46
Concluding Remarks
Chapter 4
Concluding Remarks
Experiences in designing these systems vary significantly across OSCE
participating States, yet the study clearly demonstrates that common
baselines are critical to effective cyber incident management at the national
level, and for engaging on cyber incidents regionally and internationally.
Some participating States have had incident classification systems in
place for quite some time and have developed sound legal and/or policy
bases to ensure their effective co-ordination and management as well as
adequate resource allocation. For some participating States also
members of other organizations such as the EU, existing regulation
(e.g., the NIS Directive) has accelerated the establishment of incident
classification systems, many of which are now coming into their own. Other
participating States are undertaking the
first
steps
toward
establishing an incident classification system, while yet others are
planning to establish one within the next two years.
It is clear from the experiences discussed that a common classification
taxonomy is key to ensuring the effectiveness of any cyber incident
classification system. It needs to be clearly communicated to all intended
constituencies on a regular and timely basis. Furthermore, establishing and
nurturing interagency co-operation and information sharing adds to the
effectiveness. Equally important is ensuring regular reviews of the system
and allowing enough flexibility to adapt it to shifting circumstances.
Regardless of the stage of development and implementation of
their NCICS, the study presents some important emerging practices
and lessons across the four categories of purpose, policy, processes and
people.