Chapter 3
Recommendations
Purpose and objectives
The purpose of a NCICS is to generate a clear picture of the cyber
threat landscape, ensure a prompt response to cyber/ICT incidents,
and minimise the damage they cause. A NCICS supports national
crisis management by providing a routine and consistent mechanism
to objectively assess the risk of a cyber incident in the national
context, in a timely manner and detect possible gaps in defences.
Policy and legal base
Cyber incident classification systems are generally anchored in national
policy and other relevant frameworks and often flow from national
legislation.
A sound policy and/or legal base for cyber incident classification is critical
to ensuring its effectiveness as well as its sustainability.
Establishing clear criteria to determine the stakeholders or
constituencies that a national cyber incident classification will serve,
including how critical they are to society and economy requires serious
consideration. The approach should be flexible enough to accommodate
new stakeholders and constituents as the threat landscape changes.
Uniform and consistent reporting on incidents is critical to the
effectiveness of cyber incident classification systems and helps
determine the nature of the response. In some jurisdictions and