APPENDIX C (NORMATIVE)
INCIDENT MANAGEMENT
CRITICALITY CLASSIFICATION
Category
C1
Typical Incident Categories
• Denial of service
• Compromised Asset (critical)
• Internal Hacking (active)
• External Hacking (active)
• Virus / Worm (outbreak)
• Destruction of property (critical)
C2
• Internal Hacking (not active)
• External Hacking (not active)
• Unauthorized access.
• Policy violations
• Unlawful activity.
• Compromised information.
• Compromised asset. (non-critical)
• Destruction of property (non-critical)
C3
• Email
• Forensics Request
• Inappropriate use of property.
• Policy violations.
CSO
Critical Sector Organization as defined in CIIP Law
CII
Critical Information Infrastructure as defined in CIIP Law
Incident Matrix
C1
C2
C3
CSO+CII
CL1
CL1
CL3
CSO+ Non CII
CL1
CL2
CL3
Non CSO + CII
CL1
CL2
CL3
Non CSO + Non CII
CL3
CL3
CL3
NATIONAL INFORMATION ASSURANCE MANUAL
56