Cyber Incident Classification
9
The process of developing a cyber incident classification can be lengthy and resource intensive
as well as challenging, especially in its initial phases.
A standard approach to categorizing and prioritizing cyber incidents in accordance with their
severity and scale is important for diagnosing an incident and relating the importance of the
incident to its impact on a specific institution, entity or sector and its urgency, relative to the
timing of the incident.
Once established, a cyber incident classification system should be regularly reviewed
to assess its effectiveness and ensure it is
appropriately informing a country’s incident
response and its risk or emergency management posture.
The expertise/skills/capacity required
to design, manage and sustain a
cyber incident classification system is
multi-faceted and involves a range of
expertise and responsibilities.
Sharing national approaches to classifying
ICT incidents in terms of the scale and seriousness of the incident with other States can
contribute to building confidence between
States and help avoid potential misunderstandings that may emerge around cyber
incidents and related response measures,
thus contributing to regional and international security and stability.
These skills need to be appropriately budgeted for and core duties
adequately considered in the planning
processes.
P
P
PROCESS AND
INSTITUTIONAL
ARRANGEMENTS
PEOPLE
AND
RESOURCES