Cyber Incident Classification
15
RECOMMENDATION 1
The purpose of a NCICS is to generate a clear picture of the
cyber threat landscape and ensure a prompt response to
cyber/ICT incidents and minimize the damage they cause.
A NCICS supports national crisis management by providing a routine and
consistent mechanism to objectively assess the risk of a cyber incident
in the national context, in a timely manner, and detect possible gaps in
existing defences.
Nationally a cyber incident classification system can contribute to:
reaching common understanding of what is (and what is not) a
cyber incident.
ensuring more consistency in cyber incident terminology or lexicon
(taxonomy) across organizations and constituents nationally, and
in information exchanges with other countries.
determining retroactively if the assessment was correct, and track
changes over time.
ensuring greater alignment and consistency between different
national-level crisis management tools or plans (e.g., between
national cyber emergency plans and national emergency
management plans).
identifying the needs of different stakeholders and constituencies
and how the classification system can be adapted to those needs.
developing regular metrics, statistics and comparative analysis to
inform more consistent threat landscaping or projections and to
inform forward planning.
preventing future incidents from occurring.
informing policy and regulatory development, especially regarding
monitoring and reporting requirements relevant to high-risk
incidents.