النتائج موثقة.",
          "الفجوات الرئيسية موثقة.",
          "إجراءات المعالجة موثقة.",
          "تواريخ مستهدفة مسجلة لكل إجراء.",
          "سجلات التقييم محفوظة ثلاث سنوات على الأقل.",
          "يمكن تقديم السجلات للمركز عند الطلب.",
          "تغذي الحوادث الكبرى وملاحظات التدقيق أولويات التقييم."
        ],
        "evidence": [
          "Completed self assessment for the current year",
          "Gap and action register with owners and target dates",
          "Retention proof covering the last three annual cycles",
          "Change log showing priorities updated after an incident or audit"
        ],
        "evidenceAr": [
          "التقييم الذاتي المكتمل للسنة الحالية",
          "سجل الفجوات والإجراءات مع المسؤولين والتواريخ المستهدفة",
          "ما يثبت الحفظ لآخر ثلاث دورات سنوية",
          "سجل تغيير يبين تحديث الأولويات بعد حادث أو تدقيق"
        ],
        "cadence": "annual",
        "effort": "medium",
        "phase": 1,
        "beyondAnnex": []
      },
      "appliesWhen": [],
      "crosswalk": {
        "csf": [
          "GV.OV-01",
          "GV.OV-03",
          "ID.IM-02"
        ],
        "cis": [
          "17.4"
        ],
        "iso": [
          "A.5.35",
          "A.5.36"
        ]
      }
    },
    {
      "id": "GOV-6",
      "function": "GOV",
      "official": {
        "title": "Service Provider & Outsourcing Governance",
        "titleAr": "حوكمة مزودي الخدمة والإسناد الخارجي",
        "requirement": "Establish and maintain an inventory of service providers (including cloud/managed services), including classification and an entity contact for each provider; review at least annually or upon significant change.\n• For service providers handling Sensitive data or supporting critical services, document the service scope and shared responsibilities for protecting the service and data.\n• Ensure incident response contact information includes relevant service providers, and define incident reporting timeframes and mechanisms for provider-related incidents.\n• For offboarding/termination, ensure required actions are performed to remove access and handle data appropriately, retaining evidence where applicable.",
        "requirementAr": "تنشئ الجهة حصرا لمزودي الخدمة يشمل الخدمات السحابية والمدارة وتحفظه، ويتضمن تصنيفا وجهة اتصال داخل الجهة لكل مزود، ويراجع سنويا على الأقل أو عند أي تغيير جوهري.\n• وبالنسبة لمزودي الخدمة الذين يتعاملون مع بيانات حساسة أو يدعمون خدمات حرجة، يوثق نطاق الخدمة والمسؤوليات المشتركة عن حماية الخدمة والبيانات.\n• وتضمن الجهة أن تشمل بيانات الاتصال الخاصة بالاستجابة للحوادث مزودي الخدمة المعنيين، وأن تحدد مهل الإبلاغ عن الحوادث المتعلقة بالمزودين وآلياته.\n• وعند إنهاء التعاقد، تتخذ الإجراءات اللازمة لإزالة الوصول والتعامل مع البيانات على النحو المناسب مع حفظ ما يثبت ذلك حيثما أمكن.",
        "purpose": "Manage cybersecurity risk arising from external providers, including cloud.",
        "purposeAr": "إدارة مخاطر الأمن السيبراني الناشئة عن مزودي الخدمات الخارجيين ومنهم مزودو الخدمات السحابية."
      },
      "editorial": {
        "purpose": null,
        "purposeAr": null,
        "checks": [
          "An inventory of service providers exists and covers cloud and managed services.",
          "Each provider record carries a classification.",
          "Each provider record names an entity contact.",
          "The inventory is reviewed at least annually or upon significant change.",
          "Service scope is documented for providers handling Sensitive data or critical services.",
          "Shared responsibilities for protecting the service and data are documented for those providers.",
          "Incident response contact information includes relevant service providers.",
          "Incident reporting timeframes are defined for provider related incidents.",
          "Incident reporting mechanisms are defined for provider related incidents.",
          "Offboarding actions remove provider access.",
          "Offboarding actions handle provider held data appropriately.",
          "Evidence of offboarding actions is retained."
        ],
        "checksAr": [
          "يوجد حصر لمزودي الخدمة يشمل الخدمات السحابية والمدارة.",
          "يحمل كل سجل مزود تصنيفا.",
          "يسمي كل سجل مزود جهة اتصال داخل الجهة.",
          "يراجع الحصر سنويا على الأقل أو عند أي تغيير جوهري.",
          "نطاق الخدمة موثق لمزودي البيانات الحساسة أو الخدمات الحرجة.",
          "المسؤوليات المشتركة عن حماية الخدمة والبيانات موثقة لهؤلاء المزودين.",
          "بيانات الاتصال للاستجابة للحوادث تشمل مزودي الخدمة المعنيين.",
          "مهل الإبلاغ عن الحوادث المتعلقة بالمزودين محددة.",
          "آليات الإبلاغ عن الحوادث المتعلقة بالمزودين محددة.",
          "إجراءات إنهاء التعاقد تزيل وصول المزود.",
          "تعالج إجراءات إنهاء التعاقد البيانات المحفوظة لدى المزود على النحو المناسب.",
          "ما يثبت تنفيذ إجراءات إنهاء التعاقد محفوظ."
        ],
        "evidence": [
          "Service provider register with classification, contact and review date",
          "Scope and shared responsibility documents for critical providers",
          "Incident contact list including provider escalation paths",
          "Completed offboarding checklists with access removal proof"
        ],
        "evidenceAr": [
          "سجل مزودي الخدمة مع التصنيف وجهة الاتصال وتاريخ المراجعة",
          "وثائق النطاق والمسؤوليات المشتركة للمزودين الحرجين",
          "قائمة اتصال الحوادث شاملة مسارات التصعيد لدى المزودين",
          "قوائم تحقق إنهاء التعاقد مكتملة مع ما يثبت إزالة الوصول"
        ],
        "cadence": "annual",
        "effort": "medium",
        "phase": 2,
        "beyondAnnex": []
      },
      "appliesWhen": [],
      "crosswalk": {
        "csf": [
          "GV.SC-04",
          "GV.SC-07",
          "GV.SC-10"
        ],
        "cis": [
          "15.1",
          "15.2",
          "15.4"
        ],
        "iso": [
          "A.5.19",
          "A.5.20",
          "A.5.21",
          "A.5.22"
        ]
      }
    },
    {
      "id": "ID-1",
      "function": "ID",
      "official": {
        "title": "Asset & Service Inventory",
        "titleAr": "حصر الأصول والخدمات",
        "requirement": "Maintain a central electronic inventory of hardware assets (servers, workstations, laptops, network equipment, IoT/OT devices, etc.) and key on-premises services. Record at least: owner, location, purpose, criticality, and lifecycle state (in use, spare, retired). For physical assets, use unique, machine-readable labels (e.g., barcode/QR-style) to support scanning and tracking. At least weekly, review network discovery or similar tools to identify unauthorized devices and either remove, block, or formally approve them.",
        "requirementAr": "تحفظ الجهة حصرا إلكترونيا مركزيا لأصول العتاد، ومنها الخوادم ومحطات العمل والحواسيب المحمولة ومعدات الشبكة وأجهزة إنترنت الأشياء والتقنيات التشغيلية وغيرها، وكذلك الخدمات الرئيسية داخل المقر، ويسجل فيه كحد أدنى المالك والموقع والغرض ودرجة الحرجية وحالة دورة الحياة من حيث كونه قيد الاستخدام أو احتياطيا أو مسحوبا، أما الأصول المادية فتوسم بملصقات فريدة قابلة للقراءة آليا مثل الباركود أو رمز الاستجابة السريعة بما يدعم المسح والتتبع، وتراجع الجهة أسبوعيا على الأقل مخرجات أدوات اكتشاف الشبكة أو ما شابهها لتحديد الأجهزة غير المصرح بها ثم تزيلها أو تحجبها أو تعتمدها رسميا.",
        "purpose": "Maintain an up-to-date view of hardware and key services.",
        "purposeAr": "الاحتفاظ بصورة محدثة عن الأجهزة والخدمات الرئيسية."
      },
      "editorial": {
        "purpose": null,
        "purposeAr": null,
        "checks": [
          "A central electronic inventory of hardware assets is maintained.",
          "The inventory covers servers, workstations, laptops, network equipment and IoT or OT devices.",
          "Key on premises services are recorded in the inventory.",
          "Each asset record captures an owner.",
          "Each asset record captures a location.",
          "Each asset record captures a purpose.",
          "Each asset record captures a criticality rating.",
          "Each asset record captures a lifecycle state of in use, spare or retired.",
          "Physical assets carry unique machine readable labels.",
          "Network discovery output is reviewed at least weekly.",
          "Unauthorized devices found are removed, blocked or formally approved."
        ],
        "checksAr": [
          "يحفظ حصر إلكتروني مركزي لأصول العتاد.",
          "يشمل الحصر الخوادم ومحطات العمل والحواسيب المحمولة ومعدات الشبكة وأجهزة إنترنت الأشياء أو التقنيات التشغيلية.",
          "الخدمات الرئيسية داخل المقر مسجلة في الحصر.",
          "يحمل كل سجل أصل مالكا.",
          "يحمل كل سجل أصل موقعا.",
          "يحمل كل سجل أصل غرضا.",
          "يحمل كل سجل أصل درجة حرجية.",
          "يحمل كل سجل أصل حالة دورة حياة قيد الاستخدام أو احتياطي أو مسحوب.",
          "تحمل الأصول المادية ملصقات فريدة قابلة للقراءة آليا.",
          "تراجع مخرجات اكتشاف الشبكة أسبوعيا على الأقل.",
          "تزال الأجهزة غير المصرح بها المكتشفة أو تحجب أو تعتمد رسميا."
        ],
        "evidence": [
          "Export of the asset inventory showing all mandatory fields",
          "Photographs or samples of asset labels",
          "Weekly discovery review log with disposition per finding",
          "Approval records for devices retained by exception"
        ],
        "evidenceAr": [
          "تصدير لحصر الأصول يبين جميع الحقول الإلزامية",
          "صور أو عينات من ملصقات الأصول",
          "سجل المراجعة الأسبوعية للاكتشاف مع الإجراء المتخذ لكل نتيجة",
          "سجلات اعتماد الأجهزة المبقاة على سبيل الاستثناء"
        ],
        "cadence": "weekly",
        "effort": "high",
        "phase": 1,
        "beyondAnnex": []
      },
      "appliesWhen": [],
      "crosswalk": {
        "csf": [
          "ID.AM-01",
          "ID.AM-02"
        ],
        "cis": [
          "1.1",
          "1.2"
        ],
        "iso": [
          "A.5.9",
          "A.5.10",
          "A.7.9"
        ]
      }
    },
    {
      "id": "ID-2",
      "function": "ID",
      "official": {
        "title": "Software & Provider Inventory",
        "titleAr": "حصر البرمجيات ومزودي الخدمة",
        "requirement": "Maintain a list of authorized software (including version families) and service providers (including cloud and SaaS). At least monthly, review systems for unauthorized software and either remove it or record a documented exception. The list register SHOULD include owner, contact details, service description, criticality, and data sensitivity (which classifications are processed). Review provider information at least annually.",
        "requirementAr": "تحفظ الجهة قائمة بالبرمجيات المصرح بها بما في ذلك عائلات الإصدارات، وقائمة بمزودي الخدمة بما في ذلك الخدمات السحابية والبرمجيات كخدمة، وتراجع الأنظمة شهريا على الأقل بحثا عن برمجيات غير مصرح بها فتزيلها أو تسجل لها استثناء موثقا، وينبغي أن يتضمن السجل المالك وبيانات الاتصال ووصف الخدمة ودرجة الحرجية وحساسية البيانات أي التصنيفات التي تعالج، وتراجع معلومات المزودين سنويا على الأقل.",
        "purpose": "Maintain visibility of software in use and service providers.",
        "purposeAr": "الحفاظ على وضوح الرؤية بشأن البرمجيات المستخدمة ومزودي الخدمات."
      },
      "editorial": {
        "purpose": null,
        "purposeAr": null,
        "checks": [
          "A list of authorized software is maintained.",
          "The software list records version families.",
          "A list of service providers is maintained and includes cloud and SaaS.",
          "Systems are reviewed at least monthly for unauthorized software.",
          "Unauthorized software found is removed or covered by a documented exception.",
          "The register records an owner for each entry.",
          "The register records contact details for each entry.",
          "The register records a service description for each entry.",
          "The register records criticality for each entry.",
          "The register records which data classifications are processed.",
          "Provider information is reviewed at least annually."
        ],
        "checksAr": [
          "تحفظ قائمة بالبرمجيات المصرح بها.",
          "تسجل قائمة البرمجيات عائلات الإصدارات.",
          "تحفظ قائمة بمزودي الخدمة تشمل الخدمات السحابية والبرمجيات كخدمة.",
          "تراجع الأنظمة شهريا على الأقل بحثا عن برمجيات غير مصرح بها.",
          "تزال البرمجيات غير المصرح بها المكتشفة أو يغطيها استثناء موثق.",
          "يبين السجل مالكا لكل مدخل.",
          "يبين السجل بيانات اتصال لكل مدخل.",
          "يبين السجل وصفا للخدمة لكل مدخل.",
          "يبين السجل درجة الحرجية لكل مدخل.",
          "يبين السجل تصنيفات البيانات التي تعالج.",
          "تراجع معلومات المزودين سنويا على الأقل."
        ],
        "evidence": [
          "Authorized software list with version families",
          "Monthly unauthorized software scan reports and dispositions",
          "Provider register with the five register fields populated",
          "Dated annual provider review record"
        ],
        "evidenceAr": [
          "قائمة البرمجيات المصرح بها مع عائلات الإصدارات",
          "تقارير الفحص الشهري للبرمجيات غير المصرح بها والإجراءات المتخذة",
          "سجل المزودين مستوفيا الحقول الخمسة",
          "محضر مؤرخ للمراجعة السنوية للمزودين"
        ],
        "cadence": "monthly",
        "effort": "medium",
        "phase": 1,
        "beyondAnnex": []
      },
      "appliesWhen": [],
      "crosswalk": {
        "csf": [
          "ID.AM-02",
          "GV.SC-04"
        ],
        "cis": [
          "2.1",
          "2.3",
          "15.1"
        ],
        "iso": [
          "A.5.9",
          "A.8.19"
        ]
      }
    },
    {
      "id": "ID-3",
      "function": "ID",
      "official": {
        "title": "Data & Account Inventory",
        "titleAr": "حصر البيانات والحسابات",
        "requirement": "Maintain an inventory of critical and sensitive data sets, including classification, location, and business owner. Maintain an inventory of user and service accounts including privileges and last activity. Review accounts at least quarterly. Disable or remove dormant interactive user accounts that have not been used for 90 days, where the technology supports it. Review service accounts at least quarterly to validate continued business need. Ensure high-risk or privileged accounts are clearly identified.",
        "requirementAr": "تحفظ الجهة حصرا لمجموعات البيانات الحرجة والحساسة يتضمن التصنيف والموقع والمالك من جهة الأعمال، وحصرا لحسابات المستخدمين وحسابات الخدمة يتضمن الصلاحيات وآخر نشاط، وتراجع الحسابات ربع سنويا على الأقل، وتعطل أو تزيل حسابات المستخدمين التفاعلية الخاملة التي لم تستخدم تسعين يوما متى كانت التقنية تدعم ذلك، وتراجع حسابات الخدمة ربع سنويا على الأقل للتحقق من استمرار الحاجة إليها، وتضمن تحديد الحسابات عالية الخطورة أو ذات الصلاحيات تحديدا واضحا.",
        "purpose": "Understand what data and accounts exist and who owns them.",
        "purposeAr": "معرفة البيانات والحسابات القائمة ومالكيها."
      },
      "editorial": {
        "purpose": null,
        "purposeAr": null,
        "checks": [
          "An inventory of critical and sensitive data sets is maintained.",
          "Each data set record carries a classification.",
          "Each data set record carries a location.",
          "Each data set record carries a business owner.",
          "An inventory of user and service accounts is maintained.",
          "Account records capture privileges.",
          "Account records capture last activity.",
          "Accounts are reviewed at least quarterly.",
          "Dormant interactive user accounts unused for 90 days are disabled or removed where supported.",
          "Service accounts are reviewed at least quarterly to validate continued business need.",
          "High risk and privileged accounts are clearly identified."
        ],
        "checksAr": [
          "يحفظ حصر لمجموعات البيانات الحرجة والحساسة.",
          "يحمل كل سجل مجموعة بيانات تصنيفا.",
          "يحمل كل سجل مجموعة بيانات موقعا.",
          "يحمل كل سجل مجموعة بيانات مالكا من جهة الأعمال.",
          "يحفظ حصر لحسابات المستخدمين وحسابات الخدمة.",
          "تبين سجلات الحسابات الصلاحيات.",
          "تبين سجلات الحسابات آخر نشاط.",
          "تراجع الحسابات ربع سنويا على الأقل.",
          "تعطل حسابات المستخدمين التفاعلية الخاملة تسعين يوما أو تزال حيثما أمكن.",
          "تراجع حسابات الخدمة ربع سنويا على الأقل للتحقق من استمرار الحاجة إليها.",
          "الحسابات عالية الخطورة وذات الصلاحيات محددة بوضوح."
        ],
        "evidence": [
          "Data set inventory export with classification, location and owner",
          "Account inventory export with privilege and last logon columns",
          "Quarterly account review sign off",
          "Report of accounts disabled under the 90 day dormancy rule"
        ],
        "evidenceAr": [
          "تصدير حصر مجموعات البيانات مع التصنيف والموقع والمالك",
          "تصدير حصر الحسابات مع أعمدة الصلاحيات وآخر دخول",
          "اعتماد المراجعة ربع السنوية للحسابات",
          "تقرير الحسابات المعطلة وفق قاعدة الخمول تسعين يوما"
        ],
        "cadence": "quarterly",
        "effort": "medium",
        "phase": 1,
        "beyondAnnex": []
      },
      "appliesWhen": [],
      "crosswalk": {
        "csf": [
          "ID.AM-07",
          "PR.AA-01",
          "PR.AA-05"
        ],
        "cis": [
          "3.1",
          "5.1",
          "5.3"
        ],
        "iso": [
          "A.5.9",
          "A.5.16",
          "A.5.18"
        ]
      }
    },
    {
      "id": "PR-1",
      "function": "PR",
      "official": {
        "title": "Secure Configuration, Hardening & Network Segmentation",
        "titleAr": "التهيئة الآمنة والتحصين وتجزئة الشبكة",
        "requirement": "Establish hardened configuration baselines for servers, workstations, network devices, and key applications. From this baseline, disable or remove services, features and ports that are not needed for the system’s role. Change or disable default accounts and default passwords. Enable a host-based firewall on endpoints and servers and allow only the network traffic required for normal operation. Review configurations at least annually and after major changes.",
        "requirementAr": "تضع الجهة إعدادات مرجعية محصنة للخوادم ومحطات العمل وأجهزة الشبكة والتطبيقات الرئيسية، وتعطل أو تزيل انطلاقا من هذه الإعدادات الخدمات والخصائص والمنافذ غير اللازمة لدور النظام، وتغير أو تعطل الحسابات وكلمات المرور الافتراضية، وتفعل جدار حماية على مستوى المضيف في الأجهزة الطرفية والخوادم لا يسمح إلا بحركة البيانات اللازمة للتشغيل الطبيعي، وتراجع الإعدادات سنويا على الأقل وبعد التغييرات الجوهرية.",
        "purpose": "Reduce the attack surface of systems and devices.",
        "purposeAr": "تقليص سطح الهجوم على الأنظمة والأجهزة."
      },
      "editorial": {
        "purpose": null,
        "purposeAr": null,
        "checks": [
          "Hardened configuration baselines exist for servers.",
          "Hardened configuration baselines exist for workstations.",
          "Hardened configuration baselines exist for network devices.",
          "Hardened configuration baselines exist for key applications.",
          "Services and features not needed for the system role are disabled or removed.",
          "Ports not needed for the system role are disabled or removed.",
          "Default accounts are changed or disabled.",
          "Default passwords are changed or disabled.",
          "A host based firewall is enabled on endpoints and servers.",
          "Host firewall rules allow only the traffic required for normal operation.",
          "Configurations are reviewed at least annually.",
          "Configurations are reviewed after major changes."
        ],
        "checksAr": [
          "توجد إعدادات مرجعية محصنة للخوادم.",
          "توجد إعدادات مرجعية محصنة لمحطات العمل.",
          "توجد إعدادات مرجعية محصنة لأجهزة الشبكة.",
          "توجد إعدادات مرجعية محصنة للتطبيقات الرئيسية.",
          "الخدمات والخصائص غير اللازمة لدور النظام معطلة أو مزالة.",
          "المنافذ غير اللازمة لدور النظام معطلة أو مزالة.",
          "الحسابات الافتراضية مغيرة أو معطلة.",
          "كلمات المرور الافتراضية مغيرة أو معطلة.",
          "جدار حماية على مستوى المضيف مفعل على الأجهزة الطرفية والخوادم.",
          "قواعد جدار حماية المضيف تسمح فقط بحركة البيانات اللازمة للتشغيل الطبيعي.",
          "تراجع الإعدادات سنويا على الأقل.",
          "تراجع الإعدادات عقب التغييرات الجوهرية."
        ],
        "evidence": [
          "Documented baseline per platform with the hardening decisions recorded",
          "Build checklist or golden image showing services and ports removed",
          "Report confirming no default credentials remain in use",
          "Host firewall policy export from a sample of endpoints and servers",
          "Dated configuration review record"
        ],
        "evidenceAr": [
          "إعداد مرجعي موثق لكل منصة مع تسجيل قرارات التحصين",
          "قائمة تحقق البناء أو النسخة القياسية تبين الخدمات والمنافذ المزالة",
          "تقرير يؤكد عدم بقاء أي بيانات اعتماد افتراضية قيد الاستخدام",
          "تصدير سياسة جدار حماية المضيف من عينة من الأجهزة الطرفية والخوادم",
          "محضر مؤرخ لمراجعة الإعدادات"
        ],
        "cadence": "annual",
        "effort": "high",
        "phase": 2,
        "beyondAnnex": []
      },
      "appliesWhen": [],
      "crosswalk": {
        "csf": [
          "PR.PS-01",
          "PR.IR-01"
        ],
        "cis": [
          "4.1",
          "4.2",
          "4.4",
          "4.5",
          "4.6",
          "4.7",
          "4.8"
        ],
        "iso": [
          "A.8.9"
        ]
      }
    },
    {
      "id": "PR-1.1",
      "function": "PR",
      "official": {
        "title": "Network Segmentation",
        "titleAr": "تجزئة الشبكة",
        "requirement": "Where feasible, separate user networks from server/data networks, and keep management/admin interfaces on a more restricted network segment. Place internet-facing systems in a more controlled network zone. Avoid direct access from user networks to sensitive servers unless explicitly required and approved.\n• Do not treat network location alone as sufficient basis for trust. Access to management/admin interfaces and Critical Systems MUST be explicitly authorized based on least privilege and protected with strong authentication in accordance with PR-2 (including MFA for administrative access where supported).\n• Document such access and review it at least annually.",
        "requirementAr": "تفصل الجهة متى أمكن شبكات المستخدمين عن شبكات الخوادم والبيانات، وتبقي واجهات الإدارة في مقطع شبكي أكثر تقييدا، وتضع الأنظمة المتصلة بالإنترنت في منطقة شبكية أكثر ضبطا، وتتجنب الوصول المباشر من شبكات المستخدمين إلى الخوادم الحساسة ما لم يكن مطلوبا ومعتمدا صراحة.\n• ولا يعد الموقع الشبكي وحده أساسا كافيا للثقة، إذ يجب اعتماد الوصول إلى واجهات الإدارة والأنظمة الحرجة اعتمادا صريحا قائما على أقل الصلاحيات وحمايته بمصادقة قوية وفق الضابط PR-2 بما في ذلك المصادقة متعددة العوامل للوصول الإداري حيثما كانت مدعومة.\n• ويوثق هذا الوصول ويراجع سنويا على الأقل.",
        "purpose": "Limit the spread and impact of attacks by separating networks.",
        "purposeAr": "الحد من انتشار الهجمات وأثرها عبر الفصل بين الشبكات."
      },
      "editorial": {
        "purpose": null,
        "purposeAr": null,
        "checks": [
          "User networks are separated from server and data networks where feasible.",
          "Management and admin interfaces sit on a more restricted network segment.",
          "Internet facing systems are placed in a more controlled network zone.",
          "Direct access from user networks to sensitive servers is avoided unless explicitly required and approved.",
          "Network location alone is not treated as sufficient basis for trust.",
          "Access to management and admin interfaces is explicitly authorized on least privilege.",
          "Access to Critical Systems is explicitly authorized on least privilege.",
          "Strong authentication protects management and admin access in line with PR-2.",
          "MFA protects administrative access where supported.",
          "Such access is documented.",
          "Such access is reviewed at least annually."
        ],
        "checksAr": [
          "شبكات المستخدمين مفصولة عن شبكات الخوادم والبيانات متى أمكن.",
          "واجهات الإدارة موضوعة في مقطع شبكي أكثر تقييدا.",
          "الأنظمة المتصلة بالإنترنت موضوعة في منطقة شبكية أكثر ضبطا.",
          "الوصول المباشر من شبكات المستخدمين إلى الخوادم الحساسة متجنب ما لم يكن مطلوبا ومعتمدا صراحة.",
          "لا يعد الموقع الشبكي وحده أساسا كافيا للثقة.",
          "الوصول إلى واجهات الإدارة معتمد صراحة على أساس أقل الصلاحيات.",
          "الوصول إلى الأنظمة الحرجة معتمد صراحة على أساس أقل الصلاحيات.",
          "مصادقة قوية تحمي الوصول الإداري بما يتفق مع الضابط PR-2.",
          "تحمي المصادقة متعددة العوامل الوصول الإداري حيثما كان مدعوما.",
          "هذا الوصول موثق.",
          "هذا الوصول يراجع سنويا على الأقل."
        ],
        "evidence": [
          "Network diagram showing user, server, management and internet facing zones",
          "Firewall or ACL rule set enforcing the separation",
          "Authorization register for management interface and Critical System access",
          "Annual access review sign off"
        ],
        "evidenceAr": [
          "مخطط شبكي يبين مناطق المستخدمين والخوادم والإدارة والاتصال بالإنترنت",
          "مجموعة قواعد جدار الحماية أو قوائم التحكم التي تفرض الفصل",
          "سجل اعتماد الوصول إلى واجهات الإدارة والأنظمة الحرجة",
          "اعتماد المراجعة السنوية للوصول"
        ],
        "cadence": "annual",
        "effort": "high",
        "phase": 2,
        "beyondAnnex": []
      },
      "appliesWhen": [],
      "crosswalk": {
        "csf": [
          "PR.IR-01",
          "PR.AA-05"
        ],
        "cis": [
          "12.2",
          "4.6",
          "13.4"
        ],
        "iso": [
          "A.8.20",
          "A.8.22"
        ]
      }
    },
    {
      "id": "PR-1.2",
      "function": "PR",
      "official": {
        "title": "Vulnerability Management & Patching",
        "titleAr": "إدارة الثغرات والتحديثات الأمنية",
        "requirement": "Have a simple written process for vulnerability management and review it at least annually. Run automated vulnerability scans on key systems: at least monthly for internet-facing systems, at least quarterly for other important internal systems, and after major changes. After each scan, review the report, produce a short action list, and fix the most serious issues first (for example, high and critical findings). Aim to apply operating system and application patches at least monthly on supported systems. Keep records of scans and key remediation actions.",
        "requirementAr": "تعتمد الجهة آلية مكتوبة مبسطة لإدارة الثغرات وتراجعها سنويا على الأقل، وتجري فحوصا آلية للثغرات على الأنظمة الرئيسية بواقع شهري على الأقل للأنظمة المتصلة بالإنترنت وربع سنوي على الأقل لسائر الأنظمة الداخلية المهمة وكذلك بعد التغييرات الجوهرية، وتراجع بعد كل فحص تقريره وتعد قائمة إجراءات موجزة وتعالج أخطر المسائل أولا كالنتائج العالية والحرجة، وتسعى إلى تطبيق تحديثات أنظمة التشغيل والتطبيقات شهريا على الأقل على الأنظمة المدعومة، وتحفظ سجلات الفحوص وإجراءات المعالجة الرئيسية.",
        "purpose": "Identify and address technical weaknesses in a structured way.",
        "purposeAr": "اكتشاف نقاط الضعف التقنية ومعالجتها بأسلوب منهجي."
      },
      "editorial": {
        "purpose": null,
        "purposeAr": null,
        "checks": [
          "A written vulnerability management process exists.",
          "The process is reviewed at least annually.",
          "Automated vulnerability scans run at least monthly on internet facing systems.",
          "Automated vulnerability scans run at least quarterly on other important internal systems.",
          "Scans are run after major changes.",
          "Each scan report is reviewed.",
          "A short action list is produced after each scan.",
          "High and critical findings are prioritized for fixing.",
          "Operating system patches are applied at least monthly on supported systems.",
          "Application patches are applied at least monthly on supported systems.",
          "Records of scans are retained.",
          "Records of key remediation actions are retained."
        ],
        "checksAr": [
          "توجد آلية مكتوبة لإدارة الثغرات.",
          "تراجع الآلية سنويا على الأقل.",
          "تجرى فحوص الثغرات الآلية شهريا على الأقل للأنظمة المتصلة بالإنترنت.",
          "تجرى فحوص الثغرات الآلية ربع سنويا على الأقل لسائر الأنظمة الداخلية المهمة.",
          "تجرى الفحوص عقب التغييرات الجوهرية.",
          "يراجع كل تقرير فحص.",
          "تعد قائمة إجراءات موجزة عقب كل فحص.",
          "تعطى النتائج العالية والحرجة أولوية المعالجة.",
          "تطبق تحديثات أنظمة التشغيل شهريا على الأقل على الأنظمة المدعومة.",
          "تطبق تحديثات التطبيقات شهريا على الأقل على الأنظمة المدعومة.",
          "سجلات الفحوص محفوظة.",
          "سجلات إجراءات المعالجة الرئيسية محفوظة."
        ],
        "evidence": [
          "Vulnerability management procedure with review date",
          "Scan schedule and last twelve months of scan reports",
          "Remediation tracker showing findings, owners and closure dates",
          "Patch compliance report per monthly cycle"
        ],
        "evidenceAr": [
          "إجراء إدارة الثغرات مع تاريخ المراجعة",
          "جدول الفحوص وتقارير آخر اثني عشر شهرا",
          "سجل متابعة المعالجة يبين النتائج والمسؤولين وتواريخ الإغلاق",
          "تقرير الالتزام بالتحديثات لكل دورة شهرية"
        ],
        "cadence": "monthly",
        "effort": "high",
        "phase": 2,
        "beyondAnnex": []
      },
      "appliesWhen": [],
      "crosswalk": {
        "csf": [
          "ID.RA-01",
          "ID.RA-06",
          "PR.PS-02"
        ],
        "cis": [
          "7.1",
          "7.3",
          "7.4",
          "7.5",
          "7.6"
        ],
        "iso": [
          "A.8.8"
        ]
      }
    },
    {
      "id": "PR-2",
      "function": "PR",
      "official": {
        "title": "Identity, Authentication & Password Hygiene",
        "titleAr": "الهوية والمصادقة وسلامة كلمات المرور",
        "requirement": "Require unique passwords for all accounts; do not reuse the same password across different systems. As a simple rule, require at least 8 characters for accounts protected by multi-factor authentication (MFA) and at least 14 characters for accounts without MFA. Avoid forcing regular password changes unless compromise is suspected. Enforce session lock or screen saver after 15 minutes of inactivity for workstations and around 2 minutes for mobile devices where practical. Limit administrator privileges to dedicated admin accounts, and require staff to perform day-to-day activities (email, web browsing, office work) from a normal user account. Implement MFA for all remote network access, externally exposed applications, and privileged/admin accounts where supported, using at least two different types of factor (something you know, something you have, something you are).",
        "requirementAr": "تشترط الجهة كلمات مرور فريدة لجميع الحسابات دون إعادة استخدام كلمة المرور نفسها عبر أنظمة مختلفة، وكقاعدة مبسطة تشترط ثمانية محارف على الأقل للحسابات المحمية بالمصادقة متعددة العوامل وأربعة عشر محرفا على الأقل للحسابات غير المحمية بها، وتتجنب فرض تغيير دوري لكلمات المرور ما لم يشتبه في اختراق، وتفرض قفل الجلسة أو شاشة التوقف بعد خمس عشرة دقيقة من الخمول في محطات العمل ونحو دقيقتين في الأجهزة المحمولة متى كان ذلك عمليا، وتقصر صلاحيات المدير على حسابات إدارية مخصصة وتلزم الموظفين بأداء أعمالهم اليومية من بريد وتصفح وأعمال مكتبية من حساب مستخدم عادي، وتطبق المصادقة متعددة العوامل على كل وصول شبكي عن بعد وعلى التطبيقات المكشوفة خارجيا وعلى الحسابات ذات الصلاحيات والحسابات الإدارية حيثما كانت مدعومة، على أن تستخدم نوعين مختلفين على الأقل من العوامل أي شيء تعرفه وشيء تملكه وشيء تكونه.",
        "purpose": "Ensure access is properly controlled and accounts are harder to compromise.",
        "purposeAr": "ضمان ضبط الوصول على نحو سليم وجعل اختراق الحسابات أصعب."
      },
      "editorial": {
        "purpose": null,
        "purposeAr": null,
        "checks": [
          "Unique passwords are required for all accounts.",
          "Password reuse across different systems is prohibited.",
          "Accounts protected by MFA require at least 8 characters.",
          "Accounts without MFA require at least 14 characters.",
          "Regular forced password changes are avoided unless compromise is suspected.",
          "Workstations lock the session after 15 minutes of inactivity.",
          "Mobile devices lock after around 2 minutes of inactivity where practical.",
          "Administrator privileges are limited to dedicated admin accounts.",
          "Staff perform day to day activities from a normal user account.",
          "MFA is implemented for all remote network access.",
          "MFA is implemented for externally exposed applications.",
          "MFA is implemented for privileged and admin accounts where supported.",
          "MFA uses at least two different types of factor."
        ],
        "checksAr": [
          "كلمات مرور فريدة مطلوبة لجميع الحسابات.",
          "إعادة استخدام كلمات المرور عبر أنظمة مختلفة محظورة.",
          "تتطلب الحسابات المحمية بالمصادقة متعددة العوامل ثمانية محارف على الأقل.",
          "تتطلب الحسابات غير المحمية بالمصادقة متعددة العوامل أربعة عشر محرفا على الأقل.",
          "التغيير الدوري الإجباري لكلمات المرور متجنب ما لم يشتبه في اختراق.",
          "تقفل محطات العمل الجلسة بعد خمس عشرة دقيقة من الخمول.",
          "تقفل الأجهزة المحمولة بعد نحو دقيقتين من الخمول حيثما كان ذلك عمليا.",
          "صلاحيات المدير مقصورة على حسابات إدارية مخصصة.",
          "يؤدي الموظفون أعمالهم اليومية من حساب مستخدم عادي.",
          "المصادقة متعددة العوامل مطبقة على كل وصول شبكي عن بعد.",
          "المصادقة متعددة العوامل مطبقة على التطبيقات المكشوفة خارجيا.",
          "المصادقة متعددة العوامل مطبقة على الحسابات ذات الصلاحيات والحسابات الإدارية حيثما كانت مدعومة.",
          "تستخدم المصادقة متعددة العوامل نوعين مختلفين على الأقل من العوامل."
        ],
        "evidence": [
          "Password policy configuration export from the directory service",
          "Screen lock policy from endpoint management",
          "List of privileged accounts showing separation from daily use accounts",
          "MFA enrolment report covering remote access, exposed applications and admins"
        ],
        "evidenceAr": [
          "تصدير إعداد سياسة كلمات المرور من خدمة الدليل",
          "سياسة قفل الشاشة من نظام إدارة الأجهزة الطرفية",
          "قائمة الحسابات ذات الصلاحيات تبين فصلها عن حسابات الاستخدام اليومي",
          "تقرير تسجيل المصادقة متعددة العوامل يغطي الوصول عن بعد والتطبيقات المكشوفة والمديرين"
        ],
        "cadence": "continuous",
        "effort": "medium",
        "phase": 1,
        "beyondAnnex": []
      },
      "appliesWhen": [],
      "crosswalk": {
        "csf": [
          "PR.AA-01",
          "PR.AA-02",
          "PR.AA-03",
          "PR.AA-05"
        ],
        "cis": [
          "5.2",
          "5.4",
          "6.3",
          "6.4",
          "6.5"
        ],
        "iso": [
          "A.5.15",
          "A.5.16",
          "A.5.17",
          "A.8.5"
        ]
      }
    },
    {
      "id": "PR-2.1",
      "function": "PR",
      "official": {
        "title": "Corporate Email Only & Personal Email Ban",
        "titleAr": "قصر المراسلات على البريد المؤسسي ومنع البريد الشخصي",
        "requirement": "Require that all official business communications use only Entity-approved corporate email accounts on approved domains. Personal/consumer email accounts MUST NOT be configured on corporate devices and MUST NOT be used for work-related communication. Enforce this via (1) an acceptable use policy, and (2) device and email configuration (e.g., MDM or mail client settings) that prevent adding personal accounts where feasible.",
        "requirementAr": "تشترط الجهة أن تجري كل مراسلات العمل الرسمية عبر حسابات بريد مؤسسي معتمدة منها وعلى نطاقات معتمدة، ولا يجوز تهيئة حسابات البريد الشخصي أو الاستهلاكي على أجهزة الجهة ولا استخدامها في المراسلات المتعلقة بالعمل، ويفرض ذلك أولا بسياسة للاستخدام المقبول وثانيا بإعدادات الأجهزة والبريد كنظام إدارة الأجهزة أو إعدادات عميل البريد بما يمنع إضافة الحسابات الشخصية متى أمكن.",
        "purpose": "Ensure work communications use managed, auditable channels and reduce data leakage via personal email.",
        "purposeAr": "ضمان مرور مراسلات العمل عبر قنوات مدارة قابلة للتدقيق والحد من تسرب البيانات عبر البريد الشخصي."
      },
      "editorial": {
        "purpose": null,
        "purposeAr": null,
        "checks": [
          "All official business communication uses entity approved corporate email accounts.",
          "Corporate email runs on approved domains.",
          "Personal or consumer email accounts are not configured on corporate devices.",
          "Personal or consumer email accounts are not used for work related communication.",
          "An acceptable use policy states the requirement.",
          "Device and email configuration prevents adding personal accounts where feasible."
        ],
        "checksAr": [
          "تستخدم كل مراسلات العمل الرسمية حسابات بريد مؤسسي معتمدة من الجهة.",
          "يعمل البريد المؤسسي على نطاقات معتمدة.",
          "حسابات البريد الشخصي أو الاستهلاكي غير مهيأة على أجهزة الجهة.",
          "لا تستخدم حسابات البريد الشخصي أو الاستهلاكي في المراسلات المتعلقة بالعمل.",
          "سياسة الاستخدام المقبول تنص على هذا الاشتراط.",
          "تمنع إعدادات الأجهزة والبريد إضافة الحسابات الشخصية متى أمكن."
        ],
        "evidence": [
          "Acceptable use policy clause on corporate email",
          "MDM or mail client profile blocking personal account enrolment",
          "Approved mail domain list",
          "Exception records where the technical control cannot be applied"
        ],
        "evidenceAr": [
          "بند سياسة الاستخدام المقبول الخاص بالبريد المؤسسي",
          "ملف إدارة الأجهزة أو عميل البريد الذي يمنع تسجيل الحسابات الشخصية",
          "قائمة نطاقات البريد المعتمدة",
          "سجلات الاستثناء حيث يتعذر تطبيق الضابط التقني"
        ],
        "cadence": "continuous",
        "effort": "low",
        "phase": 1,
        "beyondAnnex": []
      },
      "appliesWhen": [],
      "crosswalk": {
        "csf": [
          "PR.DS-02",
          "GV.PO-01"
        ],
        "cis": [
          "9.1",
          "14.1"
        ],
        "iso": [
          "A.5.14",
          "A.8.1"
        ]
      }
    },
    {
      "id": "PR-2.2",
      "function": "PR",
      "official": {
        "title": "Password Manager & Credential Hygiene",
        "titleAr": "مدير كلمات المرور وسلامة بيانات الاعتماد",
        "requirement": "Provide or approve a password-manager-style solution for staff who manage multiple credentials. Encourage use of long, unique passwords generated by the manager for each system. For shared/team accounts (where unavoidable), use shared password vaults or similar capabilities; do not share passwords through email, chat, or on paper.",
        "requirementAr": "توفر الجهة أو تعتمد حلا من نوع مدير كلمات المرور للموظفين الذين يديرون بيانات اعتماد متعددة، وتشجع استخدام كلمات مرور طويلة وفريدة يولدها المدير لكل نظام، وتستخدم للحسابات المشتركة أو حسابات الفرق عند تعذر تجنبها خزائن كلمات مرور مشتركة أو قدرات مماثلة، ولا تتبادل كلمات المرور عبر البريد الإلكتروني أو المحادثات أو على الورق.",
        "purpose": "Help staff maintain strong, unique passwords without reuse.",
        "purposeAr": "مساعدة الموظفين على استخدام كلمات مرور قوية وفريدة دون تكرار."
      },
      "editorial": {
        "purpose": null,
        "purposeAr": null,
        "checks": [
          "A password manager style solution is provided or approved for staff managing multiple credentials.",
          "Long unique generated passwords are encouraged for each system.",
          "Shared or team accounts use a shared password vault or similar capability.",
          "Passwords are not shared through email.",
          "Passwords are not shared through chat.",
          "Passwords are not shared on paper."
        ],
        "checksAr": [
          "يوفر أو يعتمد حل من نوع مدير كلمات المرور للموظفين الذين يديرون بيانات اعتماد متعددة.",
          "يشجع استخدام كلمات مرور طويلة وفريدة ومولدة لكل نظام.",
          "تستخدم الحسابات المشتركة أو حسابات الفرق خزانة كلمات مرور مشتركة أو قدرة مماثلة.",
          "كلمات المرور لا تتبادل عبر البريد الإلكتروني.",
          "كلمات المرور لا تتبادل عبر المحادثات.",
          "كلمات المرور لا تتبادل على الورق."
        ],
        "evidence": [
          "Approved password manager in the software inventory with licence coverage",
          "Vault configuration for shared team credentials",
          "Awareness material covering credential sharing prohibitions",
          "Rollout record for staff in credential heavy roles"
        ],
        "evidenceAr": [
          "مدير كلمات المرور المعتمد مدرجا في حصر البرمجيات مع تغطية الترخيص",
          "إعداد الخزانة الخاصة ببيانات الاعتماد المشتركة بين الفرق",
          "مواد توعوية تغطي حظر تبادل بيانات الاعتماد",
          "محضر التعميم على الموظفين في الأدوار كثيفة بيانات الاعتماد"
        ],
        "cadence": "continuous",
        "effort": "low",
        "phase": 2,
        "beyondAnnex": []
      },
      "appliesWhen": [],
      "crosswalk": {
        "csf": [
          "PR.AA-01",
          "PR.AT-01"
        ],
        "cis": [
          "5.2",
          "14.1"
        ],
        "iso": [
          "A.5.17"
        ]
      }
    },
    {
      "id": "PR-3",
      "function": "PR",
      "official": {
        "title": "Awareness & Human Factors",
        "titleAr": "التوعية والعوامل البشرية",
        "requirement": "Establish a security awareness program and provide training at least annually and for new joiners. At minimum, cover: social engineering and phishing, safe use of email and the web, handling of Sensitive and Restricted data, password and MFA hygiene, use of approved communication tools, use of portable media, and how to report suspicious activity or incidents. Use simple language and relevant examples.",
        "requirementAr": "تنشئ الجهة برنامجا للتوعية الأمنية وتقدم التدريب سنويا على الأقل وللموظفين الجدد، ويغطي كحد أدنى الهندسة الاجتماعية والتصيد والاستخدام الآمن للبريد الإلكتروني والإنترنت والتعامل مع البيانات الحساسة والمقيدة وسلامة كلمات المرور والمصادقة متعددة العوامل واستخدام أدوات التواصل المعتمدة واستخدام وسائط التخزين الخارجية وكيفية الإبلاغ عن النشاط المشبوه أو الحوادث، وتستخدم في ذلك لغة بسيطة وأمثلة ذات صلة.",
        "purpose": "Build a basic culture of secure behavior.",
        "purposeAr": "بناء ثقافة أساسية للسلوك الآمن."
      },
      "editorial": {
        "purpose": null,
        "purposeAr": null,
        "checks": [
          "A security awareness program is established.",
          "Training is delivered at least annually.",
          "Training is delivered to new joiners.",
          "Training covers social engineering and phishing.",
          "Training covers safe use of email and the web.",
          "Training covers handling of Sensitive and Restricted data.",
          "Training covers password and MFA hygiene.",
          "Training covers use of approved communication tools.",
          "Training covers use of portable media.",
          "Training covers how to report suspicious activity or incidents.",
          "Material uses simple language and relevant examples."
        ],
        "checksAr": [
          "يوجد برنامج للتوعية الأمنية.",
          "يقدم التدريب سنويا على الأقل.",
          "يقدم التدريب للموظفين الجدد.",
          "يغطي التدريب الهندسة الاجتماعية والتصيد.",
          "يغطي التدريب الاستخدام الآمن للبريد الإلكتروني والإنترنت.",
          "يغطي التدريب التعامل مع البيانات الحساسة والمقيدة.",
          "يغطي التدريب سلامة كلمات المرور والمصادقة متعددة العوامل.",
          "يغطي التدريب استخدام أدوات التواصل المعتمدة.",
          "يغطي التدريب استخدام وسائط التخزين الخارجية.",
          "يغطي التدريب كيفية الإبلاغ عن النشاط المشبوه أو الحوادث.",
          "تستخدم المواد لغة بسيطة وأمثلة ذات صلة."
        ],
        "evidence": [
          "Awareness program plan and content outline mapped to the seven required topics",
          "Attendance and completion records for the current year",
          "New joiner induction record showing security training",
          "Sample training material in the working language of staff"
        ],
        "evidenceAr": [
          "خطة برنامج التوعية وموجز محتواه مقابلا للموضوعات السبعة المطلوبة",
          "سجلات الحضور والإتمام للسنة الحالية",
          "محضر تعريف الموظفين الجدد يبين التدريب الأمني",
          "عينة من المواد التدريبية بلغة عمل الموظفين"
        ],
        "cadence": "annual",
        "effort": "medium",
        "phase": 1,
        "beyondAnnex": []
      },
      "appliesWhen": [],
      "crosswalk": {
        "csf": [
          "PR.AT-01",
          "PR.AT-02"
        ],
        "cis": [
          "14.1",
          "14.2",
          "14.3",
          "14.6"
        ],
        "iso": [
          "A.6.3"
        ]
      }
    },
    {
      "id": "PR-3.1",
      "function": "PR",
      "official": {
        "title": "Official Social Media & Digital Presence",
        "titleAr": "الحسابات الرسمية والحضور الرقمي",
        "requirement": "Maintain a central register of official Entity accounts on external platforms (e.g., major social networks, video platforms). Create official accounts using corporate email addresses and appropriate naming conventions. Where the platform provides it and criteria are met, enable verification or \"official\" status. Protect these accounts with MFA and role-based administration; review access at least annually and remove access when staff leave or change roles.",
        "requirementAr": "تحفظ الجهة سجلا مركزيا لحساباتها الرسمية على المنصات الخارجية كشبكات التواصل ومنصات الفيديو الكبرى، وتنشئ الحسابات الرسمية باستخدام عناوين بريد مؤسسي وأعراف تسمية مناسبة، وتفعل التوثيق أو صفة الحساب الرسمي حيثما توفرها المنصة واستوفيت شروطها، وتحمي هذه الحسابات بالمصادقة متعددة العوامل وتديرها وفق الأدوار، وتراجع الوصول إليها سنويا على الأقل وتزيله عند مغادرة الموظفين أو تغير أدوارهم.",
        "purpose": "Ensure official accounts are authentic, protected, and clearly distinguished from impostors.",
        "purposeAr": "ضمان أصالة الحسابات الرسمية وحمايتها وتمييزها بوضوح عن الحسابات المنتحلة."
      },
      "editorial": {
        "purpose": null,
        "purposeAr": null,
        "checks": [
          "A central register of official entity accounts on external platforms is maintained.",
          "Official accounts are created using corporate email addresses.",
          "Official accounts follow appropriate naming conventions.",
          "Verification or official status is enabled where the platform provides it and criteria are met.",
          "Official accounts are protected with MFA.",
          "Official accounts use role based administration.",
          "Access to official accounts is reviewed at least annually.",
          "Access is removed when staff leave or change roles."
        ],
        "checksAr": [
          "يحفظ سجل مركزي لحسابات الجهة الرسمية على المنصات الخارجية.",
          "تنشأ الحسابات الرسمية باستخدام عناوين بريد مؤسسي.",
          "تتبع الحسابات الرسمية أعرافا مناسبة في التسمية.",
          "التوثيق أو صفة الحساب الرسمي مفعلة حيثما توفرها المنصة واستوفيت شروطها.",
          "الحسابات الرسمية محمية بالمصادقة متعددة العوامل.",
          "تدار الحسابات الرسمية وفق الأدوار.",
          "يراجع الوصول إلى الحسابات الرسمية سنويا على الأقل.",
          "يزال الوصول عند مغادرة الموظف أو تغير دوره."
        ],
        "evidence": [
          "Register of official accounts with platform, handle, owner and admin list",
          "MFA status screenshot per official account",
          "Annual access review record",
          "Leaver checklist entry covering social account access removal"
        ],
        "evidenceAr": [
          "سجل الحسابات الرسمية يبين المنصة والمعرف والمالك وقائمة المديرين",
          "لقطة تبين حالة المصادقة متعددة العوامل لكل حساب رسمي",
          "محضر المراجعة السنوية للوصول",
          "بند في قائمة تحقق المغادرة يغطي إزالة الوصول إلى حسابات التواصل"
        ],
        "cadence": "annual",
        "effort": "low",
        "phase": 2,
        "beyondAnnex": []
      },
      "appliesWhen": [
        "hasPublicAccounts"
      ],
      "crosswalk": {
        "csf": [
          "PR.AA-05",
          "ID.AM-02"
        ],
        "cis": [
          "5.1",
          "6.5"
        ],
        "iso": [
          "A.5.16",
          "A.8.5"
        ]
      }
    },
    {
      "id": "PR-4",
      "function": "PR",
      "official": {
        "title": "Malware, Email & Web Protection",
        "titleAr": "الحماية من البرمجيات الخبيثة وحماية البريد والويب",
        "requirement": "Deploy endpoint protection (e.g., anti-malware/EDR software) on supported servers and workstations with automatic updates and centralized alerting where possible. Use email and web security controls (e.g., spam filtering, attachment and URL filtering) to block common malicious content and clearly suspicious file types. Configure email systems to block or warn on dangerous file extensions that are not needed for business and to limit very large attachments according to business need. Configure email domains with appropriate anti-spoofing controls (SPF, DKIM, DMARC) to prevent impersonation. Train staff to be cautious with unexpected links and attachments, and to report suspicious messages.",
        "requirementAr": "تنشر الجهة حلول حماية الأجهزة الطرفية كبرمجيات مكافحة البرمجيات الخبيثة أو الكشف والاستجابة على الخوادم ومحطات العمل المدعومة مع تحديث تلقائي وتنبيه مركزي متى أمكن، وتستخدم ضوابط أمن البريد والويب كترشيح الرسائل المزعجة والمرفقات والروابط لحجب المحتوى الخبيث الشائع وأنواع الملفات المشبوهة بوضوح، وتهيئ أنظمة البريد لحجب امتدادات الملفات الخطرة غير اللازمة للعمل أو التنبيه عليها ولتحديد المرفقات الكبيرة جدا وفق حاجة العمل، وتهيئ نطاقات البريد بضوابط مناسبة لمنع الانتحال هي SPF وDKIM وDMARC، وتدرب الموظفين على الحذر من الروابط والمرفقات غير المتوقعة وعلى الإبلاغ عن الرسائل المشبوهة.",
        "purpose": "Reduce the risk of malware and phishing attacks.",
        "purposeAr": "تقليل مخاطر البرمجيات الخبيثة وهجمات التصيد."
      },
      "editorial": {
        "purpose": null,
        "purposeAr": null,
        "checks": [
          "Endpoint protection is deployed on supported servers.",
          "Endpoint protection is deployed on supported workstations.",
          "Endpoint protection signatures and engines update automatically.",
          "Centralized alerting is in place where possible.",
          "Email security controls block common malicious content.",
          "Web security controls block common malicious content.",
          "Email systems block or warn on dangerous file extensions not needed for business.",
          "Very large attachments are limited according to business need.",
          "SPF is configured on entity email domains.",
          "DKIM is configured on entity email domains.",
          "DMARC is configured on entity email domains.",
          "Staff are trained to be cautious with unexpected links and attachments.",
          "Staff are trained to report suspicious messages."
        ],
        "checksAr": [
          "حماية الأجهزة الطرفية منشورة على الخوادم المدعومة.",
          "حماية الأجهزة الطرفية منشورة على محطات العمل المدعومة.",
          "تحدث بصمات ومحركات حماية الأجهزة الطرفية تلقائيا.",
          "يوجد تنبيه مركزي حيثما أمكن.",
          "تحجب ضوابط أمن البريد المحتوى الخبيث الشائع.",
          "تحجب ضوابط أمن الويب المحتوى الخبيث الشائع.",
          "تحجب أنظمة البريد أو تنبه على امتدادات الملفات الخطرة غير اللازمة للعمل.",
          "المرفقات الكبيرة جدا محدودة وفق حاجة العمل.",
          "سجل SPF مهيأ على نطاقات بريد الجهة.",
          "سجل DKIM مهيأ على نطاقات بريد الجهة.",
          "سجل DMARC مهيأ على نطاقات بريد الجهة.",
          "الموظفون مدربون على الحذر من الروابط والمرفقات غير المتوقعة.",
          "الموظفون مدربون على الإبلاغ عن الرسائل المشبوهة."
        ],
        "evidence": [
          "Endpoint protection coverage report against the asset inventory",
          "Mail gateway policy showing attachment and URL filtering rules",
          "DNS records proving SPF, DKIM and DMARC on every sending domain",
          "Phishing reporting statistics or mailbox activity"
        ],
        "evidenceAr": [
          "تقرير تغطية حماية الأجهزة الطرفية مقارنا بحصر الأصول",
          "سياسة بوابة البريد تبين قواعد ترشيح المرفقات والروابط",
          "سجلات نظام أسماء النطاقات تثبت تهيئة SPF وDKIM وDMARC على كل نطاق مرسل",
          "إحصاءات الإبلاغ عن التصيد أو نشاط صندوق البريد المخصص"
        ],
        "cadence": "continuous",
        "effort": "medium",
        "phase": 1,
        "beyondAnnex": []
      },
      "appliesWhen": [],
      "crosswalk": {
        "csf": [
          "PR.PS-05",
          "DE.CM-01",
          "PR.AT-01"
        ],
        "cis": [
          "9.2",
          "9.3",
          "9.6",
          "10.1",
          "10.2"
        ],
        "iso": [
          "A.8.7",
          "A.8.23"
        ]
      }
    },
    {
      "id": "PR-4.1",
      "function": "PR",
      "official": {
        "title": "Approved Communication & Videoconferencing Platforms",
        "titleAr": "منصات التواصل والاجتماعات المرئية المعتمدة",
        "requirement": "For official work (meetings, calls, messaging, screen sharing), use only Entity-approved communication and collaboration platforms. Do not use personal or unapproved apps (for example, private messaging, personal email, unauthorized remote-control tools) for work data or meetings. Maintain a simple list of approved platforms and ensure staff are aware of it. Where feasible, restrict installation or use of unapproved tools on corporate devices via configuration.",
        "requirementAr": "تستخدم الجهة في الأعمال الرسمية من اجتماعات ومكالمات ومراسلة ومشاركة للشاشة منصات التواصل والتعاون المعتمدة منها وحدها، ولا تستخدم التطبيقات الشخصية أو غير المعتمدة كالمراسلة الخاصة والبريد الشخصي وأدوات التحكم عن بعد غير المصرح بها في بيانات العمل أو اجتماعاته، وتحفظ قائمة مبسطة بالمنصات المعتمدة وتضمن علم الموظفين بها، وتقيد متى أمكن تثبيت الأدوات غير المعتمدة أو استخدامها على أجهزة الجهة عن طريق الإعدادات.",
        "purpose": "Reduce risk from unapproved chat/voice/video tools and remote control apps.",
        "purposeAr": "تقليل المخاطر الناتجة عن أدوات المحادثة والصوت والفيديو والتحكم عن بعد غير المعتمدة."
      },
      "editorial": {
        "purpose": null,
        "purposeAr": null,
        "checks": [
          "Only entity approved platforms are used for official meetings, calls, messaging and screen sharing.",
          "Personal or unapproved apps are not used for work data or meetings.",
          "Unauthorized remote control tools are not used for work.",
          "A list of approved platforms is maintained.",
          "Staff are made aware of the approved platform list.",
          "Installation or use of unapproved tools on corporate devices is restricted by configuration where feasible."
        ],
        "checksAr": [
          "تستخدم المنصات المعتمدة من الجهة وحدها للاجتماعات والمكالمات والمراسلة ومشاركة الشاشة الرسمية.",
          "لا تستخدم التطبيقات الشخصية أو غير المعتمدة لبيانات العمل أو اجتماعاته.",
          "لا تستخدم أدوات التحكم عن بعد غير المصرح بها في العمل.",
          "تحفظ قائمة بالمنصات المعتمدة.",
          "الموظفون على علم بقائمة المنصات المعتمدة.",
          "تثبيت الأدوات غير المعتمدة أو استخدامها على أجهزة الجهة مقيد بالإعدادات متى أمكن."
        ],
        "evidence": [
          "Approved collaboration platform list published to staff",
          "Application allow list or blocklist configuration from endpoint management",
          "Awareness communication announcing the list",
          "Exception records for any tolerated third party tool"
        ],
        "evidenceAr": [
          "قائمة منصات التعاون المعتمدة المعممة على الموظفين",
          "إعداد قائمة السماح أو الحجب للتطبيقات من نظام إدارة الأجهزة الطرفية",
          "تعميم توعوي يعلن القائمة",
          "سجلات الاستثناء لأي أداة طرف ثالث مسموح بها"
        ],
        "cadence": "continuous",
        "effort": "low",
        "phase": 2,
        "beyondAnnex": []
      },
      "appliesWhen": [],
      "crosswalk": {
        "csf": [
          "PR.PS-01",
          "GV.PO-01"
        ],
        "cis": [
          "2.3",
          "2.5",
          "2.7"
        ],
        "iso": [
          "A.5.14",
          "A.8.19"
        ]
      }
    },
    {
      "id": "PR-4.2",
      "function": "PR",
      "official": {
        "title": "Portable Media Device Control",
        "titleAr": "التحكم في وسائط التخزين الخارجية",
        "requirement": "Where feasible, restrict or technically disable the use of unapproved portable storage media (e.g., USB drives) on Entity systems, especially those handling Sensitive data. Establish procedures to allow only authorized portable media if necessary for business, and train staff on proper usage of portable media devices.",
        "requirementAr": "تقيد الجهة متى أمكن استخدام وسائط التخزين الخارجية غير المعتمدة كأقراص الناقل التسلسلي العام على أنظمتها أو تعطله تقنيا، ولا سيما الأنظمة التي تعالج بيانات حساسة، وتضع إجراءات لا تسمح إلا بوسائط التخزين الخارجية المصرح بها إذا اقتضت حاجة العمل ذلك، وتدرب الموظفين على الاستخدام السليم لأجهزة وسائط التخزين الخارجية.",
        "purpose": "Limit the risks from use of unapproved removable media devices.",
        "purposeAr": "الحد من مخاطر استخدام وسائط التخزين الخارجية غير المعتمدة."
      },
      "editorial": {
        "purpose": null,
        "purposeAr": null,
        "checks": [
          "Use of unapproved portable storage media is restricted or technically disabled where feasible.",
          "Systems handling Sensitive data receive the strictest portable media restriction.",
          "A procedure exists to authorize portable media where a business need exists.",
          "Only authorized portable media can be used.",
          "Staff are trained on proper usage of portable media devices."
        ],
        "checksAr": [
          "استخدام وسائط التخزين الخارجية غير المعتمدة مقيد أو معطل تقنيا متى أمكن.",
          "تخضع الأنظمة التي تعالج بيانات حساسة لأشد قيود وسائط التخزين الخارجية.",
          "يوجد إجراء لاعتماد وسائط التخزين الخارجية عند وجود حاجة عمل.",
          "وسائط التخزين الخارجية المصرح بها وحدها يمكن استخدامها.",
          "الموظفون مدربون على الاستخدام السليم لأجهزة وسائط التخزين الخارجية."
        ],
        "evidence": [
          "Endpoint policy showing removable media control settings",
          "Register of authorized media and their approvals",
          "Training module covering removable media",
          "Report of blocked device events"
        ],
        "evidenceAr": [
          "سياسة الأجهزة الطرفية تبين إعدادات التحكم في وسائط التخزين الخارجية",
          "سجل وسائط التخزين المصرح بها واعتماداتها",
          "وحدة تدريبية تغطي وسائط التخزين الخارجية",
          "تقرير أحداث الأجهزة المحجوبة"
        ],
        "cadence": "continuous",
        "effort": "low",
        "phase": 2,
        "beyondAnnex": []
      },
      "appliesWhen": [],
      "crosswalk": {
        "csf": [
          "PR.DS-01",
          "PR.PS-01"
        ],
        "cis": [
          "10.3",
          "10.4",
          "3.9"
        ],
        "iso": [
          "A.7.10",
          "A.8.7"
        ]
      }
    },
    {
      "id": "PR-5",
      "function": "PR",
      "official": {
        "title": "Data Protection, Backup & Lifecycle",
        "titleAr": "حماية البيانات والنسخ الاحتياطي ودورة حياتها",
        "requirement": "Implement regular, automated backups for critical systems and data, with priority to Sensitive and Restricted data. Store backups in at least one separate location (for example, a separate network segment, storage system, or cloud account). Protect backup data from unauthorized access and tampering (e.g., access controls, encryption). Test restoration of backups for key systems at least annually. Define and apply retention periods and secure disposal procedures aligned with legal requirements and the National Data Classification Framework, ensuring Sensitive data is securely erased or destroyed when no longer needed. For Sensitive data, if backups involve storage outside Kuwait (such as cloud backups), obtain any required approvals in line with data sovereignty requirements.",
        "requirementAr": "تنفذ الجهة نسخا احتياطية آلية منتظمة للأنظمة والبيانات الحرجة مع إعطاء الأولوية للبيانات الحساسة والمقيدة، وتحفظ النسخ في موقع منفصل واحد على الأقل كمقطع شبكي مستقل أو نظام تخزين آخر أو حساب سحابي، وتحمي بيانات النسخ الاحتياطي من الوصول غير المصرح به ومن العبث بضوابط الوصول والتشفير، وتختبر استعادة النسخ للأنظمة الرئيسية سنويا على الأقل، وتحدد وتطبق مدد الحفظ وإجراءات الإتلاف الآمن بما يتوافق مع المتطلبات القانونية ومع الإطار الوطني لتصنيف البيانات وبما يضمن محو البيانات الحساسة أو إتلافها بصورة آمنة عند انتفاء الحاجة إليها، أما البيانات الحساسة فإذا انطوت نسخها الاحتياطية على حفظ خارج الكويت كالنسخ السحابية وجب الحصول على أي موافقات مطلوبة وفق متطلبات سيادة البيانات.",
        "purpose": "Ensure critical data is appropriately protected, can be restored, and is disposed of safely.",
        "purposeAr": "ضمان حماية البيانات الحرجة على النحو المناسب وإمكانية استعادتها والتخلص منها بأمان."
      },
      "editorial": {
        "purpose": null,
        "purposeAr": null,
        "checks": [
          "Regular automated backups run for critical systems and data.",
          "Sensitive and Restricted data receive backup priority.",
          "Backups are stored in at least one separate location.",
          "Backup data is protected from unauthorized access.",
          "Backup data is protected from tampering.",
          "Restoration of backups for key systems is tested at least annually.",
          "Retention periods are defined and applied.",
          "Secure disposal procedures are defined and applied.",
          "Retention and disposal align with legal requirements and the National Data Classification Framework.",
          "Sensitive data is securely erased or destroyed when no longer needed.",
          "Backups of Sensitive data held outside Kuwait carry the required approvals."
        ],
        "checksAr": [
          "تجرى نسخ احتياطية آلية منتظمة للأنظمة والبيانات الحرجة.",
          "تعطى البيانات الحساسة والمقيدة أولوية في النسخ الاحتياطي.",
          "تحفظ النسخ الاحتياطية في موقع منفصل واحد على الأقل.",
          "بيانات النسخ الاحتياطي محمية من الوصول غير المصرح به.",
          "بيانات النسخ الاحتياطي محمية من العبث.",
          "تختبر استعادة النسخ الاحتياطية للأنظمة الرئيسية سنويا على الأقل.",
          "مدد الحفظ محددة ومطبقة.",
          "إجراءات الإتلاف الآمن محددة ومطبقة.",
          "الحفظ والإتلاف متوائمان مع المتطلبات القانونية ومع الإطار الوطني لتصنيف البيانات.",
          "تمحى البيانات الحساسة أو تتلف بصورة آمنة عند انتفاء الحاجة إليها.",
          "تحمل النسخ الاحتياطية للبيانات الحساسة المحفوظة خارج الكويت الموافقات المطلوبة."
        ],
        "evidence": [
          "Backup schedule and last thirty days of job success reports",
          "Architecture note showing the separate backup location",
          "Backup encryption and access control configuration",
          "Restore test report with date, scope and outcome",
          "Retention schedule and destruction certificates"
        ],
        "evidenceAr": [
          "جدول النسخ الاحتياطي وتقارير نجاح المهام لآخر ثلاثين يوما",
          "مذكرة معمارية تبين موقع النسخ الاحتياطي المنفصل",
          "إعداد تشفير النسخ الاحتياطية وضوابط الوصول إليها",
          "تقرير اختبار الاستعادة مع التاريخ والنطاق والنتيجة",
          "جدول الحفظ وشهادات الإتلاف"
        ],
        "cadence": "annual",
        "effort": "high",
        "phase": 1,
        "beyondAnnex": []
      },
      "appliesWhen": [],
      "crosswalk": {
        "csf": [
          "PR.DS-11",
          "PR.DS-01",
          "PR.DS-10"
        ],
        "cis": [
          "11.1",
          "11.2",
          "11.3",
          "11.4",
          "11.5",
          "3.5"
        ],
        "iso": [
          "A.8.13",
          "A.8.10",
          "A.8.24"
        ]
      }
    },
    {
      "id": "PR-6",
      "function": "PR",
      "official": {
        "title": "Physical Protection of Critical IT Assets",
        "titleAr": "الحماية المادية للأصول التقنية الحرجة",
        "requirement": "Identify critical IT areas (for example, data centers, server rooms, main network rooms, and locations where backup media are stored) and keep a simple list of them. For these areas, implement basic physical protections appropriate to the site, including at least:\n• Doors or cabinets that can be locked when the area is unattended.\n• Restricted access so that only authorized personnel can enter or unlock equipment (for example, keys, access cards, or codes managed by IT or facilities).\n• A simple record of non-routine visitors (such as contractors or vendors) to critical IT areas, which MAY be kept using existing building or guard logs.\nStore backup media and portable equipment (such as laptops) in a locked room or cabinet when not in use; avoid leaving them unattended in public or shared areas. This control focuses on the physical protection of IT assets and SHOULD make use of the entity’s existing building or facility security arrangements wherever possible.",
        "requirementAr": "تحدد الجهة المناطق التقنية الحرجة كمراكز البيانات وغرف الخوادم وغرف الشبكة الرئيسية ومواقع حفظ وسائط النسخ الاحتياطي وتحفظ قائمة مبسطة بها، وتطبق على هذه المناطق حمايات مادية أساسية تناسب الموقع تشمل كحد أدنى ما يلي:\n• أبوابا أو خزائن يمكن قفلها عند خلو المنطقة.\n• وصولا مقيدا بحيث لا يدخل أو يفتح المعدات إلا المخولون، وذلك مثلا بمفاتيح أو بطاقات دخول أو رموز تديرها تقنية المعلومات أو إدارة المرافق.\n• سجلا مبسطا للزوار غير المعتادين كالمقاولين والموردين إلى المناطق التقنية الحرجة، ويجوز حفظه ضمن سجلات المبنى أو الحراسة القائمة.\nوتحفظ وسائط النسخ الاحتياطي والمعدات المحمولة كالحواسيب المحمولة في غرفة أو خزانة مقفلة عند عدم الاستخدام، مع تجنب تركها دون رقابة في الأماكن العامة أو المشتركة، ويركز هذا الضابط على الحماية المادية للأصول التقنية وينبغي أن يستفيد من ترتيبات أمن المبنى أو المرافق القائمة لدى الجهة حيثما أمكن.",
        "purpose": "Reduce the risk of tampering, theft or damage to critical IT equipment.",
        "purposeAr": "تقليل مخاطر العبث بالمعدات التقنية الحرجة أو سرقتها أو إتلافها."
      },
      "editorial": {
        "purpose": null,
        "purposeAr": null,
        "checks": [
          "Critical IT areas are identified and listed.",
          "Doors or cabinets in critical IT areas can be locked when unattended.",
          "Access is restricted so only authorized personnel can enter or unlock equipment.",
          "Keys, access cards or codes are managed by IT or facilities.",
          "A record of non routine visitors to critical IT areas is kept.",
          "Backup media are stored in a locked room or cabinet when not in use.",
          "Portable equipment is stored in a locked room or cabinet when not in use.",
          "Equipment is not left unattended in public or shared areas."
        ],
        "checksAr": [
          "المناطق التقنية الحرجة محددة ومدرجة في قائمة.",
          "يمكن قفل الأبواب أو الخزائن في المناطق التقنية الحرجة عند خلوها.",
          "الوصول مقيد بحيث لا يدخل أو يفتح المعدات إلا المخولون.",
          "تدار المفاتيح وبطاقات الدخول والرموز من تقنية المعلومات أو إدارة المرافق.",
          "يحفظ سجل بالزوار غير المعتادين للمناطق التقنية الحرجة.",
          "تحفظ وسائط النسخ الاحتياطي في غرفة أو خزانة مقفلة عند عدم الاستخدام.",
          "تحفظ المعدات المحمولة في غرفة أو خزانة مقفلة عند عدم الاستخدام.",
          "لا تترك المعدات دون رقابة في الأماكن العامة أو المشتركة."
        ],
        "evidence": [
          "List of critical IT areas",
          "Access card holder list for each area with authorization basis",
          "Visitor log samples covering contractor and vendor entry",
          "Photographs or inspection notes of media storage arrangements"
        ],
        "evidenceAr": [
          "قائمة المناطق التقنية الحرجة",
          "قائمة حاملي بطاقات الدخول لكل منطقة مع أساس التخويل",
          "عينات من سجل الزوار تغطي دخول المقاولين والموردين",
          "صور أو ملاحظات تفتيش لترتيبات حفظ الوسائط"
        ],
        "cadence": "annual",
        "effort": "low",
        "phase": 2,
        "beyondAnnex": []
      },
      "appliesWhen": [],
      "crosswalk": {
        "csf": [
          "PR.AA-06",
          "ID.AM-01"
        ],
        "cis": [
          "1.1",
          "12.1"
        ],
        "iso": [
          "A.7.1",
          "A.7.2",
          "A.7.3",
          "A.7.4",
          "A.7.10"
        ]
      }
    },
    {
      "id": "DE-1",
      "function": "DE",
      "official": {
        "title": "Audit Logging & Monitoring",
        "titleAr": "تسجيل الأحداث والمراقبة",
        "requirement": "Enable audit logging on critical systems, network devices, security tools, and key applications. At minimum, log authentication events, administrative actions, and important security events. Where feasible, centralize logs into a basic logging solution for easier review.\n• Restrict access to logs to authorized personnel only and protect logs from unauthorized modification or deletion (including logging configuration changes), prioritizing Critical Systems and the central logging solution where used.\n• Retain logs for at least 90 days live and 12 months in total (live or archived). Review logs for suspicious activity at a frequency appropriate to the Entity’s risk (for example, weekly for smaller Entities, daily for higher-risk environments).",
        "requirementAr": "تفعل الجهة تسجيل التدقيق على الأنظمة الحرجة وأجهزة الشبكة وأدوات الأمن والتطبيقات الرئيسية، وتسجل كحد أدنى أحداث المصادقة والإجراءات الإدارية والأحداث الأمنية المهمة، وتجمع السجلات مركزيا في نظام تسجيل مركزي متى كان ذلك ممكنا تيسيرا للمراجعة.\n• ويقصر الوصول إلى السجلات على المخولين وحدهم، وتحمى السجلات من التعديل أو الحذف غير المصرح به بما في ذلك تغييرات إعدادات التسجيل، مع إعطاء الأولوية للأنظمة الحرجة ولحل التسجيل المركزي حيثما استخدم.\n• وتحفظ السجلات تسعين يوما على الأقل بصورة حية واثني عشر شهرا إجمالا حية كانت أو مؤرشفة، وتراجع بحثا عن نشاط مشبوه بوتيرة تناسب مخاطر الجهة، فأسبوعيا مثلا للجهات الأصغر ويوميا للبيئات الأعلى خطورة.",
        "purpose": "Provide visibility into suspicious activity and support investigations.",
        "purposeAr": "إتاحة رؤية للأنشطة المشبوهة ودعم التحقيقات."
      },
      "editorial": {
        "purpose": null,
        "purposeAr": null,
        "checks": [
          "Audit logging is enabled on critical systems.",
          "Audit logging is enabled on network devices.",
          "Audit logging is enabled on security tools.",
          "Audit logging is enabled on key applications.",
          "Authentication events are logged.",
          "Administrative actions are logged.",
          "Important security events are logged.",
          "Logs are centralized into a logging solution where feasible.",
          "Access to logs is restricted to authorized personnel only.",
          "Logs are protected from unauthorized modification or deletion.",
          "Changes to logging configuration are themselves logged.",
          "Logs are retained at least 90 days live.",
          "Logs are retained at least 12 months in total, live or archived.",
          "Logs are reviewed for suspicious activity at a frequency matched to entity risk."
        ],
        "checksAr": [
          "تسجيل التدقيق مفعل على الأنظمة الحرجة.",
          "تسجيل التدقيق مفعل على أجهزة الشبكة.",
          "تسجيل التدقيق مفعل على أدوات الأمن.",
          "تسجيل التدقيق مفعل على التطبيقات الرئيسية.",
          "أحداث المصادقة مسجلة.",
          "الإجراءات الإدارية مسجلة.",
          "الأحداث الأمنية المهمة مسجلة.",
          "تجمع السجلات مركزيا في نظام تسجيل مركزي متى أمكن.",
          "الوصول إلى السجلات مقصور على المخولين فقط.",
          "السجلات محمية من التعديل أو الحذف غير المصرح به.",
          "تسجل التغييرات على إعدادات التسجيل هي نفسها.",
          "تحفظ السجلات تسعين يوما على الأقل بصورة حية.",
          "تحفظ السجلات اثني عشر شهرا على الأقل إجمالا حية كانت أو مؤرشفة.",
          "تراجع السجلات بحثا عن نشاط مشبوه بوتيرة تناسب مخاطر الجهة."
        ],
        "evidence": [
          "Logging configuration export from a sample of critical systems",
          "Central log platform onboarding list against the asset inventory",
          "Retention policy configuration proving 90 day live and 12 month total",
          "Log review records with reviewer, date and findings"
        ],
        "evidenceAr": [
          "تصدير إعدادات التسجيل من عينة من الأنظمة الحرجة",
          "قائمة الأنظمة المرتبطة بمنصة السجلات المركزية مقارنة بحصر الأصول",
          "إعداد سياسة الحفظ يثبت تسعين يوما حية واثني عشر شهرا إجمالا",
          "محاضر مراجعة السجلات مع اسم المراجع والتاريخ والنتائج"
        ],
        "cadence": "weekly",
        "effort": "high",
        "phase": 2,
        "beyondAnnex": []
      },
      "appliesWhen": [],
      "crosswalk": {
        "csf": [
          "DE.CM-01",
          "DE.CM-03",
          "PR.PS-04"
        ],
        "cis": [
          "8.1",
          "8.2",
          "8.5",
          "8.9",
          "8.10",
          "8.11"
        ],
        "iso": [
          "A.8.15",
          "A.8.16"
        ]
      }
    },
    {
      "id": "DE-2",
      "function": "DE",
      "official": {
        "title": "Time Synchronization",
        "titleAr": "مزامنة الوقت",
        "requirement": "Ensure all information systems (servers, workstations, network devices) synchronize their system clocks to a reliable, authoritative time source (e.g., NTP). Timestamps in logs MUST be consistent across the infrastructure. Periodically verify that system clocks remain in sync (for example, by comparing log timestamps from different systems).",
        "requirementAr": "تضمن الجهة أن تزامن جميع أنظمة المعلومات، من خوادم ومحطات عمل وأجهزة شبكة، ساعاتها مع مصدر زمني موثوق ومعتمد مثل بروتوكول توقيت الشبكة، ويجب أن تكون الطوابع الزمنية في السجلات متسقة عبر البنية التحتية، مع التحقق دوريا من بقاء ساعات الأنظمة متزامنة وذلك مثلا بمقارنة الطوابع الزمنية الواردة من أنظمة مختلفة.",
        "purpose": "Ensure consistent timestamps across systems to facilitate incident investigation.",
        "purposeAr": "ضمان اتساق الطوابع الزمنية بين الأنظمة لتيسير التحقيق في الحوادث."
      },
      "editorial": {
        "purpose": null,
        "purposeAr": null,
        "checks": [
          "Servers synchronize their clocks to a reliable authoritative time source.",
          "Workstations synchronize their clocks to a reliable authoritative time source.",
          "Network devices synchronize their clocks to a reliable authoritative time source.",
          "Log timestamps are consistent across the infrastructure.",
          "System clock synchronization is verified periodically."
        ],
        "checksAr": [
          "تزامن الخوادم ساعاتها مع مصدر زمني موثوق ومعتمد.",
          "تزامن محطات العمل ساعاتها مع مصدر زمني موثوق ومعتمد.",
          "تزامن أجهزة الشبكة ساعاتها مع مصدر زمني موثوق ومعتمد.",
          "الطوابع الزمنية في السجلات متسقة عبر البنية التحتية.",
          "تزامن ساعات الأنظمة يتحقق منه دوريا."
        ],
        "evidence": [
          "NTP configuration standard and the authoritative source in use",
          "Time drift report or comparison of timestamps across systems",
          "Group policy or configuration management proof of enforcement"
        ],
        "evidenceAr": [
          "معيار إعداد بروتوكول توقيت الشبكة والمصدر المعتمد المستخدم",
          "تقرير انحراف التوقيت أو مقارنة الطوابع الزمنية عبر الأنظمة",
          "ما يثبت الإلزام عبر سياسة المجموعة أو إدارة الإعدادات"
        ],
        "cadence": "quarterly",
        "effort": "low",
        "phase": 1,
        "beyondAnnex": []
      },
      "appliesWhen": [],
      "crosswalk": {
        "csf": [
          "DE.CM-01",
          "PR.PS-01"
        ],
        "cis": [
          "8.4"
        ],
        "iso": [
          "A.8.17"
        ]
      }
    },
    {
      "id": "RS-1",
      "function": "RS",
      "official": {
        "title": "Incident Reporting to NCSC & Leadership",
        "titleAr": "الإبلاغ عن الحوادث للمركز وللإدارة العليا",
        "requirement": "Establish and communicate a simple incident reporting process so that staff know how to report suspected incidents (for example, phishing, data loss, or system compromise). Appoint one person as the incident response lead and at least one backup to coordinate incident handling, even if external service providers are used. Maintain up-to-date contact details for the incident lead, backup, relevant service providers, and NCSC. Where an actual or suspected cybersecurity incident or threat may be reportable under NCSC-issued incident management or reporting guidance, the Entity MUST notify NCSC promptly through the official channels and within the applicable timelines set by NCSC. Where appropriate, the Entity MUST use out-of-band communication channels during active incidents or where normal channels may be affected. The Entity MUST provide follow-up updates and information as required by applicable NCSC reporting guidance.",
        "requirementAr": "تنشئ الجهة آلية مبسطة للإبلاغ عن الحوادث وتعممها بحيث يعرف الموظفون كيف يبلغون عن الحوادث المشتبه بها، ومنها مثلا التصيد أو فقد البيانات أو اختراق الأنظمة، وتعين شخصا واحدا مسؤولا عن الاستجابة للحوادث وبديلا واحدا على الأقل لتنسيق التعامل معها حتى مع الاستعانة بمزودي خدمة خارجيين، وتحفظ بيانات اتصال محدثة للمسؤول وبديله ولمزودي الخدمة المعنيين وللمركز، وحيثما كان الحادث أو التهديد السيبراني القائم أو المشتبه به مما يجب الإبلاغ عنه بموجب إرشادات المركز في إدارة الحوادث أو الإبلاغ عنها، وجب على الجهة إخطار المركز فورا عبر القنوات الرسمية وضمن المهل التي يحددها، وعند الاقتضاء يجب على الجهة استخدام قنوات اتصال بديلة أثناء الحوادث النشطة أو حين تتأثر القنوات المعتادة، كما يجب عليها تقديم التحديثات والمعلومات اللاحقة وفق إرشادات الإبلاغ المعمول بها لدى المركز.",
        "purpose": "Ensure serious incidents are reported to NCSC and handled by designated leaders.",
        "purposeAr": "ضمان الإبلاغ عن الحوادث الجسيمة للمركز وإسناد معالجتها إلى مسؤولين محددين."
      },
      "editorial": {
        "purpose": null,
        "purposeAr": null,
        "checks": [
          "A simple incident reporting process is established.",
          "The reporting process is communicated so staff know how to report suspected incidents.",
          "One person is appointed as incident response lead.",
          "At least one backup to the incident response lead is appointed.",
          "The appointment holds even where external service providers are used.",
          "Contact details are current for the incident lead and backup.",
          "Contact details are current for relevant service providers.",
          "Contact details are current for NCSC.",
          "Reportable incidents are notified to NCSC promptly through official channels.",
          "Notification meets the applicable timelines set by NCSC.",
          "Out of band communication channels are available for use during active incidents.",
          "Follow up updates are provided to NCSC as required by reporting guidance."
        ],
        "checksAr": [
          "توجد آلية مبسطة للإبلاغ عن الحوادث.",
          "آلية الإبلاغ معممة بحيث يعرف الموظفون كيف يبلغون عن الحوادث المشتبه بها.",
          "يعين شخص واحد مسؤولا عن الاستجابة للحوادث.",
          "يعين بديل واحد على الأقل لمسؤول الاستجابة للحوادث.",
          "التعيين قائم حتى مع الاستعانة بمزودي خدمة خارجيين.",
          "بيانات الاتصال محدثة لمسؤول الحوادث وبديله.",
          "بيانات الاتصال محدثة لمزودي الخدمة المعنيين.",
          "بيانات الاتصال محدثة للمركز.",
          "تبلغ الحوادث الواجب الإبلاغ عنها للمركز فورا عبر القنوات الرسمية.",
          "يلتزم الإبلاغ بالمهل التي يحددها المركز.",
          "تتوافر قنوات اتصال بديلة للاستخدام أثناء الحوادث النشطة.",
          "تقدم التحديثات اللاحقة للمركز وفق إرشادات الإبلاغ."
        ],
        "evidence": [
          "Published incident reporting procedure and the channel staff use",
          "Appointment record for the incident lead and backup",
          "Contact directory including NCSC official channels",
          "Notification records for any incident in the reporting period",
          "Out of band channel description and test record"
        ],
        "evidenceAr": [
          "إجراء الإبلاغ عن الحوادث المعمم والقناة التي يستخدمها الموظفون",
          "محضر تعيين مسؤول الحوادث وبديله",
          "دليل جهات الاتصال شاملا القنوات الرسمية للمركز",
          "سجلات الإبلاغ عن أي حادث خلال فترة التقرير",
          "وصف القناة البديلة ومحضر اختبارها"
        ],
        "cadence": "continuous",
        "effort": "medium",
        "phase": 1,
        "beyondAnnex": []
      },
      "appliesWhen": [],
      "crosswalk": {
        "csf": [
          "RS.CO-02",
          "RS.CO-03",
          "RS.MA-01"
        ],
        "cis": [
          "17.1",
          "17.2",
          "17.3",
          "17.5"
        ],
        "iso": [
          "A.5.24",
          "A.5.25",
          "A.6.8"
        ]
      }
    },
    {
      "id": "RS-2",
      "function": "RS",
      "official": {
        "title": "Basic Incident Handling & Coordination",
        "titleAr": "التعامل الأساسي مع الحوادث والتنسيق بشأنها",
        "requirement": "Maintain a short written incident response procedure that covers: initial triage, containment, communication, evidence preservation, recovery, and reporting/escalation (including when and how to notify NCSC and other regulators or law enforcement). When NCSC or another competent authority notifies the entity of a potential incident, promptly triage and investigate, take reasonable remedial actions, and provide feedback where requested. After significant incidents, perform a brief lessons-learned review and record key improvements to be implemented, and share relevant lessons learned with NCSC or sector authorities where appropriate.",
        "requirementAr": "تحفظ الجهة إجراء مكتوبا موجزا للاستجابة للحوادث يغطي الفرز الأولي والاحتواء والتواصل وحفظ الأدلة والتعافي والإبلاغ والتصعيد بما في ذلك متى وكيف يخطر المركز وسائر الجهات الرقابية أو جهات إنفاذ القانون، وحين يخطر المركز أو جهة مختصة أخرى الجهة بحادث محتمل، تفرزه وتحقق فيه فورا وتتخذ إجراءات معالجة معقولة وتقدم تغذية راجعة عند طلبها، وبعد الحوادث الجوهرية تجري مراجعة موجزة للدروس المستفادة وتسجل التحسينات الرئيسية الواجب تنفيذها وتشارك الدروس ذات الصلة مع المركز أو جهات القطاع عند الاقتضاء.",
        "purpose": "Provide a structured but simple way to handle incidents and cooperate with NCSC.",
        "purposeAr": "توفير أسلوب منظم وبسيط لمعالجة الحوادث والتعاون مع المركز."
      },
      "editorial": {
        "purpose": null,
        "purposeAr": null,
        "checks": [
          "A written incident response procedure exists.",
          "The procedure covers initial triage.",
          "The procedure covers containment.",
          "The procedure covers communication.",
          "The procedure covers evidence preservation.",
          "The procedure covers recovery.",
          "The procedure covers reporting and escalation including NCSC, regulators and law enforcement.",
          "Notifications from NCSC or another competent authority are triaged and investigated promptly.",
          "Reasonable remedial actions are taken in response to such notifications.",
          "Feedback is provided to the notifying authority where requested.",
          "A lessons learned review follows every significant incident.",
          "Key improvements from lessons learned are recorded.",
          "Relevant lessons learned are shared with NCSC or sector authorities where appropriate."
        ],
        "checksAr": [
          "يوجد إجراء مكتوب للاستجابة للحوادث.",
          "يغطي الإجراء الفرز الأولي.",
          "يغطي الإجراء الاحتواء.",
          "يغطي الإجراء التواصل.",
          "يغطي الإجراء حفظ الأدلة.",
          "يغطي الإجراء التعافي.",
          "يغطي الإجراء الإبلاغ والتصعيد شاملا المركز والجهات الرقابية وجهات إنفاذ القانون.",
          "تفرز الإخطارات الواردة من المركز أو من جهة مختصة أخرى ويحقق فيها فورا.",
          "تتخذ إجراءات معالجة معقولة استجابة لتلك الإخطارات.",
          "تقدم تغذية راجعة للجهة المخطرة عند طلبها.",
          "تجرى مراجعة للدروس المستفادة عقب كل حادث جوهري.",
          "التحسينات الرئيسية المستخلصة من الدروس المستفادة مسجلة.",
          "تشارك الدروس المستفادة ذات الصلة مع المركز أو جهات القطاع عند الاقتضاء."
        ],
        "evidence": [
          "Incident response procedure covering the six required stages",
          "Ticket history showing triage of authority notifications",
          "Lessons learned reports for significant incidents",
          "Improvement tracker linked to incident findings"
        ],
        "evidenceAr": [
          "إجراء الاستجابة للحوادث يغطي المراحل الست المطلوبة",
          "سجل التذاكر يبين فرز إخطارات الجهات المختصة",
          "تقارير الدروس المستفادة للحوادث الجوهرية",
          "سجل متابعة التحسينات مرتبطا بنتائج الحوادث"
        ],
        "cadence": "per incident",
        "effort": "medium",
        "phase": 2,
        "beyondAnnex": []
      },
      "appliesWhen": [],
      "crosswalk": {
        "csf": [
          "RS.MA-02",
          "RS.MI-01",
          "RS.AN-03",
          "ID.IM-04"
        ],
        "cis": [
          "17.4",
          "17.6",
          "17.8"
        ],
        "iso": [
          "A.5.26",
          "A.5.27",
          "A.5.28"
        ]
      }
    },
    {
      "id": "RC-1",
      "function": "RC",
      "official": {
        "title": "Recovery Planning",
        "titleAr": "التخطيط للتعافي",
        "requirement": "Maintain a simple recovery plan or documented procedures for restoring critical systems and services after incidents or other disruptions. The plan SHOULD reference backup locations, key contacts, and any sequencing needed for restoration, especially for Sensitive and Restricted data. Review and update the plan at least annually and after major changes.",
        "requirementAr": "تحفظ الجهة خطة تعاف مبسطة أو إجراءات موثقة لاستعادة الأنظمة والخدمات الحرجة بعد الحوادث أو غيرها من حالات التعطل، وينبغي أن تشير الخطة إلى مواقع النسخ الاحتياطية وجهات الاتصال الرئيسية وأي ترتيب لازم لعمليات الاستعادة ولا سيما بالنسبة للبيانات الحساسة والمقيدة، وتراجع الخطة وتحدث سنويا على الأقل وبعد التغييرات الجوهرية.",
        "purpose": "Support structured recovery after incidents and disruptions.",
        "purposeAr": "دعم التعافي المنظم بعد الحوادث والاضطرابات."
      },
      "editorial": {
        "purpose": null,
        "purposeAr": null,
        "checks": [
          "A recovery plan or documented restoration procedures exist for critical systems and services.",
          "The plan references backup locations.",
          "The plan references key contacts.",
          "The plan sets out any sequencing needed for restoration.",
          "Sequencing gives particular attention to Sensitive and Restricted data.",
          "The plan is reviewed and updated at least annually.",
          "The plan is reviewed and updated after major changes."
        ],
        "checksAr": [
          "توجد خطة تعاف أو إجراءات استعادة موثقة للأنظمة والخدمات الحرجة.",
          "تشير الخطة إلى مواقع النسخ الاحتياطية.",
          "تشير الخطة إلى جهات الاتصال الرئيسية.",
          "تبين الخطة أي ترتيب لازم لعمليات الاستعادة.",
          "يولي الترتيب عناية خاصة للبيانات الحساسة والمقيدة.",
          "تراجع الخطة وتحدث سنويا على الأقل.",
          "تراجع الخطة وتحدث عقب التغييرات الجوهرية."
        ],
        "evidence": [
          "Recovery plan document with version and review date",
          "Restoration runbook per critical system",
          "Contact list embedded in or attached to the plan",
          "Change record showing update after a major change"
        ],
        "evidenceAr": [
          "وثيقة خطة التعافي مع رقم الإصدار وتاريخ المراجعة",
          "دليل تشغيل الاستعادة لكل نظام حرج",
          "قائمة جهات الاتصال مدرجة في الخطة أو مرفقة بها",
          "محضر تغيير يبين التحديث عقب تغيير جوهري"
        ],
        "cadence": "annual",
        "effort": "medium",
        "phase": 2,
        "beyondAnnex": []
      },
      "appliesWhen": [],
      "crosswalk": {
        "csf": [
          "RC.RP-01",
          "RC.RP-03"
        ],
        "cis": [
          "11.1",
          "17.4"
        ],
        "iso": [
          "A.5.29",
          "A.5.30"
        ]
      }
    },
    {
      "id": "RC-2",
      "function": "RC",
      "official": {
        "title": "Testing & Continuous Improvement",
        "titleAr": "الاختبار والتحسين المستمر",
        "requirement": "Conduct basic recovery or continuity tests (for example, tabletop exercises or partial restoration tests) for critical systems at least annually. After tests or real incidents, capture lessons learned, update procedures and controls where practical, and track completion of agreed improvements.",
        "requirementAr": "تجري الجهة اختبارات أساسية للتعافي أو الاستمرارية للأنظمة الحرجة سنويا على الأقل، ومنها مثلا التمارين المكتبية أو اختبارات الاستعادة الجزئية، وبعد الاختبارات أو الحوادث الفعلية توثق الدروس المستفادة وتحدث الإجراءات والضوابط حيثما كان ذلك عمليا وتتابع إنجاز التحسينات المتفق عليها.",
        "purpose": "Ensure recovery works in practice and improvements are implemented.",
        "purposeAr": "التأكد من نجاعة التعافي عمليا وتنفيذ التحسينات."
      },
      "editorial": {
        "purpose": null,
        "purposeAr": null,
        "checks": [
          "Recovery or continuity tests are conducted for critical systems at least annually.",
          "Tests take a recognizable form such as a tabletop exercise or partial restoration test.",
          "Lessons learned are captured after tests.",
          "Lessons learned are captured after real incidents.",
          "Procedures and controls are updated where practical.",
          "Completion of agreed improvements is tracked."
        ],
        "checksAr": [
          "تجرى اختبارات التعافي أو الاستمرارية للأنظمة الحرجة سنويا على الأقل.",
          "تتخذ الاختبارات صورة معروفة كتمرين مكتبي أو اختبار استعادة جزئي.",
          "توثق الدروس المستفادة عقب الاختبارات.",
          "توثق الدروس المستفادة عقب الحوادث الفعلية.",
          "تحدث الإجراءات والضوابط حيثما كان ذلك عمليا.",
          "يتابع إنجاز التحسينات المتفق عليها."
        ],
        "evidence": [
          "Test plan and after action report for the current year",
          "Attendance record for the exercise",
          "Updated procedure versions traceable to test findings",
          "Improvement tracker with closure dates"
        ],
        "evidenceAr": [
          "خطة الاختبار وتقرير ما بعد التمرين للسنة الحالية",
          "كشف حضور التمرين",
          "إصدارات الإجراءات المحدثة مرتبطة بنتائج الاختبار",
          "سجل متابعة التحسينات مع تواريخ الإغلاق"
        ],
        "cadence": "annual",
        "effort": "medium",
        "phase": 3,
        "beyondAnnex": []
      },
      "appliesWhen": [],
      "crosswalk": {
        "csf": [
          "ID.IM-02",
          "RC.RP-05"
        ],
        "cis": [
          "11.5",
          "17.7"
        ],
        "iso": [
          "A.5.30"
        ]
      }
    },
    {
      "id": "CLD-1",
      "function": "CLD",
      "official": {
        "title": "Regulatory Authorization",
        "titleAr": "الترخيص التنظيمي",
        "requirement": "Entities MUST ensure the Cloud Service Provider (CSP) is authorized to operate in the State of Kuwait in accordance with regulations issued by the relevant national authorities",
        "requirementAr": "يجب على الجهات التأكد من أن مزود الخدمة السحابية مرخص له بالعمل في دولة الكويت وفقا للوائح الصادرة عن الجهات الوطنية المختصة",
        "purpose": null,
        "purposeAr": null
      },
      "editorial": {
        "purpose": "Confirm the provider may lawfully operate in Kuwait before it is engaged.",
        "purposeAr": "التحقق من أحقية المزود في العمل داخل الكويت قبل التعاقد معه.",
        "checks": [
          "Every cloud service provider in use is authorized to operate in the State of Kuwait.",
          "Authorization is verified against regulations issued by the relevant national authorities.",
          "Verification is recorded before the provider is engaged."
        ],
        "checksAr": [
          "كل مزود خدمة سحابية مستخدم مرخص له بالعمل في دولة الكويت.",
          "يتحقق من الترخيص مقابل اللوائح الصادرة عن الجهات الوطنية المختصة.",
          "يوثق التحقق قبل التعاقد مع المزود."
        ],
        "evidence": [
          "Copy of the provider authorization or licence",
          "Verification note in the procurement file",
          "Provider register entry linking to the authorization record"
        ],
        "evidenceAr": [
          "نسخة من ترخيص المزود أو تصريحه",
          "مذكرة التحقق ضمن ملف المشتريات",
          "مدخل في سجل المزودين يربط بوثيقة الترخيص"
        ],
        "cadence": "per engagement",
        "effort": "low",
        "phase": 1,
        "beyondAnnex": [
          2
        ]
      },
      "appliesWhen": [
        "usesCloud"
      ],
      "crosswalk": {
        "csf": [
          "GV.SC-03",
          "GV.OC-03"
        ],
        "cis": [
          "15.1"
        ],
        "iso": [
          "A.5.19",
          "A.5.31"
        ]
      }
    },
    {
      "id": "CLD-2",
      "function": "CLD",
      "official": {
        "title": "Provider Due Diligence",
        "titleAr": "العناية الواجبة بمزود الخدمة",
        "requirement": "Prior to selection, Entities MUST evaluate the CSP’s security posture. This requirement is satisfied by reviewing the CSP’s valid, independent international security certifications (e.g., ISO 27001, SOC 2 Type II, CSA STAR Level 2).",
        "requirementAr": "يجب على الجهات قبل الاختيار تقييم الوضع الأمني لمزود الخدمة السحابية، ويستوفى هذا المتطلب بمراجعة الشهادات الأمنية الدولية المستقلة السارية لدى المزود مثل الأيزو 27001 وSOC 2 Type II وCSA STAR المستوى الثاني.",
        "purpose": null,
        "purposeAr": null
      },
      "editorial": {
        "purpose": "Evaluate the security posture of the provider before selection.",
        "purposeAr": "تقييم الوضع الأمني للمزود قبل اختياره.",
        "checks": [
          "The security posture of the provider is evaluated before selection.",
          "The evaluation reviews valid independent international security certifications.",
          "Certification validity dates are checked and recorded."
        ],
        "checksAr": [
          "يقيم الوضع الأمني للمزود قبل اختياره.",
          "يراجع التقييم الشهادات الأمنية الدولية المستقلة السارية.",
          "تواريخ سريان الشهادات تفحص وتوثق."
        ],
        "evidence": [
          "Certification copies such as ISO 27001, SOC 2 Type II or CSA STAR Level 2",
          "Due diligence assessment record with reviewer and date",
          "Diary entry for the next certification expiry"
        ],
        "evidenceAr": [
          "نسخ الشهادات مثل الأيزو 27001 أو SOC 2 Type II أو CSA STAR المستوى الثاني",
          "محضر تقييم العناية الواجبة مع اسم المراجع والتاريخ",
          "قيد في التقويم بموعد انتهاء الشهادة التالي"
        ],
        "cadence": "per engagement",
        "effort": "low",
        "phase": 1,
        "beyondAnnex": [
          2
        ]
      },
      "appliesWhen": [
        "usesCloud"
      ],
      "crosswalk": {
        "csf": [
          "GV.SC-06",
          "GV.SC-07"
        ],
        "cis": [
          "15.3",
          "15.5"
        ],
        "iso": [
          "A.5.19",
          "A.5.21"
        ]
      }
    },
    {
      "id": "CLD-3",
      "function": "CLD",
      "official": {
        "title": "Right to Audit (Third-Party Assurance)",
        "titleAr": "حق التدقيق (تأكيدات الأطراف الخارجية)",
        "requirement": "Contracts MUST include a \"Right to Audit.\" To protect the security of multi-tenant environments, this right is exercised by the Entity reviewing the CSP’s independent Third-Party Audit Reports (e.g., SOC 2, C5) rather than conducting physical data center visits.",
        "requirementAr": "يجب أن تتضمن العقود حق التدقيق، وحماية لأمن البيئات متعددة المستأجرين يمارس هذا الحق بمراجعة الجهة لتقارير التدقيق المستقلة الصادرة عن طرف ثالث لدى المزود مثل SOC 2 وC5 بدلا من إجراء زيارات مادية لمراكز البيانات.",
        "purpose": null,
        "purposeAr": null
      },
      "editorial": {
        "purpose": "Preserve assurance over a shared environment without physical inspection.",
        "purposeAr": "الحصول على تأكيد بشأن البيئة المشتركة دون الحاجة إلى زيارة ميدانية.",
        "checks": [
          "Every cloud contract includes a right to audit clause.",
          "The right is exercised by reviewing independent third party audit reports.",
          "Reports are obtained and reviewed rather than physical data center visits being sought."
        ],
        "checksAr": [
          "يتضمن كل عقد سحابي بندا بحق التدقيق.",
          "يمارس الحق عبر مراجعة تقارير تدقيق مستقلة من طرف ثالث.",
          "تطلب التقارير وتراجع بدلا من السعي لزيارة مراكز البيانات ماديا."
        ],
        "evidence": [
          "Contract clause reference for each cloud agreement",
          "Latest third party audit report on file such as SOC 2 or C5",
          "Review note recording exceptions and their treatment"
        ],
        "evidenceAr": [
          "مرجع البند التعاقدي لكل اتفاقية سحابية",
          "أحدث تقرير تدقيق من طرف ثالث محفوظ مثل SOC 2 أو C5",
          "مذكرة مراجعة تسجل الملاحظات وكيفية معالجتها"
        ],
        "cadence": "annual",
        "effort": "low",
        "phase": 2,
        "beyondAnnex": []
      },
      "appliesWhen": [
        "usesCloud"
      ],
      "crosswalk": {
        "csf": [
          "GV.SC-05",
          "GV.SC-07"
        ],
        "cis": [
          "15.5"
        ],
        "iso": [
          "A.5.22",
          "A.5.35"
        ]
      }
    },
    {
      "id": "CLD-4",
      "function": "CLD",
      "official": {
        "title": "Incident Notification Clause",
        "titleAr": "شرط الإخطار بالحوادث",
        "requirement": "Contracts MUST include a commitment from the CSP to notify the Entity of a confirmed data incident without undue delay to allow for accurate investigation and reporting.",
        "requirementAr": "يجب أن تتضمن العقود التزاما من مزود الخدمة السحابية بإخطار الجهة بأي حادث مؤكد يمس البيانات دون تأخير غير مبرر بما يتيح التحقيق والإبلاغ على نحو دقيق.",
        "purpose": null,
        "purposeAr": null
      },
      "editorial": {
        "purpose": "Guarantee the entity learns of provider side incidents in time to act.",
        "purposeAr": "ضمان علم الجهة بحوادث المزود في وقت يسمح لها بالتصرف.",
        "checks": [
          "Every cloud contract commits the provider to notify the entity of a confirmed data incident.",
          "The commitment requires notification without undue delay.",
          "The notification path feeds the entity incident process under RS-1."
        ],
        "checksAr": [
          "يلزم كل عقد سحابي المزود بإخطار الجهة عند تأكد وقوع حادث يمس البيانات.",
          "يشترط الالتزام الإخطار دون تأخير غير مبرر.",
          "مسار الإخطار يغذي آلية الحوادث لدى الجهة وفق الضابط RS-1."
        ],
        "evidence": [
          "Contract clause reference for each cloud agreement",
          "Provider notification contact recorded in the incident contact list",
          "Any notification received and its handling record"
        ],
        "evidenceAr": [
          "مرجع البند التعاقدي لكل اتفاقية سحابية",
          "جهة اتصال الإخطار لدى المزود مدرجة في قائمة اتصال الحوادث",
          "أي إخطار ورد ومحضر التعامل معه"
        ],
        "cadence": "per engagement",
        "effort": "low",
        "phase": 1,
        "beyondAnnex": [
          2
        ]
      },
      "appliesWhen": [
        "usesCloud"
      ],
      "crosswalk": {
        "csf": [
          "GV.SC-08",
          "RS.CO-02"
        ],
        "cis": [
          "15.6",
          "17.2"
        ],
        "iso": [
          "A.5.22",
          "A.5.24"
        ]
      }
    },
    {
      "id": "CLD-5",
      "function": "CLD",
      "official": {
        "title": "Data Ownership & Exit",
        "titleAr": "ملكية البيانات وإنهاء الخدمة",
        "requirement": "The contract MUST explicitly state that the Entity retains exclusive ownership of their data. The CSP MUST provide tools or standard APIs to allow the Entity to retrieve their data upon contract termination.",
        "requirementAr": "يجب أن ينص العقد صراحة على احتفاظ الجهة بالملكية الحصرية لبياناتها، ويجب على مزود الخدمة السحابية توفير أدوات أو واجهات برمجية قياسية تمكن الجهة من استرجاع بياناتها عند إنهاء العقد.",
        "purpose": null,
        "purposeAr": null
      },
      "editorial": {
        "purpose": "Keep ownership with the entity and keep exit technically possible.",
        "purposeAr": "إبقاء ملكية البيانات لدى الجهة وإبقاء إنهاء الخدمة ممكنا من الناحية التقنية.",
        "checks": [
          "The contract explicitly states that the entity retains exclusive ownership of its data.",
          "The provider offers tools or standard APIs for data retrieval on termination.",
          "The retrieval route is identified and understood before it is needed."
        ],
        "checksAr": [
          "ينص العقد صراحة على احتفاظ الجهة بالملكية الحصرية لبياناتها.",
          "يوفر المزود أدوات أو واجهات برمجية قياسية لاسترجاع البيانات عند الإنهاء.",
          "مسار الاسترجاع محدد ومفهوم قبل الحاجة إليه."
        ],
        "evidence": [
          "Ownership clause reference for each cloud agreement",
          "Documented export path or API for the data held",
          "Exit plan note in the provider register"
        ],
        "evidenceAr": [
          "مرجع بند الملكية لكل اتفاقية سحابية",
          "مسار تصدير موثق أو واجهة برمجية للبيانات المحفوظة",
          "مذكرة خطة الخروج ضمن سجل المزودين"
        ],
        "cadence": "per engagement",
        "effort": "low",
        "phase": 2,
        "beyondAnnex": [
          2
        ]
      },
      "appliesWhen": [
        "usesCloud"
      ],
      "crosswalk": {
        "csf": [
          "GV.SC-10",
          "ID.AM-08"
        ],
        "cis": [
          "15.7"
        ],
        "iso": [
          "A.5.23",
          "A.5.9"
        ]
      }
    },
    {
      "id": "CLD-6",
      "function": "CLD",
      "official": {
        "title": "Service Level Agreements (SLAs)",
        "titleAr": "اتفاقيات مستوى الخدمة (SLA)",
        "requirement": "Contracts MUST define Service Level Agreements (SLAs) for availability. The agreement SHOULD include financial remedies (service credits) for failure to meet these standards.",
        "requirementAr": "يجب أن تحدد العقود اتفاقيات مستوى الخدمة الخاصة بالإتاحة، وينبغي أن تتضمن الاتفاقية تعويضات مالية في صورة أرصدة خدمة عند الإخفاق في بلوغ هذه المستويات.",
        "purpose": null,
        "purposeAr": null
      },
      "editorial": {
        "purpose": "Fix availability expectations and the remedy for missing them.",
        "purposeAr": "تثبيت التوقعات بشأن الإتاحة وتحديد التعويض عند الإخلال بها.",
        "checks": [
          "Every cloud contract defines a service level agreement for availability.",
          "The agreement includes financial remedies such as service credits.",
          "Achieved availability is compared against the agreed level."
        ],
        "checksAr": [
          "يحدد كل عقد سحابي اتفاقية مستوى خدمة للإتاحة.",
          "تتضمن الاتفاقية تعويضات مالية مثل أرصدة الخدمة.",
          "تقارن الإتاحة المتحققة بالمستوى المتفق عليه."
        ],
        "evidence": [
          "SLA schedule for each cloud agreement",
          "Service credit terms",
          "Availability reports for the reporting period"
        ],
        "evidenceAr": [
          "جدول اتفاقية مستوى الخدمة لكل اتفاقية سحابية",
          "شروط أرصدة الخدمة",
          "تقارير الإتاحة عن فترة التقرير"
        ],
        "cadence": "annual",
        "effort": "low",
        "phase": 3,
        "beyondAnnex": [
          2
        ]
      },
      "appliesWhen": [
        "usesCloud"
      ],
      "crosswalk": {
        "csf": [
          "GV.SC-05",
          "ID.AM-08"
        ],
        "cis": [
          "15.4"
        ],
        "iso": [
          "A.5.22",
          "A.5.30"
        ]
      }
    },
    {
      "id": "CLD-7",
      "function": "CLD",
      "official": {
        "title": "Shared Responsibility Matrix",
        "titleAr": "مصفوفة المسؤولية المشتركة",
        "requirement": "Entities MUST document the cloud service model (IaaS, PaaS, or SaaS) and the resulting division of security responsibilities. The Entity retains accountability for Data Classification, Identity & Access Management (IAM), and Resource Configuration, regardless of the model.",
        "requirementAr": "يجب على الجهات توثيق نموذج الخدمة السحابية سواء كان بنية تحتية كخدمة أو منصة كخدمة أو برمجية كخدمة، وتوثيق ما يترتب عليه من توزيع للمسؤوليات الأمنية، وتظل الجهة مسؤولة عن تصنيف البيانات وإدارة الهوية والوصول وتهيئة الموارد أيا كان النموذج.",
        "purpose": null,
        "purposeAr": null
      },
      "editorial": {
        "purpose": "Remove ambiguity about which party secures which layer.",
        "purposeAr": "إزالة الغموض بشأن الطرف المسؤول عن تأمين كل طبقة.",
        "checks": [
          "The cloud service model is documented for each service as IaaS, PaaS or SaaS.",
          "The resulting division of security responsibilities is documented.",
          "The entity accepts accountability for data classification regardless of model.",
          "The entity accepts accountability for identity and access management regardless of model.",
          "The entity accepts accountability for resource configuration regardless of model."
        ],
        "checksAr": [
          "نموذج الخدمة السحابية موثق لكل خدمة بوصفه بنية تحتية أو منصة أو برمجية كخدمة.",
          "توزيع المسؤوليات الأمنية المترتب على ذلك موثق.",
          "تقر الجهة بمسؤوليتها عن تصنيف البيانات أيا كان النموذج.",
          "تقر الجهة بمسؤوليتها عن إدارة الهوية والوصول أيا كان النموذج.",
          "تقر الجهة بمسؤوليتها عن تهيئة الموارد أيا كان النموذج."
        ],
        "evidence": [
          "Shared responsibility matrix per cloud service",
          "Service model field populated in the provider register",
          "Owner named for classification, IAM and configuration in each environment"
        ],
        "evidenceAr": [
          "مصفوفة المسؤولية المشتركة لكل خدمة سحابية",
          "حقل نموذج الخدمة مستوفى في سجل المزودين",
          "تسمية مالك للتصنيف وإدارة الهوية والتهيئة في كل بيئة"
        ],
        "cadence": "annual",
        "effort": "medium",
        "phase": 1,
        "beyondAnnex": []
      },
      "appliesWhen": [
        "usesCloud"
      ],
      "crosswalk": {
        "csf": [
          "GV.SC-04",
          "GV.RR-02"
        ],
        "cis": [
          "15.2"
        ],
        "iso": [
          "A.5.23"
        ]
      }
    },
    {
      "id": "CLD-8",
      "function": "CLD",
      "official": {
        "title": "Cloud Asset Inventory",
        "titleAr": "حصر الأصول السحابية",
        "requirement": "Maintain a real-time inventory of cloud resources. Use programmatic resource tagging to identify the Data Classification (Public, Restricted, Sensitive) and Business Owner of each resource.",
        "requirementAr": "تحفظ الجهة حصرا آنيا لموارد السحابة، وتستخدم الوسم البرمجي للموارد لتحديد تصنيف البيانات لكل مورد بوصفه عاما أو مقيدا أو حساسا وتحديد مالكه من جهة الأعمال.",
        "purpose": null,
        "purposeAr": null
      },
      "editorial": {
        "purpose": "Keep a live view of cloud resources and what they hold.",
        "purposeAr": "الاحتفاظ برؤية آنية للموارد السحابية ولما تحتويه.",
        "checks": [
          "A real time inventory of cloud resources is maintained.",
          "Programmatic resource tagging is in use.",
          "Tags identify the data classification of each resource as Public, Restricted or Sensitive.",
          "Tags identify the business owner of each resource."
        ],
        "checksAr": [
          "يحفظ حصر آني لموارد السحابة.",
          "الوسم البرمجي للموارد مستخدم.",
          "تبين الوسوم تصنيف بيانات كل مورد بوصفه عاما أو مقيدا أو حساسا.",
          "تبين الوسوم مالك المورد من جهة الأعمال."
        ],
        "evidence": [
          "Inventory export from the cloud provider or a cloud posture tool",
          "Tagging standard document",
          "Report of untagged or non compliant resources and their remediation"
        ],
        "evidenceAr": [
          "تصدير الحصر من مزود السحابة أو من أداة لمتابعة الوضع السحابي",
          "وثيقة معيار الوسم",
          "تقرير الموارد غير الموسومة أو غير الممتثلة وما اتخذ لمعالجتها"
        ],
        "cadence": "continuous",
        "effort": "medium",
        "phase": 2,
        "beyondAnnex": []
      },
      "appliesWhen": [
        "usesCloud"
      ],
      "crosswalk": {
        "csf": [
          "ID.AM-01",
          "ID.AM-07"
        ],
        "cis": [
          "1.1",
          "3.1"
        ],
        "iso": [
          "A.5.9"
        ]
      }
    },
    {
      "id": "CLD-9",
      "function": "CLD",
      "official": {
        "title": "MFA for Cloud Consoles",
        "titleAr": "المصادقة متعددة العوامل للوحات التحكم السحابية",
        "requirement": "Multi-Factor Authentication (MFA) MUST be enforced for all users with administrative access to the Cloud Management Console and root accounts.",
        "requirementAr": "يجب فرض المصادقة متعددة العوامل على جميع المستخدمين ذوي الوصول الإداري إلى لوحة الإدارة السحابية وعلى الحسابات الجذرية.",
        "purpose": null,
        "purposeAr": null
      },
      "editorial": {
        "purpose": "Protect the highest value credentials in the environment.",
        "purposeAr": "حماية أثمن بيانات الاعتماد في البيئة.",
        "checks": [
          "MFA is enforced for every user with administrative access to the cloud management console.",
          "MFA is enforced on root accounts.",
          "Enforcement is technical rather than advisory."
        ],
        "checksAr": [
          "المصادقة متعددة العوامل مفروضة على كل مستخدم له وصول إداري إلى لوحة الإدارة السحابية.",
          "المصادقة متعددة العوامل مفروضة على الحسابات الجذرية.",
          "الفرض تقني لا توجيهي."
        ],
        "evidence": [
          "MFA enforcement policy from the cloud identity provider",
          "Report listing every console administrator and MFA status",
          "Root account protection evidence including any break glass procedure"
        ],
        "evidenceAr": [
          "سياسة فرض المصادقة متعددة العوامل من مزود الهوية السحابي",
          "تقرير يعدد كل مدير للوحة الإدارة وحالة المصادقة متعددة العوامل لديه",
          "ما يثبت حماية الحساب الجذري بما في ذلك أي إجراء للوصول الطارئ"
        ],
        "cadence": "continuous",
        "effort": "low",
        "phase": 1,
        "beyondAnnex": [
          2
        ]
      },
      "appliesWhen": [
        "usesCloud"
      ],
      "crosswalk": {
        "csf": [
          "PR.AA-03",
          "PR.AA-05"
        ],
        "cis": [
          "6.5",
          "5.4"
        ],
        "iso": [
          "A.8.5"
        ]
      }
    },
    {
      "id": "CLD-10",
      "function": "CLD",
      "official": {
        "title": "Service Account Hygiene",
        "titleAr": "سلامة حسابات الخدمة",
        "requirement": "Service Accounts (non-human identities) MUST NOT be used for interactive human login. Keys for service accounts SHOULD be rotated periodically based on risk, or managed via automated identity federation (e.g., OIDC) to prevent credential theft.",
        "requirementAr": "لا يجوز استخدام حسابات الخدمة، أي الهويات غير البشرية، في الدخول التفاعلي البشري، وينبغي تدوير مفاتيح حسابات الخدمة دوريا بناء على المخاطر أو إدارتها عبر اتحاد هوية آلي مثل OIDC منعا لسرقة بيانات الاعتماد.",
        "purpose": null,
        "purposeAr": null
      },
      "editorial": {
        "purpose": "Prevent credential theft through long lived non human identities.",
        "purposeAr": "منع سرقة بيانات الاعتماد عبر الهويات غير البشرية طويلة الأمد.",
        "checks": [
          "Service accounts are not used for interactive human login.",
          "Service account keys are rotated periodically based on risk, or federation removes the need for static keys.",
          "Automated identity federation such as OIDC is used where available."
        ],
        "checksAr": [
          "لا تستخدم حسابات الخدمة للدخول التفاعلي البشري.",
          "تجدد مفاتيح حسابات الخدمة دوريا بحسب المخاطر أو يستعاض عنها باتحاد الهوية بدل المفاتيح الثابتة.",
          "يستخدم اتحاد الهوية الآلي مثل OIDC حيثما توفر."
        ],
        "evidence": [
          "Service account register with key age or federation status",
          "Policy statement prohibiting interactive use of service accounts",
          "Key rotation records or federation configuration"
        ],
        "evidenceAr": [
          "سجل حسابات الخدمة مع عمر المفاتيح أو حالة اتحاد الهوية",
          "نص السياسة الذي يحظر الاستخدام التفاعلي لحسابات الخدمة",
          "سجلات تجديد المفاتيح أو إعداد اتحاد الهوية"
        ],
        "cadence": "quarterly",
        "effort": "medium",
        "phase": 2,
        "beyondAnnex": []
      },
      "appliesWhen": [
        "usesCloud"
      ],
      "crosswalk": {
        "csf": [
          "PR.AA-01",
          "PR.AA-05"
        ],
        "cis": [
          "5.2",
          "5.4",
          "5.6"
        ],
        "iso": [
          "A.5.16",
          "A.5.17"
        ]
      }
    },
    {
      "id": "CLD-11",
      "function": "CLD",
      "official": {
        "title": "Encryption by Default",
        "titleAr": "التشفير الافتراضي",
        "requirement": "All data at rest in the cloud MUST be encrypted. Entities SHOULD utilize the CSP’s default encryption (platform-managed keys) as a minimum standard. For Sensitive data, Entities MAY opt for Customer-Managed Encryption Keys (CMEK) on cloud, based on a risk assessment. In accordance with Decision (1) of 2025.",
        "requirementAr": "يجب تشفير جميع البيانات المحفوظة في السحابة، وينبغي أن تستخدم الجهات التشفير الافتراضي لدى مزود الخدمة السحابية أي المفاتيح المدارة من المنصة بوصفه حدا أدنى، أما البيانات الحساسة فيجوز أن تختار الجهات لها مفاتيح تشفير يديرها العميل في السحابة بناء على تقييم للمخاطر، وذلك وفقا للقرار رقم 1 لسنة 2025.",
        "purpose": null,
        "purposeAr": null
      },
      "editorial": {
        "purpose": "Ensure stored data is unreadable without the key.",
        "purposeAr": "ضمان عدم إمكانية قراءة البيانات المخزنة دون المفتاح.",
        "checks": [
          "All data at rest in the cloud is encrypted.",
          "Platform managed keys are used at minimum.",
          "Use of customer managed encryption keys for Sensitive data is decided on a risk assessment.",
          "The approach aligns with Decision No. 1 of 2025."
        ],
        "checksAr": [
          "كل البيانات المحفوظة في السحابة مشفرة.",
          "المفاتيح المدارة من المنصة مستخدمة كحد أدنى.",
          "استخدام مفاتيح تشفير يديرها العميل للبيانات الحساسة يقرر بناء على تقييم للمخاطر.",
          "النهج متوائم مع القرار رقم 1 لسنة 2025."
        ],
        "evidence": [
          "Encryption status report across storage, database and backup services",
          "Key management approach note per environment",
          "Risk assessment supporting the CMEK decision for Sensitive data"
        ],
        "evidenceAr": [
          "تقرير حالة التشفير عبر خدمات التخزين وقواعد البيانات والنسخ الاحتياطي",
          "مذكرة نهج إدارة المفاتيح لكل بيئة",
          "تقييم المخاطر الداعم لقرار المفاتيح المدارة من العميل للبيانات الحساسة"
        ],
        "cadence": "continuous",
        "effort": "low",
        "phase": 1,
        "beyondAnnex": []
      },
      "appliesWhen": [
        "usesCloud"
      ],
      "crosswalk": {
        "csf": [
          "PR.DS-01",
          "PR.DS-02"
        ],
        "cis": [
          "3.11",
          "3.6"
        ],
        "iso": [
          "A.8.24"
        ]
      }
    },
    {
      "id": "CLD-12",
      "function": "CLD",
      "official": {
        "title": "Data Residency (Customer Content)",
        "titleAr": "توطين البيانات (محتوى العميل)",
        "requirement": "The Entity MUST configure cloud services and related contracts to store and process Customer Content (files, databases, application data) according to the National Data Classification Framework (Decision No. 1 of 2025).",
        "requirementAr": "يجب على الجهة تهيئة الخدمات السحابية والعقود المرتبطة بها لحفظ محتوى العميل، أي الملفات وقواعد البيانات وبيانات التطبيقات، ومعالجته وفقا للإطار الوطني لتصنيف البيانات الصادر بالقرار رقم 1 لسنة 2025.",
        "purpose": null,
        "purposeAr": null
      },
      "editorial": {
        "purpose": "Keep Customer Content where the national framework requires it.",
        "purposeAr": "إبقاء محتوى العميل داخل النطاق الجغرافي الذي يفرضه الإطار الوطني.",
        "checks": [
          "Cloud services are configured to store Customer Content in line with the National Data Classification Framework.",
          "Cloud services are configured to process Customer Content in line with that framework.",
          "Related contracts carry the same residency commitment.",
          "Customer Content is understood to mean files, databases and application data."
        ],
        "checksAr": [
          "الخدمات السحابية مهيأة لحفظ محتوى العميل بما يتفق مع الإطار الوطني لتصنيف البيانات.",
          "الخدمات السحابية مهيأة لمعالجة محتوى العميل بما يتفق مع ذلك الإطار.",
          "تحمل العقود ذات الصلة الالتزام نفسه بتوطين البيانات.",
          "محتوى العميل مفهوم بأنه الملفات وقواعد البيانات وبيانات التطبيقات."
        ],
        "evidence": [
          "Region configuration per service holding Customer Content",
          "Contract clause on data location",
          "Mapping of data sets to regions with their classification"
        ],
        "evidenceAr": [
          "إعداد المنطقة الجغرافية لكل خدمة تحتفظ بمحتوى العميل",
          "البند التعاقدي الخاص بموقع البيانات",
          "مواءمة بين مجموعات البيانات والمناطق مع تصنيف كل منها"
        ],
        "cadence": "annual",
        "effort": "medium",
        "phase": 1,
        "beyondAnnex": []
      },
      "appliesWhen": [
        "usesCloud"
      ],
      "crosswalk": {
        "csf": [
          "GV.OC-03",
          "PR.DS-01"
        ],
        "cis": [
          "3.1",
          "3.12"
        ],
        "iso": [
          "A.5.12",
          "A.5.34"
        ]
      }
    },
    {
      "id": "CLD-13",
      "function": "CLD",
      "official": {
        "title": "Operational Metadata Exemption",
        "titleAr": "استثناء البيانات الوصفية التشغيلية",
        "requirement": "Residency requirements apply to Customer Content. Operational Metadata (e.g., project IDs, billing logs, system status, and IP addresses) can be processed globally to ensure platform security, reliability, and accurate billing. Entities must ensure that metadata identifiers (such as Project IDs, folder names and labels) remain non-sensitive.",
        "requirementAr": "تسري متطلبات توطين البيانات على محتوى العميل، أما البيانات الوصفية التشغيلية مثل معرفات المشاريع وسجلات الفوترة وحالة الأنظمة وعناوين بروتوكول الإنترنت فيمكن معالجتها عالميا ضمانا لأمن المنصة وموثوقيتها ودقة الفوترة، وعلى الجهات التأكد من بقاء معرفات البيانات الوصفية مثل معرفات المشاريع وأسماء المجلدات والوسوم غير حساسة.",
        "purpose": null,
        "purposeAr": null
      },
      "editorial": {
        "purpose": "Keep the residency rule workable by keeping metadata non sensitive.",
        "purposeAr": "إبقاء قاعدة التوطين قابلة للتطبيق بجعل البيانات الوصفية غير حساسة.",
        "checks": [
          "The entity distinguishes Customer Content from Operational Metadata in its records.",
          "Project identifiers remain non sensitive.",
          "Folder names remain non sensitive.",
          "Labels remain non sensitive.",
          "Naming guidance is issued so metadata does not leak sensitive information."
        ],
        "checksAr": [
          "تميز الجهة محتوى العميل عن البيانات الوصفية التشغيلية في سجلاتها.",
          "معرفات المشاريع تبقى غير حساسة.",
          "أسماء المجلدات تبقى غير حساسة.",
          "تبقى الوسوم غير حساسة.",
          "تصدر إرشادات للتسمية حتى لا تسرب البيانات الوصفية معلومات حساسة."
        ],
        "evidence": [
          "Naming and tagging convention prohibiting sensitive strings",
          "Review of existing project names, folders and labels",
          "Remediation record for identifiers that had to be renamed"
        ],
        "evidenceAr": [
          "عرف التسمية والوسم الذي يحظر النصوص الحساسة",
          "مراجعة لأسماء المشاريع والمجلدات والوسوم القائمة",
          "محضر معالجة المعرفات التي لزم تغيير أسمائها"
        ],
        "cadence": "annual",
        "effort": "low",
        "phase": 2,
        "beyondAnnex": [
          4
        ]
      },
      "appliesWhen": [
        "usesCloud"
      ],
      "crosswalk": {
        "csf": [
          "PR.DS-01",
          "ID.AM-07"
        ],
        "cis": [
          "3.1"
        ],
        "iso": [
          "A.5.12"
        ]
      }
    },
    {
      "id": "CLD-14",
      "function": "CLD",
      "official": {
        "title": "Public Access Prevention",
        "titleAr": "منع الوصول العام",
        "requirement": "Cloud storage resources (e.g., object storage buckets) MUST be configured to block public access by default. Public exposure MUST be an explicit, documented exception approved by the data owner.",
        "requirementAr": "يجب تهيئة موارد التخزين السحابي مثل حاويات تخزين الكائنات لحجب الوصول العام افتراضيا، ويجب أن يكون أي كشف للعموم استثناء صريحا وموثقا ومعتمدا من مالك البيانات.",
        "purpose": null,
        "purposeAr": null
      },
      "editorial": {
        "purpose": "Close the single most common cause of cloud data exposure.",
        "purposeAr": "سد أكثر أسباب انكشاف البيانات السحابية شيوعا.",
        "checks": [
          "Cloud storage resources block public access by default.",
          "The default applies at the organization or account level, not only per resource.",
          "Any public exposure exists as an explicit documented exception.",
          "Each exception is approved by the data owner."
        ],
        "checksAr": [
          "تحجب موارد التخزين السحابي الوصول العام افتراضيا.",
          "الإعداد الافتراضي مطبق على مستوى المؤسسة أو الحساب لا على مستوى المورد وحده.",
          "أي كشف للعموم قائم بوصفه استثناء صريحا وموثقا.",
          "كل استثناء معتمد من مالك البيانات."
        ],
        "evidence": [
          "Organization policy or account setting enforcing public access block",
          "Scan report listing any publicly reachable storage",
          "Approved exception records naming the data owner"
        ],
        "evidenceAr": [
          "سياسة المؤسسة أو إعداد الحساب الذي يفرض حجب الوصول العام",
          "تقرير فحص يعدد أي تخزين يمكن بلوغه من العموم",
          "سجلات الاستثناءات المعتمدة مع تسمية مالك البيانات"
        ],
        "cadence": "continuous",
        "effort": "low",
        "phase": 1,
        "beyondAnnex": [
          1
        ]
      },
      "appliesWhen": [
        "usesCloud"
      ],
      "crosswalk": {
        "csf": [
          "PR.AA-05",
          "PR.DS-01"
        ],
        "cis": [
          "3.3",
          "4.1"
        ],
        "iso": [
          "A.5.15",
          "A.8.3"
        ]
      }
    },
    {
      "id": "CLD-15",
      "function": "CLD",
      "official": {
        "title": "Cloud Audit Logging",
        "titleAr": "تسجيل الأحداث السحابية",
        "requirement": "Enable audit logging for cloud projects. Logs MUST capture \"Admin Activity\" (configuration changes) and \"Data Access\" (who accessed data) for sensitive workloads. Retain logs for a minimum of 12 months.",
        "requirementAr": "تفعل الجهة تسجيل التدقيق لمشاريع السحابة، ويجب أن تلتقط السجلات النشاط الإداري أي تغييرات التهيئة والوصول إلى البيانات أي من اطلع عليها بالنسبة لأحمال العمل الحساسة، وتحفظ السجلات اثني عشر شهرا كحد أدنى.",
        "purpose": null,
        "purposeAr": null
      },
      "editorial": {
        "purpose": "Record who changed the environment and who reached the data.",
        "purposeAr": "تسجيل من أجرى تغييرا على البيئة ومن اطلع على البيانات.",
        "checks": [
          "Audit logging is enabled for cloud projects.",
          "Logs capture admin activity covering configuration changes.",
          "Logs capture data access for sensitive workloads.",
          "Cloud logs are retained for a minimum of 12 months."
        ],
        "checksAr": [
          "تسجيل التدقيق مفعل لمشاريع السحابة.",
          "تلتقط السجلات النشاط الإداري شاملا تغييرات التهيئة.",
          "تلتقط السجلات الوصول إلى البيانات في أحمال العمل الحساسة.",
          "تحفظ سجلات السحابة اثني عشر شهرا كحد أدنى."
        ],
        "evidence": [
          "Audit log configuration per project or subscription",
          "Retention setting proof showing at least 12 months",
          "Sample query demonstrating admin activity and data access capture"
        ],
        "evidenceAr": [
          "إعداد سجل التدقيق لكل مشروع أو اشتراك",
          "ما يثبت إعداد الحفظ لاثني عشر شهرا على الأقل",
          "استعلام نموذجي يبين التقاط النشاط الإداري والوصول إلى البيانات"
        ],
        "cadence": "continuous",
        "effort": "medium",
        "phase": 2,
        "beyondAnnex": []
      },
      "appliesWhen": [
        "usesCloud"
      ],
      "crosswalk": {
        "csf": [
          "DE.CM-01",
          "DE.CM-03"
        ],
        "cis": [
          "8.2",
          "8.5",
          "8.10"
        ],
        "iso": [
          "A.8.15"
        ]
      }
    },
    {
      "id": "CLD-16",
      "function": "CLD",
      "official": {
        "title": "Secure Connectivity",
        "titleAr": "الاتصال الآمن",
        "requirement": "All traffic between the entity and the cloud provider MUST be encrypted in transit using industry-standard protocols (e.g., TLS 1.2 or higher). Management interfaces MUST NOT be exposed directly to the public internet; use secure bastions, VPNs, or Identity-Aware Proxies.",
        "requirementAr": "يجب تشفير كل حركة البيانات بين الجهة ومزود الخدمة السحابية أثناء النقل باستخدام بروتوكولات قياسية في الصناعة مثل TLS 1.2 فأعلى، ولا يجوز كشف واجهات الإدارة مباشرة على الإنترنت العام، بل تستخدم مضيفات وسيطة آمنة أو شبكات خاصة افتراضية أو وكلاء واعين بالهوية.",
        "purpose": null,
        "purposeAr": null
      },
      "editorial": {
        "purpose": "Protect traffic in transit and keep management planes off the open internet.",
        "purposeAr": "حماية البيانات أثناء نقلها وإبعاد واجهات الإدارة عن الإنترنت المفتوح.",
        "checks": [
          "All traffic between the entity and the cloud provider is encrypted in transit.",
          "Encryption uses industry standard protocols such as TLS 1.2 or higher.",
          "Management interfaces are not exposed directly to the public internet.",
          "Access to management interfaces runs through a bastion, VPN or identity aware proxy."
        ],
        "checksAr": [
          "كل حركة البيانات بين الجهة ومزود السحابة مشفرة أثناء النقل.",
          "يستخدم التشفير بروتوكولات قياسية في الصناعة مثل TLS 1.2 فأعلى.",
          "واجهات الإدارة غير مكشوفة مباشرة على الإنترنت العام.",
          "يمر الوصول إلى واجهات الإدارة عبر مضيف وسيط أو شبكة خاصة افتراضية أو وكيل واع بالهوية."
        ],
        "evidence": [
          "TLS configuration and version report for entity to cloud paths",
          "Network policy showing management interfaces restricted",
          "Bastion, VPN or identity aware proxy configuration",
          "External scan confirming no exposed management endpoints"
        ],
        "evidenceAr": [
          "تقرير إعداد وإصدار TLS لمسارات الاتصال بين الجهة والسحابة",
          "سياسة الشبكة التي تبين تقييد واجهات الإدارة",
          "إعداد المضيف الوسيط أو الشبكة الخاصة الافتراضية أو الوكيل الواعي بالهوية",
          "فحص خارجي يؤكد عدم وجود نقاط إدارة مكشوفة"
        ],
        "cadence": "continuous",
        "effort": "medium",
        "phase": 1,
        "beyondAnnex": []
      },
      "appliesWhen": [
        "usesCloud"
      ],
      "crosswalk": {
        "csf": [
          "PR.DS-02",
          "PR.AA-05",
          "PR.IR-01"
        ],
        "cis": [
          "3.10",
          "12.6",
          "12.7"
        ],
        "iso": [
          "A.8.20",
          "A.8.21",
          "A.8.24"
        ]
      }
    }
  ]
}
