Cyber Incident Classification
29
COMMONALITIES IN CATEGORIZING AND PRIORITIZING CYBER INCIDENTS
In accordance with existing approaches, when categorizing incident
types, participating States generally assess the impact of a cyber incident
on the following:
Impacts the Classification System is Aiming to Measure
IMPACTS ON NATIONAL
INSTITUTIONS
21
IMPACTS ON SERVICES
PROVIDING ESSENTIAL
SERVICES TO THE PUBLIC
24
IMPACTS ON SPECIFIC
SECTORS
20
IMPACTS ON THE
ECONOMY
18
IMPACTS ON THE
POPULATION
17
OTHER
4
0
5
10
15
20
25
There are also many commonalities regarding the criteria for classifying
an incident in terms of its severity and/or seriousness. These criteria
include: scale (magnitude/primary and secondary effects/impact/
consequences
of
the
incident),
targeted
institution/sector,
duration, scope, capabilities used, frequency and other.
Mostly two or more of the listed criteria are used, with scale, targeted
institution, duration and scope being the most commonly cited, followed
by capabilities used and frequency.