36 Cyber Incident Classification in the OSCE Region Another identified challenge relates to the categorization and prioritization of incidents. Even the best classification system cannot include all the different possible incident categories. Sometimes, however, an incident does not fit into a certain category or can fit into multiple categories, creating obstacles for triaging an incident. Protocols for determining how to proceed in such situations may therefore be required. RECOMMENDATION 12 It is important to establish protocols that determine how to proceed when challenges relevant to categorization of incidents are encountered. The challenge of setting meaningful thresholds for classifying incidents in a manner that can then be interpreted by relevant stakeholders requires specific attention. Since there are many ways of looking at an incident and different actors generally have different information at their disposal, it is often challenging to achieve a common picture of the incident. A lack of specific information provided by target organizations relevant to an incident often requires further interaction to fully leverage the classification scheme. Furthermore, the dynamic, non-static aspect of cyber incidents is not necessarily catered for in current approaches. In this regard, decisions regarding the category and priority assignation of a given incident is generally based on the information that the incident handler has at a given moment. However, said information can change as time passes, which may in turn change the priority level of the incident. Terminology continues to pose challenges, since many terms in and of themselves do not have a delimited meaning. An example of how to overcome this challenge includes developing a list of definitions and concepts that is then included in the relevant legal instrument or guidance document, although this might become a challenge too, if too narrow in scope.

Select target paragraph3