16 Cyber Incident Classification in the OSCE Region providing greater legal certainty [or greater predictability] for organizations and relevant stakeholders. Internationally a classification system can also serve as a basis for or contribute to: facilitating exchanges of information between different states or services across the region on their approaches to incident classification (including on what a cyber incident can be and how governments should deal with it), which in turn can strengthen confidence and co-operation and reinforce mutual understandings. assessing and comparing statistics with other countries. RELATION WITH BROADER NATIONAL CYBER INCIDENT OR CRISIS MANAGEMENT FRAMEWORK AND NATIONAL LEGISLATION RECOMMENDATION 2 Cyber incident classification systems are generally anchored in national policy and other relevant frameworks and often flow from or are anchored in national legislation. Cyber incident classification systems are generally anchored in national policy or other relevant frameworks (e.g., national information security, cyber security or cyber incident systems or frameworks; national cyber emergency plans; cyber security event management plans). However, the place of a cyber incident classification system in any given country’s national incident or crisis management policy hierarchy may depend on the level of a given incident (or set of incidents) or how high it is scored in relation to its relevance to national security. In some cases, only certain elements of a plan may be made public. For instance, a government may have a public cyber/ICT security event management plan, while the national centre for cyber/ICT security may have a separate, non-public plan accessible only to the centre.

Select target paragraph3