20
Cyber Incident Classification in the OSCE Region
continuity of their services; the number of people affected (e.g., if an
incident (could) affect more than 500,000 people) etc.
While mid- or lower-level incidents do not necessarily trigger reporting
or notification requirements, in some instances reporting or notification
may be accepted or recommended. For instance, a National Cyber
Incident Response Plan may still recommend reporting minor incidents
as a means to achieve wider situational awareness.
For the EU, operators of essential services and digital service
providers are required to notify the relevant competent body (e.g.,
national cyber or information security agency; CSIRT/CERT;
security incident response institution) in the case of security incidents
that have significantly impacted the continuity of the essential or digital
services they provide. Detailed instructions in this regard outline the
time frame; means of notification; and information that should be
provided to the competent body upon notification of the incident. The
competent body is in turn responsible for reporting the incident up the
policy ladder to the political level where a decision is made on whether
to activate crisis management mechanisms. How a cyber incident is
classified will generally dictate factors such as who leads the response,
and the support arrangements that will be mobilised accordingly.
GUIDANCE TO SUPPORT IMPLEMENTATION OF INCIDENT CLASSIFICATION
FRAMEWORKS
Guidance development is a process that is critical to the implementation
of policy. Engaging relevant stakeholders during the guidance
development process can improve guideline recommendation uptake.
Where cyber incident classification is concerned, in a national context,
it is important to have in place clear guidance that specifies inter alia,
the policy and legal base for what the cyber incident classification
is setting out to achieve; who co-ordinates its development and
implementation; who its key stakeholders/constituencies are; what the
process of categorizing and prioritizing an incident entails; and how
regularly the incident classification system is reviewed and what the
review process entails.