Cyber Incident Classification
21
Where OSCE practice is concerned, only a few participating States have
developed guidance to accompany implementation of their classification
system. For those that have, such guidance is embedded in, or draws
from, regional (e.g., EU) or national policy, legislation, standards,
or regulation relevant to cyber incident or broader emergency
planning and can also link to other types of incident responserelated
guidance
(e.g.,
guidance
on
observed
activity,
identified threats etc.) In some cases, guidance is broad enough to
be nation-wide and applicable to any sector and/or enterprise, while
in others it is sector (e.g., for the financial sector) or enterprise
specific.
RECOMMENDATION 6
Clearly articulated guidance contributes to the effective
implementation and socialization of a cyber incident
classification system. Such guidance can specify: the
purpose of the cyber incident classification system
and its policy and/or legal basis; who co-ordinates its development and
implementation; its scope/coverage in terms of its key stakeholders/
constituencies; definitions and explanations of categories and priorities;
the response mechanisms for incidents, including an explanation of
what would activate a specific classification, which organization
responds and what actions they would take; and how regularly the
incident classification system is reviewed and what the review process
entails.
Examples of existing guidance include:
•
US NCCIC Scoring System (nation-wide sector guidance on
implementation of the scoring system), which is based on the
NIST Special Publication 800-61 Rev. 2, Computer Security
Incident Handling Guide, and tailored to include entity-specific
potential impact categories that allow NCCIC personnel to evaluate
risk severity and incident priority from a nationwide perspective.