Chapter 1
Background and
Introduction
In 2021, the OSCE initiated an extra-budgetary project focused on CBM 3
and CBM 15, specifically on cyber/ICT crisis communication procedures,
crisis management and the classification of ICT incidents in terms of the
scale and seriousness of the incident. The project aims to raise the
implementation rate of the OSCE cyber/ICT CBMs, as well as enhance
capacities of OSCE participating States to deal with significant
cyber/ICT incidents in an effective way through providing support in
developing national cyber incident severity scales.
Recognizing the increasing complexity of cyber/ICT security incidents and
the need for advancing crisis management procedures and expanding
the classification of cyber/ICT incidents in terms of their scale and
seriousness, the OSCE Secretariat’s Transnational Threats Department
aims to promote, assist and foster the use of national cyber incident
severity scales in OSCE participating States through the aforementioned
extra-budgetary project. Rather than only focusing on severity scales
per se, the project is taking a broader approach to cover the processes,
capacities, resources and institutional arrangements required to design,
develop and implement such scales, hence the reference throughout the
document to national cyber incident classification systems.
Drawing from CBM 15 on critical infrastructure protection and CBM 3 on
consultation procedures in particular, the project acknowledges that
creating a cyber/ICT incident classification system can contribute
significantly to enabling the proper prioritization and management of