8  P P PURPOSE AND OBJECTIVES POLICY AND LEGAL BASES Clarity about the purpose and objectives of the cyber incident classification system and its core stakeholders and constituents is a critical first step in its implementation and socialisation. Having a sound policy and/or legal base for cyber incident classification is critical to ensuring its effectiveness as well as its sustainability. Clear provisions on overall responsibility for the system, interagency co-operation, reporting and notification, data-handling procedures, resource allocation and review procedures are equally important. Furthermore, ensuring appropriate linkages with broader national crisis/emergency management policy or legislation is also essential. In a national context, it is important to have clearly articulated guidance in place, which specifies: • The policy and legal base for what the cyber incident classification is setting out to achieve; • Who co-ordinates its development and implementation; • Who its key stakeholders/constituencies are; • What the process of categorizing and prioritizing an incident entails; • The response mechanisms for incidents; • What would happen to activate a specific classification; and • How regularly the incident classification system is reviewed and what the review process entails.

Select target paragraph3