Cyber Incident Classification 7 Executive Summary In January 2022, the Secretariat of the Organization for Security and Co-operation in Europe (OSCE), in the framework of an extra-budgetary project, embarked on a study of emerging practices in cyber/ICT incident classification in the OSCE region. To inform this study, it disseminated a questionnaire to OSCE participating States. An analysis of the survey results along with a review of publicly available documents referenced in participating States’ responses suggest that greater attention is being paid to cyber incident classification across the region and that these systems are viewed as critical to managing cyber incidents at the national level and for engaging with other States on cyber incidents at the regional and international levels. A growing number of OSCE participating States already have, or are in the process of establishing a national cyber/ICT incident classification system. Many have also established or are reviewing the policy and legal basis for cyber incident classification or are moving in that direction. In several States, their system is closely tied to national plans for crisis management or emergency planning. Responsibility for the development and co-ordination of NCICS varies across the region. Existing practices conf i rm that, for incident classif i cation to be effective, co-operation between a broad range of public and private actors and sectors, including, for instance, government agencies, CERTs1/CSIRTs2 or similar, operators of essential services and digital service providers, is necessary. The importance of engaging relevant non-State actors such as cyber security researchers is increasingly acknowledged by some participating States. The study also provides insights into some of the challenges OSCE participating States are facing in developing and implementing their cyber incident classification systems. These challenges range from personnel and resource constraints, to agreeing on a common classification taxonomy that is clearly communicated to and used by all intended constituencies, but also interagency co-operation and information sharing as well as reviewing and adapting the system once in place. The study suggests that efforts are underway to overcome many of these challenges and that capacity building and other forms of co-operation will play an important role to that end. Several participating States have voiced an interest in availing of the OSCE to exchange national experiences on incident classification and to potentially engage in more dedicated exchanges on the topic, including crisis management exercises. The study also suggests that these emerging practices and related challenges, which are presented below under the rubrics purpose, policy, process and people, be taken up within further exchanges among OSCE participating States and between the OSCE and other regions. These discussions would ensure further advancements in the spirit and intent of the OSCE cyber/ICT CBMs, particularly CBMs 15 and 33, as well as those agreed at the UN. 1 CERTs—Computer Emergency Response Teams 2 CSIRTs—Computer Security Incident Response Teams 3 Permanent Council Decision No. 1202 | OSCE

Select target paragraph3