Cyber Incident Classification 21 Where OSCE practice is concerned, only a few participating States have developed guidance to accompany implementation of their classification system. For those that have, such guidance is embedded in, or draws from, regional (e.g., EU) or national policy, legislation, standards, or regulation relevant to cyber incident or broader emergency planning and can also link to other types of incident responserelated guidance (e.g., guidance on observed activity, identified threats etc.) In some cases, guidance is broad enough to be nation-wide and applicable to any sector and/or enterprise, while in others it is sector (e.g., for the financial sector) or enterprise specific. RECOMMENDATION 6 Clearly articulated guidance contributes to the effective implementation and socialization of a cyber incident classification system. Such guidance can specify: the purpose of the cyber incident classification system and its policy and/or legal basis; who co-ordinates its development and implementation; its scope/coverage in terms of its key stakeholders/ constituencies; definitions and explanations of categories and priorities; the response mechanisms for incidents, including an explanation of what would activate a specific classification, which organization responds and what actions they would take; and how regularly the incident classification system is reviewed and what the review process entails. Examples of existing guidance include: • US NCCIC Scoring System (nation-wide sector guidance on implementation of the scoring system), which is based on the NIST Special Publication 800-61 Rev. 2, Computer Security Incident Handling Guide, and tailored to include entity-specific potential impact categories that allow NCCIC personnel to evaluate risk severity and incident priority from a nationwide perspective.

Select target paragraph3