26
Cyber Incident Classification in the OSCE Region
EXAMPLES
THE US APPROACH
The US approach to incident categorization involves a scoring system
based on eight different categories of incidents: Functional Impact;
Observed Activity; Location of Observed Activity; Actor Characterization;
Information Impact; Recoverability; Cross-Sector Dependency; and
Potential Impact. A weighted arithmetic mean is used to arrive at a
score between zero and 100. Each category is assigned a weight and the
response to each category has an associated score. Each response score is
then multiplied by the category weight, and the weighted scores are added
together. Once the score is determined, the incident is then assigned a
priority for which a colour scheme is used, with priorities ranging from
Baseline (baseline minor (blue) and baseline negligible (white)) to
Low (green) all the way up the ladder to Emergency (black). In addition,
the schema also assesses whether incidents are connected and how
incident aggregation should be considered when assessing a campaign.
Source: https://www.cisa.gov/uscert/sites/default/files/ncirp/National_Cyber_Incident_
Response_Plan.pdf (pg 38)