Cyber Incident Classification 19 agencies (e.g., offices of the head of government, ministries of the interior/ homeland security, justice, defence, foreign affairs, economic affairs and digital transformation; national intelligence agencies, departments or bureaux; and national cyber or information security agencies or entities), ‘essential’ or ‘important’ sectors or services deemed critical to the functioning of society or the economy, critical infrastructure asset owners, businesses, and individuals. REQUIREMENTS (E.G., GOVERNMENT-MANDATED REPORTING OR NOTIFICATION REQUIREMENTS) STEMMING FROM NATIONAL CYBER INCIDENT CLASSIFICATION SYSTEMS Uniform and consistent reporting on incidents is critical to the effectiveness of cyber incident classification systems. Often, reporting and/or notification requirements stem from the NCICS. The requirements vary, with some stemming from national cyber/ICT security- or incident-related legislation or policy frameworks that provide for a variety of government actions. RECOMMENDATION 5 Uniform and consistent reporting on incidents is critical to the effectiveness of cyber incident classification systems and helps determine the nature of the response. In some jurisdictions and depending on the severity of an incident and the entity affected, incident reporting is legally required. Reporting or notification requirements tend to be linked to incidents that are categorized higher up in the severity scale in accordance with a given country’s scoring system, which as discussed earlier, can be presented in a variety of ways (colour scheme, numerical ratings, range of severity etc.) and depends on the entities affected (e.g., operators of essential services; digital service providers; government entities; critical infrastructure sectors; information infrastructure operators) and the

Select target paragraph3