Cyber Incident Classification
17
Often, the cyber incident classification system flows from or is anchored
in national legislation (e.g., in an information or cyber security act;
a law on cyber or information security; a federal law on the safety of
critical information infrastructure). It may also be included in legislation
outlining the functions of incident or emergency response teams (CERTS
or CSIRTs), in regulatory instruments (e.g., on the cybersecurity of
operators of essential services and digital service providers) or incidentspecific regulation (e.g., on incident notification); or in decrees, orders
or presidential authorities. In the case of members of the EU, their
classification systems draw directly from the Network and Information
Systems (NIS) Directive4 and in future will likely be more closely
integrated into general national crisis management frameworks.5 Cyber
incident classification may also be relevant to or included in other pieces
of crisis management legislation or policy (e.g., a civil protection act) as
a means to support a wider diffusion and use of the tool.
RECOMMENDATION 3
A sound policy and/or legal base for cyber incident
classification is critical to ensuring its effectiveness as well as
its sustainability.
Introducing clear provisions on overall responsibility for the system,
interagency co-operation, reporting and notification requirements and
procedures, data-handling procedures, resource allocation and review
procedures are equally important.
In some cases, the cyber incident classification system was preceded
by other legislation, policies, strategies or plans relevant to cyber
or information security, cyber defence, the security of information
technologies or incident management, reflecting an incremental
4 Directive (EU) 2016/1148 of the European Parliament and of the Council of 6 July 2016
concerning measures for a high common level of security of network and information
systems across the Union.
5 Proposal for a Directive of the European Parliament and of the Council on measures for a
high common level of cybersecurity across the Union, repealing Directive 2016/1148, Doc.
No. 14337/21, 26 November 2021, Art. 7, para. 3 (b) on cybersecurity crisis management
procedures.