Cyber Incident Classification
19
agencies (e.g., offices of the head of government, ministries of the interior/
homeland security, justice, defence, foreign affairs, economic affairs
and digital transformation; national intelligence agencies, departments
or bureaux; and national cyber or information security agencies or
entities), ‘essential’ or ‘important’ sectors or services deemed critical to
the functioning of society or the economy, critical infrastructure asset
owners, businesses, and individuals.
REQUIREMENTS (E.G., GOVERNMENT-MANDATED REPORTING OR
NOTIFICATION REQUIREMENTS) STEMMING FROM NATIONAL CYBER
INCIDENT CLASSIFICATION SYSTEMS
Uniform and consistent reporting on incidents is critical to the effectiveness
of cyber incident classification systems.
Often, reporting and/or notification requirements stem from the NCICS.
The requirements vary, with some stemming from national cyber/ICT
security- or incident-related legislation or policy frameworks that provide
for a variety of government actions.
RECOMMENDATION 5
Uniform and consistent reporting on incidents is critical to
the effectiveness of cyber incident classification systems and
helps determine the nature of the response.
In some jurisdictions and depending on the severity of an incident and the
entity affected, incident reporting is legally required.
Reporting or notification requirements tend to be linked to incidents
that are categorized higher up in the severity scale in accordance with
a given country’s scoring system, which as discussed earlier, can be
presented in a variety of ways (colour scheme, numerical ratings, range
of severity etc.) and depends on the entities affected (e.g., operators of
essential services; digital service providers; government entities; critical
infrastructure sectors; information infrastructure operators) and the