32
Cyber Incident Classification in the OSCE Region
In instances where there is no obligation or requirement to periodically
review the cyber incident classification system, reviews can take place
organically when necessary.
Regardless of the approach, it is important that any changes to the
incident classification system deriving from a review process should be
introduced in a manner that allows for long-term comparative analysis.
CAPACITY AND RESOURCE REQUIREMENTS
Continuous political commitment, skilled personnel, adequate and
stable budgets, and review procedures are required to develop, manage
and sustain a NCICS.
RECOMMENDATION 10
Continuous political commitment, skilled personnel, including
a dedicated incident response entity or team with sound
expertise in both general and cyber crisis management, and
adequate and stable budgets are critical to the development and
management of cyber incident classification systems.
The prior existence of the relevant policy base, legal authorities and
requirements and a dedicated incident response entity or team
with sound expertise in both general and cyber crisis management
are perceived as important pre-conditions to ensuring the effective
management of the system and for securing adequate human capital
and resources.
Developing, managing and sustaining a classification system also requires
inter-personal skills since agreeing on a classification system that serves
the purpose of a broad range of organizations and constituents involves
a significant amount of engagement (via meetings, workshops, exercises
etc.) of public and private actors across a range of sectors and services
both during the development and implementation of the system. This
can serve an important trust-building function.