Cyber Incident Classification
7
Executive Summary
In January 2022, the Secretariat of the Organization for Security and Co-operation
in Europe (OSCE), in the framework of an extra-budgetary project, embarked on a study
of emerging practices in cyber/ICT incident classification in the OSCE region. To inform this
study, it disseminated a questionnaire to OSCE participating States. An analysis of the
survey results along with a review of publicly available documents referenced in
participating States’ responses suggest that greater attention is being paid to cyber
incident classification across the region and that these systems are viewed as critical
to managing cyber incidents at the national level and for engaging with other States on
cyber incidents at the regional and international levels.
A growing number of OSCE participating States already have, or are in the process
of establishing a national cyber/ICT incident classification system. Many have also
established or are reviewing the policy and legal basis for cyber incident classification
or are moving in that direction. In several States, their system is closely tied to
national plans for crisis management or emergency planning. Responsibility for the
development and co-ordination of NCICS varies across the region. Existing
practices conf i rm that, for incident classif i cation to be effective, co-operation
between a broad range of public and private actors and sectors, including, for
instance, government agencies, CERTs1/CSIRTs2 or similar, operators of essential
services and digital service providers, is necessary. The importance of engaging
relevant non-State actors such as cyber security researchers is increasingly
acknowledged by some participating States.
The study also provides insights into some of the challenges OSCE participating States
are facing in developing and implementing their cyber incident classification systems.
These challenges range from personnel and resource constraints, to agreeing on
a common classification taxonomy that is clearly communicated to and used by all
intended constituencies, but also interagency co-operation and information sharing
as well as reviewing and adapting the system once in place. The study suggests that
efforts are underway to overcome many of these challenges and that capacity building
and other forms of co-operation will play an important role to that end. Several
participating States have voiced an interest in availing of the OSCE to exchange national
experiences on incident classification and to potentially engage in more dedicated
exchanges on the topic, including crisis management exercises.
The study also suggests that these emerging practices and related challenges, which
are presented below under the rubrics purpose, policy, process and people, be taken
up within further exchanges among OSCE participating States and between the OSCE
and other regions. These discussions would ensure further advancements in the spirit
and intent of the OSCE cyber/ICT CBMs, particularly CBMs 15 and 33, as well as those
agreed at the UN.
1 CERTs—Computer Emergency Response Teams
2 CSIRTs—Computer Security Incident Response Teams
3 Permanent Council Decision No. 1202 | OSCE