Cyber Incident Classification 3 Contents Acknowledgments 4 List of Acronyms and Abbreviations 5 Foreword 6 Executive Summary 7 Chapter 1 Background and Introduction 10 Chapter 2 Cyber Incident Classification in the OSCE Region 12 2.1 Purpose of a national cyber incident classification system 12 Relation with broader national cyber incident or crisis management framework and national legislation 16 Scope of national cyber incident classification systems 18 Requirements (e.g., government-mandated reporting or notification requirements) stemming from national cyber incident classification systems 19 Guidance to support implementation of incident classification frameworks 2.2 Process and Institutional Arrangements 20 23 Institutional responsibilities: the national entities responsible for designing and co-ordinating decisions on cyber incident classification 23 National approaches to cyber incident categorization and prioritization 24 Commonalities in categorizing and prioritizing cyber incidents 29 Review procedures 31 Capacity and resource requirements 32 Challenges in developing and implementing national cyber incident classification systems 2.3 International Co-operation Exchanges on national approaches to cyber incident classification Capacity building and other initiatives relevant to national cyber incident classification 35 39 39 40 Chapter 3 Recommendations 42 Chapter 4 Concluding Remarks 46 Annex 1 – OSCE Permanent Council Decision No. 1202 48 Annex 2 – Publicly available documents shared by OSCE participating States on national cyber incident classification systems 55

Select target paragraph3