depending on the severity of an incident and the entity affected, incident reporting is legally required. Clearly articulated guidance contributes to the effective implementation and socialization of a cyber incident classification system. Such guidance can specify: • The purpose of the cyber incident classification system and its policy and/or legal basis; • Who co-ordinates its development and implementation; • Its scope/coverage in terms of its key stakeholders/constituencies; • Definitions and explanations of categories and priorities; • The response mechanisms for incidents, including an explanation of what would activate a specific classification, which organization responds and what actions they would take; and • How regularly the incident classification system is reviewed and what the review process entails. Process and institutional arrangements Cyber incident classification is generally a centralised process co-ordinated by a central entity or authority and can involve a range of government bodies. Depending on the context, it may also include essential services/ critical infrastructure asset owners or operators, digital service providers and other relevant private sector entities.

Select target paragraph3