20 Cyber Incident Classification in the OSCE Region continuity of their services; the number of people affected (e.g., if an incident (could) affect more than 500,000 people) etc. While mid- or lower-level incidents do not necessarily trigger reporting or notification requirements, in some instances reporting or notification may be accepted or recommended. For instance, a National Cyber Incident Response Plan may still recommend reporting minor incidents as a means to achieve wider situational awareness. For the EU, operators of essential services and digital service providers are required to notify the relevant competent body (e.g., national cyber or information security agency; CSIRT/CERT; security incident response institution) in the case of security incidents that have significantly impacted the continuity of the essential or digital services they provide. Detailed instructions in this regard outline the time frame; means of notification; and information that should be provided to the competent body upon notification of the incident. The competent body is in turn responsible for reporting the incident up the policy ladder to the political level where a decision is made on whether to activate crisis management mechanisms. How a cyber incident is classified will generally dictate factors such as who leads the response, and the support arrangements that will be mobilised accordingly. GUIDANCE TO SUPPORT IMPLEMENTATION OF INCIDENT CLASSIFICATION FRAMEWORKS Guidance development is a process that is critical to the implementation of policy. Engaging relevant stakeholders during the guidance development process can improve guideline recommendation uptake. Where cyber incident classification is concerned, in a national context, it is important to have in place clear guidance that specifies inter alia, the policy and legal base for what the cyber incident classification is setting out to achieve; who co-ordinates its development and implementation; who its key stakeholders/constituencies are; what the process of categorizing and prioritizing an incident entails; and how regularly the incident classification system is reviewed and what the review process entails.

Select target paragraph3