Cyber Incident Classification
25
Statutory notification requirements can also provide more detail, with
each requirement including a defined set of incident categories.
RECOMMENDATION 8
A standard approach to categorizing and prioritizing
cyber incidents in accordance with their severity and
scale is important for diagnosing an incident and relating
the importance of the incident to its impact on a specific institution, entity
or sector and its urgency, relative to the timing of the incident.
Categorization speeds up the process of incident classification and creates
greater efficiency within the process flow while priority assignment can
help ensure a common lexicon when an incident is being discussed, help
determine urgency, incident response and reporting requirements, as well
as recommendations for leadership engagement.
Incident priority designation can help ensure a common lexicon when
an incident is being discussed. It also helps determine urgency, incident
response and reporting requirements, as well as recommendations for
leadership engagement.
Based on the material reviewed for this study, some States first categorize
a cyber incident and then assign it priority, while some only attend to the
first. Ideally, both should be covered.
Other taxonomies developed by private entities can also be useful to
consider when developing NCICS.6
6 See, for example, FIRST Metrics SIG; FIRST DNS Abuse SIG; the MITRE framework.