28 Cyber Incident Classification in the OSCE Region (using a colour schema from white to red); and outlook (i.e., the prognosis of the impact (from improving to worsening). Some also use the ENISA8 Reference Incident Classification Taxonomy (which also informed the NIS CIT) as a starting point for incident classification. It is centered on ten incident types (abusive content, malicious code, information gathering, intrusion attempts, intrusion, availability, information content security, fraud, vulnerable, and other). Many European CSIRTs or relevant bodies already use this taxonomy, often in conjunction with an incident ‘category’ scale based on incident severity. CONCLUSION Learning from other States and drawing from their experiences is also important. In this regard, one participating State noted that its classification matrix (severity and impact presented on an axis) was influenced by the cyber incident categorization system developed by the National Cyber Security Centre (NCSC) of the United Kingdom.9 Said system includes 6 categories, with category 1 representing a national emergency. Like others, it also includes category definitions, as well as explanations of who responds, and what that response entails across each category. 8 ENISA - The European Union Agency for Cybersecurity - Reference Incident Classification Taxonomy https://www.enisa.europa.eu/publications/ reference-incident-classification-taxonomy/ 9 The UK National Cyber Security Centre’s updated incident categoriation system is available here: https://www.ncsc.gov.uk/pdfs/news/new-cyber-attack-categorization-system-improve-uk-response-incidents.pdf

Select target paragraph3