34 Cyber Incident Classification in the OSCE Region RECOMMENDATION 11 Engagement of relevant stakeholders and constituencies in the development of the classification system can contribute to building trust between public and private actors and within and across sectors and services. The development of a classification system can be time and resource intensive in its initial phases and rollout, requiring significant technical expertise for the development of the classification system (e.g., defining the qualitative categories for the incident assessment, priority assignment etc.), as well as significant engagement of other entities and stakeholders in the process. Different tools, procedures, documents will then need to be put in place and information about the new (or reviewed) classification system communicated to its constituents and the broader public. Once agreed and these steps become embedded in national emergency or incident management frameworks or plans, the resources required to sustain it are minimal. Importantly, the capacities and resources required to sustain a cyber incident classification system are also influenced by its design, including whether its technical component is developed in-house or is out-sourced (e.g., if it is a subscription-based model) and whether it needs to be regularly upgraded in line with changes in cyber incident types. In this regard, cost and efficiency will be a constant factor. The types of expertise required to develop, manage and sustain the system can include: political, technical, subject-matter, countryspecific, legal and communications expertise. Core duties that are required to manage and sustain the system once developed and that would need to be budgeted for can include: • Communication and promotion of the system across organizations and constituencies. • Periodic review of the classification system (categories, scoring etc.) and its effectiveness.

Select target paragraph3