18 Cyber Incident Classification in the OSCE Region process leading to the system or approach currently in place. In other cases, classification systems emerged organically early on, in response to the growing severity of cyber incidents. In the case of the EU, these existing systems or approaches have continued to mature, gradually aligning with or integrating elements of the NIS Directive’s cyber incident taxonomy, which, in many cases, was or is being developed by national CERTs or CSIRTs. These, in turn, often use playbooks for incident classification, which tend to be very detailed, specific to the organization and very dynamic. SCOPE OF NATIONAL CYBER INCIDENT CLASSIFICATION SYSTEMS A key step in the process of developing a national cyber incident classification system is clearly identifying its scope, i.e., its main stakeholders or constituencies. This entails establishing criteria for assessing the risk profiles of different stakeholders and constituents in terms of how critical they are to the functioning of society and the economy, which, in turn, requires accommodating very diverse public and private interests, ranging from government bodies to critical infrastructure assets or services, to businesses (small, medium and large), communities and individuals. It is equally important that the system be flexible enough to accommodate additional stakeholders/ constituents as the threat landscape changes in tandem with our dependency on ICTs. RECOMMENDATION 4 Establishing clear criteria to determine the stakeholders or constituencies that a national cyber incident classification will serve, including how critical they are to society and economy requires serious consideration. The approach should be flexible enough to accommodate new stakeholders and constituents as the threat landscape changes. In the OSCE region, to date, the main stakeholders/constituencies of national incident classification systems include a range of government

Select target paragraph3