Cyber Incident Classification 29 COMMONALITIES IN CATEGORIZING AND PRIORITIZING CYBER INCIDENTS In accordance with existing approaches, when categorizing incident types, participating States generally assess the impact of a cyber incident on the following: Impacts the Classification System is Aiming to Measure IMPACTS ON NATIONAL INSTITUTIONS 21 IMPACTS ON SERVICES PROVIDING ESSENTIAL SERVICES TO THE PUBLIC 24 IMPACTS ON SPECIFIC SECTORS 20 IMPACTS ON THE ECONOMY 18 IMPACTS ON THE POPULATION 17 OTHER 4 0 5 10 15 20 25 There are also many commonalities regarding the criteria for classifying an incident in terms of its severity and/or seriousness. These criteria include: scale (magnitude/primary and secondary effects/impact/ consequences of the incident), targeted institution/sector, duration, scope, capabilities used, frequency and other. Mostly two or more of the listed criteria are used, with scale, targeted institution, duration and scope being the most commonly cited, followed by capabilities used and frequency.

Select target paragraph3