Cyber Incident Classification 31 Incident and be defined as a cyber attack which has a serious impact on a medium-sized organization, or which poses a considerable risk to a large organization or wider / local government. REVIEW PROCEDURES RECOMMENDATION 9 Once established, a cyber incident classification system should be regularly reviewed to assess its effectiveness and ensure it is appropriately informing a country’s incident response and its risk or emergency management posture. Any changes to the incident classification schema deriving from the review process should be introduced in a manner that allows for long-term comparative analysis. Ideally, once established, a cyber incident classification system should be regularly reviewed to assess its scope and effectiveness and ensure it is appropriately informing a country’s incident response and its risk or emergency management posture. To date, across the OSCE region only a few review their NCICS with some frequency. Approaches to the review process vary across countries. In some cases, legal or planning requirements stipulate fixed terms for reviewing the system (every semester, annually, bi-annually), while in others the review process is more organic, carried out whenever optimal or in accordance with the outcome of an assessment or validation of the system. A requirement to carry out a regular review of the process and system can be included in national legislation (e.g., national information security act), regulatory or guidance documents and may be tied to broader reviews of national cyber incident response or national emergency plans. Lessons from regular exercises to test the national cyber emergency plan could potentially form the basis of the review process.

Select target paragraph3