Cyber Incident Classification
23
2.2 Process and Institutional Arrangements
This section of the report highlights the capacities and resources
that might be required to develop, manage and sustain a national
cyber incident classification system, as well as related processes and
arrangements. It explores approaches to classifying cyber incidents,
what existing systems set out to measure, whether specific schemas are
used, how they are presented and defined/explained, and the criteria
that are considered when an incident is being classified in terms of
severity/ seriousness. It also discusses review procedures, and explores
whether specific requirements stem from the system. It concludes with
an essential discussion on some of the core challenges States have
encountered when developing and implementing national cyber incident
classification systems.
INSTITUTIONAL RESPONSIBILITIES: THE NATIONAL ENTITIES RESPONSIBLE
FOR DESIGNING AND CO-ORDINATING DECISIONS ON CYBER INCIDENT
CLASSIFICATION
RECOMMENDATION 7
Cyber incident classification is generally a centralized process
co-ordinated by a central entity or authority and
involving a range of government bodies. Depending on
the context, it may also include essential or important
services/critical infrastructure asset owners or operators,
service providers and other private sector entities.
digital
Responsibility for the development and co-ordination of national cyber
incident classification systems varies significantly. In some cases, this
role is held by a central co-ordinating entity (e.g., a national security
council under which a national cyber security council is; an interagency
co-ordination body; a national computer incident response and
co-ordination centre).
In other instances, the responsibility is held by a dedicated cyber
or information security entity or authority (e.g., national cyber or