Cyber Incident Classification 9 The process of developing a cyber incident classification can be lengthy and resource intensive as well as challenging, especially in its initial phases. A standard approach to categorizing and prioritizing cyber incidents in accordance with their severity and scale is important for diagnosing an incident and relating the importance of the incident to its impact on a specific institution, entity or sector and its urgency, relative to the timing of the incident. Once established, a cyber incident classification system should be regularly reviewed to assess its effectiveness and ensure it is appropriately informing a country’s incident response and its risk or emergency management posture. The expertise/skills/capacity required to design, manage and sustain a cyber incident classification system is multi-faceted and involves a range of expertise and responsibilities. Sharing national approaches to classifying ICT incidents in terms of the scale and seriousness of the incident with other States can contribute to building confidence between States and help avoid potential misunderstandings that may emerge around cyber incidents and related response measures, thus contributing to regional and international security and stability. These skills need to be appropriately budgeted for and core duties adequately considered in the planning processes. P P PROCESS AND INSTITUTIONAL ARRANGEMENTS PEOPLE AND RESOURCES

Select target paragraph3