18
Cyber Incident Classification in the OSCE Region
process leading to the system or approach currently in place. In other
cases, classification systems emerged organically early on, in response to
the growing severity of cyber incidents. In the case of the EU, these
existing systems or approaches have continued to mature, gradually
aligning with or integrating elements of the NIS Directive’s cyber incident
taxonomy, which, in many cases, was or is being developed by national
CERTs or CSIRTs. These, in turn, often use playbooks for incident
classification, which tend to be very detailed, specific to the organization
and very dynamic.
SCOPE OF NATIONAL CYBER INCIDENT CLASSIFICATION SYSTEMS
A key step in the process of developing a national cyber incident
classification system is clearly identifying its scope, i.e., its main
stakeholders or constituencies. This entails establishing criteria for
assessing the risk profiles of different stakeholders and constituents
in terms of how critical they are to the functioning of society and the
economy, which, in turn, requires accommodating very diverse public
and private interests, ranging from government bodies to critical
infrastructure assets or services, to businesses (small, medium and
large), communities and individuals. It is equally important that the
system be flexible enough to accommodate additional stakeholders/
constituents as the threat landscape changes in tandem with our
dependency on ICTs.
RECOMMENDATION 4
Establishing clear criteria to determine the stakeholders or
constituencies that a national cyber incident classification
will serve, including how critical they are to society and
economy requires serious consideration. The approach should be flexible
enough to accommodate new stakeholders and constituents as the threat
landscape changes.
In the OSCE region, to date, the main stakeholders/constituencies of
national incident classification systems include a range of government