34
Cyber Incident Classification in the OSCE Region
RECOMMENDATION 11
Engagement of relevant stakeholders and constituencies in
the development of the classification system can contribute
to building trust between public and private actors and within
and across sectors and services.
The development of a classification system can be time and resource
intensive in its initial phases and rollout, requiring significant technical
expertise for the development of the classification system (e.g.,
defining the qualitative categories for the incident assessment, priority
assignment etc.), as well as significant engagement of other entities and
stakeholders in the process. Different tools, procedures, documents
will then need to be put in place and information about the new (or
reviewed) classification system communicated to its constituents and
the broader public. Once agreed and these steps become embedded
in national emergency or incident management frameworks or plans,
the resources required to sustain it are minimal.
Importantly, the capacities and resources required to sustain a cyber
incident classification system are also influenced by its design, including
whether its technical component is developed in-house or is out-sourced
(e.g., if it is a subscription-based model) and whether it needs to be
regularly upgraded in line with changes in cyber incident types. In this
regard, cost and efficiency will be a constant factor.
The types of expertise required to develop, manage and sustain the
system can include: political, technical, subject-matter, countryspecific, legal and communications expertise.
Core duties that are required to manage and sustain the system once
developed and that would need to be budgeted for can include:
•
Communication and promotion of the system across organizations
and constituencies.
•
Periodic review of the classification system (categories, scoring etc.)
and its effectiveness.