it is a means to support national crisis management and incident
response processes by providing a routine and consistent mechanism
that can be used to objectively assess and prioritize cyber incidents in
the national context, in a timely manner, and to identify gaps in existing
defences. Such a mechanism in turn informs decision-making - including
at strategic and political levels - relevant to the nature and timeliness
of the response and the procedures for moving from identification of
an incident to its treatment and eventual resolution, while minimising
disruption to network operations. It is important that the purpose of a
cyber incident classification and its core stakeholders and constituents
is clearly articulated from the outset.
Importantly, a cyber incident classification system also informs
decision-making relevant to who leads or co-ordinates each step of the
response, as well as to effort and resource allocation or requirements.
In some instances, it may be accompanied by an entity responsible for
managing incidents.
In addition, a NCICS can help develop shared situational awareness of
cyber incidents and make comparisons with peers, including through
more routine exchanges of information across organizations. It can
also help ensure consistency and clarity in the way an incident is
communicated within and across organizations, or to the broader public.