24
Cyber Incident Classification in the OSCE Region
information security agency; national cyber security directorate;
information systems security bureau; government information security
office; national authority for electronic certification and cyber security;
e-government state agency).
In some cases, a specific ministry plays this role, while in others, it is
the role of a national CERT or CSIRT, sometimes with specific reporting
requirements in the case of serious incidents (e.g., to a national police
commission). Engaging of relevant stakeholders and constituencies in
the design and development of the classification system can contribute
to building trust between public and private actors and within and across
sectors and services from the outset.
NATIONAL APPROACHES TO CYBER INCIDENT CATEGORIZATION AND
PRIORITIZATION
A standard approach to categorizing and prioritizing cyber incidents in
accordance with their severity and scale is important for diagnosing an
incident and relating the importance of the incident to its impact on a
specific institution, entity or sector and its urgency, relative to the timing
of the incident.
Categorization speeds up the process of incident classification and creates
greater efficiency within the process flow while priority assignment can
help ensure a common lexicon when an incident is being discussed, help
determine urgency, incident response and reporting requirements, as
well as recommendations for leadership engagement.
Incident priority designation can help ensure a common lexicon when
an incident is being discussed. It also helps determine urgency, incident
response and reporting requirements, as well as recommendations for
leadership engagement.
Using a standard methodology to categorizing and prioritizing
cyber incidents seems to be the common approach, in some cases
anchored in national legislation (e.g., in a cyber or information security
act, a royal decree), with more detail provided in national plans (e.g., a
national cyber incident response plan, a cyber defense review) which
define unified processes for categorizing and reporting different types
of incidents.