16
Cyber Incident Classification in the OSCE Region
providing greater legal certainty [or greater predictability] for
organizations and relevant stakeholders.
Internationally a classification system can also serve as a basis for or
contribute to:
facilitating exchanges of information between different states
or services across the region on their approaches to incident
classification (including on what a cyber incident can be and how
governments should deal with it), which in turn can strengthen
confidence and co-operation and reinforce mutual understandings.
assessing and comparing statistics with other countries.
RELATION WITH BROADER NATIONAL CYBER INCIDENT OR CRISIS
MANAGEMENT FRAMEWORK AND NATIONAL LEGISLATION
RECOMMENDATION 2
Cyber incident classification systems are generally anchored
in national policy and other relevant frameworks and often
flow from or are anchored in national legislation.
Cyber incident classification systems are generally anchored in national
policy or other relevant frameworks (e.g., national information security,
cyber security or cyber incident systems or frameworks; national cyber
emergency plans; cyber security event management plans).
However, the place of a cyber incident classification system in any given
country’s national incident or crisis management policy hierarchy may
depend on the level of a given incident (or set of incidents) or how high it
is scored in relation to its relevance to national security. In some cases,
only certain elements of a plan may be made public. For instance, a
government may have a public cyber/ICT security event management
plan, while the national centre for cyber/ICT security may have a
separate, non-public plan accessible only to the centre.