28
Cyber Incident Classification in the OSCE Region
(using a colour schema from white to red); and outlook (i.e., the
prognosis of the impact (from improving to worsening). Some also use the
ENISA8 Reference Incident Classification Taxonomy (which also informed
the NIS CIT) as a starting point for incident classification. It is centered
on ten incident types (abusive content, malicious code, information
gathering, intrusion attempts, intrusion, availability, information content
security, fraud, vulnerable, and other). Many European CSIRTs or relevant
bodies already use this taxonomy, often in conjunction with an incident
‘category’ scale based on incident severity.
CONCLUSION
Learning from other States and drawing from their experiences is
also important. In this regard, one participating State noted that its
classification matrix (severity and impact presented on an axis) was
influenced by the cyber incident categorization system developed by
the National Cyber Security Centre (NCSC) of the United Kingdom.9 Said
system includes 6 categories, with category 1 representing a national
emergency. Like others, it also includes category definitions, as well as
explanations of who responds, and what that response entails across
each category.
8 ENISA - The European Union Agency for Cybersecurity - Reference Incident Classification Taxonomy https://www.enisa.europa.eu/publications/
reference-incident-classification-taxonomy/
9 The UK National Cyber Security Centre’s updated incident categoriation system is
available here: https://www.ncsc.gov.uk/pdfs/news/new-cyber-attack-categorization-system-improve-uk-response-incidents.pdf