32 Cyber Incident Classification in the OSCE Region In instances where there is no obligation or requirement to periodically review the cyber incident classification system, reviews can take place organically when necessary. Regardless of the approach, it is important that any changes to the incident classification system deriving from a review process should be introduced in a manner that allows for long-term comparative analysis. CAPACITY AND RESOURCE REQUIREMENTS Continuous political commitment, skilled personnel, adequate and stable budgets, and review procedures are required to develop, manage and sustain a NCICS. RECOMMENDATION 10 Continuous political commitment, skilled personnel, including a dedicated incident response entity or team with sound expertise in both general and cyber crisis management, and adequate and stable budgets are critical to the development and management of cyber incident classification systems. The prior existence of the relevant policy base, legal authorities and requirements and a dedicated incident response entity or team with sound expertise in both general and cyber crisis management are perceived as important pre-conditions to ensuring the effective management of the system and for securing adequate human capital and resources. Developing, managing and sustaining a classification system also requires inter-personal skills since agreeing on a classification system that serves the purpose of a broad range of organizations and constituents involves a significant amount of engagement (via meetings, workshops, exercises etc.) of public and private actors across a range of sectors and services both during the development and implementation of the system. This can serve an important trust-building function.

Select target paragraph3