APPENDIX C (NORMATIVE) INCIDENT MANAGEMENT CRITICALITY CLASSIFICATION Category C1 Typical Incident Categories • Denial of service • Compromised Asset (critical) • Internal Hacking (active) • External Hacking (active) • Virus / Worm (outbreak) • Destruction of property (critical) C2 • Internal Hacking (not active) • External Hacking (not active) • Unauthorized access. • Policy violations • Unlawful activity. • Compromised information. • Compromised asset. (non-critical) • Destruction of property (non-critical) C3 • Email • Forensics Request • Inappropriate use of property. • Policy violations. CSO Critical Sector Organization as defined in CIIP Law CII Critical Information Infrastructure as defined in CIIP Law Incident Matrix C1 C2 C3 CSO+CII CL1 CL1 CL3 CSO+ Non CII CL1 CL2 CL3 Non CSO + CII CL1 CL2 CL3 Non CSO + Non CII CL3 CL3 CL3 NATIONAL INFORMATION ASSURANCE MANUAL 56

Select target paragraph3