Chapter 2
Cyber Incident
Classification in
the OSCE Region
2.1 Purpose of a national cyber incident
classification system
This section of the report explores questions faced when establishing
cyber incident classification systems, including whether such a system
is already in place and if not, whether there are plans underway to
establish such a system. Importantly, it considers views on the purpose
of such systems and explores whether existing approaches derive from
or are tied to broader policy and legislative frameworks. It also delves
into the question of roles and responsibilities relevant to cyber incident
classification systems, including co-ordination of the development and
implementation of the classification system and those entities that
might be involved in the process of classifying cyber incidents.
OSCE participating States have taken different approaches to cyber
incident classification. While some systems have been in place over two
decades, most were established after 2015. Many of these classification
systems and enabling legislative or regulatory instruments are publicly
available online. Some countries that do not currently have a cyber
incident classification system in place plan to establish one within the next
two years.
In general terms, the purpose of a NCICS is to generate a clear picture of
the cyber threat landscape, to ensure a prompt response to cyber/ICT
incidents and to minimise the damage they can cause. More specifically,