Cyber Incident Classification
31
Incident and be defined as a cyber attack which has a serious impact on
a medium-sized organization, or which poses a considerable risk to a
large organization or wider / local government.
REVIEW PROCEDURES
RECOMMENDATION 9
Once established, a cyber incident classification system should
be regularly reviewed to assess its effectiveness and ensure it is
appropriately informing a country’s incident response and its
risk or emergency management posture.
Any changes to the incident classification schema deriving from the review
process should be introduced in a manner that allows for long-term
comparative analysis.
Ideally, once established, a cyber incident classification system should
be regularly reviewed to assess its scope and effectiveness and ensure
it is appropriately informing a country’s incident response and its risk
or emergency management posture. To date, across the OSCE
region only a few review their NCICS with some frequency.
Approaches to the review process vary across countries. In some cases,
legal or planning requirements stipulate fixed terms for reviewing the
system (every semester, annually, bi-annually), while in others the
review process is more organic, carried out whenever optimal or
in accordance with the outcome of an assessment or validation of the
system.
A requirement to carry out a regular review of the process and system
can be included in national legislation (e.g., national information
security act), regulatory or guidance documents and may be tied to
broader reviews of national cyber incident response or national
emergency plans. Lessons from regular exercises to test the national
cyber emergency plan could potentially form the basis of the review
process.