depending on the severity of an incident and the entity affected, incident
reporting is legally required.
Clearly articulated guidance contributes to the effective implementation
and socialization of a cyber incident classification system. Such guidance
can specify:
• The purpose of the cyber incident classification system and its
policy and/or legal basis;
• Who co-ordinates its development and implementation;
• Its scope/coverage in terms of its key stakeholders/constituencies;
• Definitions and explanations of categories and priorities;
• The response mechanisms for incidents, including an explanation
of what would activate a specific classification, which organization
responds and what actions they would take; and
• How regularly the incident classification system is reviewed and
what the review process entails.
Process and institutional arrangements
Cyber incident classification is generally a centralised process co-ordinated
by a central entity or authority and can involve a range of government
bodies. Depending on the context, it may also include essential services/
critical infrastructure asset owners or operators, digital service providers
and other relevant private sector entities.