40 Cyber Incident Classification in the OSCE Region Exchanges could also take the form of workshops or meetings where lessons and good practices in cyber incident classification and on the different taxonomies are shared. This could help expand existing taxonomies to cover those used by other countries as well as those developed by private actors or research institutes. There are, however, challenges to participating in dedicated exchanges and exercises. These include capacity constraints and staffing requirements, especially those experienced by smaller countries or those with limited resources. Nonetheless, most States agree that a possible starting point could be information exchanges on national approaches to incident classification. A range of formats can be used to share national approaches to cyber incident classification. These include making relevant information (policies, regulation, etc.) publicly available on government websites; using existing multilateral platforms or processes, bi-lateral or multistakeholder dialogues; or in-person or online workshops. CAPACITY BUILDING AND OTHER INITIATIVES RELEVANT TO NATIONAL CYBER INCIDENT CLASSIFICATION Cyber-security-related capacity building needs remain poorly addressed across the globe, including where cyber incident classification is concerned. In the OSCE region many States view this as a gap that needs to be filled. Crisis management scenarios and table top exercises can play an important role in this regard, and could potentially be tied to a Points of Contact Network, where appropriate.

Select target paragraph3