Cyber Incident Classification 17 Often, the cyber incident classification system flows from or is anchored in national legislation (e.g., in an information or cyber security act; a law on cyber or information security; a federal law on the safety of critical information infrastructure). It may also be included in legislation outlining the functions of incident or emergency response teams (CERTS or CSIRTs), in regulatory instruments (e.g., on the cybersecurity of operators of essential services and digital service providers) or incidentspecific regulation (e.g., on incident notification); or in decrees, orders or presidential authorities. In the case of members of the EU, their classification systems draw directly from the Network and Information Systems (NIS) Directive4 and in future will likely be more closely integrated into general national crisis management frameworks.5 Cyber incident classification may also be relevant to or included in other pieces of crisis management legislation or policy (e.g., a civil protection act) as a means to support a wider diffusion and use of the tool. RECOMMENDATION 3 A sound policy and/or legal base for cyber incident classification is critical to ensuring its effectiveness as well as its sustainability. Introducing clear provisions on overall responsibility for the system, interagency co-operation, reporting and notification requirements and procedures, data-handling procedures, resource allocation and review procedures are equally important. In some cases, the cyber incident classification system was preceded by other legislation, policies, strategies or plans relevant to cyber or information security, cyber defence, the security of information technologies or incident management, reflecting an incremental 4 Directive (EU) 2016/1148 of the European Parliament and of the Council of 6 July 2016 concerning measures for a high common level of security of network and information systems across the Union. 5 Proposal for a Directive of the European Parliament and of the Council on measures for a high common level of cybersecurity across the Union, repealing Directive 2016/1148, Doc. No. 14337/21, 26 November 2021, Art. 7, para. 3 (b) on cybersecurity crisis management procedures.

Select target paragraph3