30 Cyber Incident Classification in the OSCE Region What key criteria are considered when an incident (or series of incidents) is being classified in terms of severity and seriousness? TARGETED INSTITUTION/ SECTOR 23 8 CAPABILITIES USED SCOPE 16 20 DURATION 7 FREQUENCY SCALE (MAGNITUDE/PRIMARY AND SECONDARY EFFECTS/IMPACT/ CONSEQUENCES OF THE INCIDENT) 27 OTHER 6 0 5 10 15 20 25 30 Once an incident is scored or assessed, the next step is to assign it priority. Priority assignments contribute to ensuring common lexicon when an incident is being discussed. They help determine urgency, incident response, reporting requirements, as well as recommendations for leadership engagement. Options for priority level designation include: 1. Low-critical 2. Levels 1-5 3. Colour schema Ideally, the priority assignation would include an explanation or definition of each level. For instance, the colour black may represent the level of National Emergency, whereby the incident poses an imminent threat to the provision of wide-scale critical infrastructure services, national government stability, or the lives of (…) persons. In numerical categorizations, category 4 on a scale of 1-6 may represent a Substantial

Select target paragraph3