Cyber Incident Classification 23 2.2 Process and Institutional Arrangements This section of the report highlights the capacities and resources that might be required to develop, manage and sustain a national cyber incident classification system, as well as related processes and arrangements. It explores approaches to classifying cyber incidents, what existing systems set out to measure, whether specific schemas are used, how they are presented and defined/explained, and the criteria that are considered when an incident is being classified in terms of severity/ seriousness. It also discusses review procedures, and explores whether specific requirements stem from the system. It concludes with an essential discussion on some of the core challenges States have encountered when developing and implementing national cyber incident classification systems. INSTITUTIONAL RESPONSIBILITIES: THE NATIONAL ENTITIES RESPONSIBLE FOR DESIGNING AND CO-ORDINATING DECISIONS ON CYBER INCIDENT CLASSIFICATION RECOMMENDATION 7 Cyber incident classification is generally a centralized process co-ordinated by a central entity or authority and involving a range of government bodies. Depending on the context, it may also include essential or important services/critical infrastructure asset owners or operators, service providers and other private sector entities. digital Responsibility for the development and co-ordination of national cyber incident classification systems varies significantly. In some cases, this role is held by a central co-ordinating entity (e.g., a national security council under which a national cyber security council is; an interagency co-ordination body; a national computer incident response and co-ordination centre). In other instances, the responsibility is held by a dedicated cyber or information security entity or authority (e.g., national cyber or

Select target paragraph3