Cyber Incident Classification
3
Contents
Acknowledgments
4
List of Acronyms and Abbreviations
5
Foreword
6
Executive Summary
7
Chapter 1 Background and Introduction
10
Chapter 2 Cyber Incident Classification in the OSCE Region
12
2.1 Purpose of a national cyber incident classification system
12
Relation with broader national cyber incident or crisis management
framework and national legislation
16
Scope of national cyber incident classification systems
18
Requirements (e.g., government-mandated reporting or notification
requirements) stemming from national cyber incident classification systems
19
Guidance to support implementation of incident classification frameworks
2.2 Process and Institutional Arrangements
20
23
Institutional responsibilities: the national entities responsible for
designing and co-ordinating decisions on cyber incident classification
23
National approaches to cyber incident categorization and prioritization
24
Commonalities in categorizing and prioritizing cyber incidents
29
Review procedures
31
Capacity and resource requirements
32
Challenges in developing and implementing national cyber incident
classification systems
2.3 International Co-operation
Exchanges on national approaches to cyber incident classification
Capacity building and other initiatives relevant to national cyber incident
classification
35
39
39
40
Chapter 3 Recommendations
42
Chapter 4 Concluding Remarks
46
Annex 1 – OSCE Permanent Council Decision No. 1202
48
Annex 2 – Publicly available documents shared by OSCE participating
States on national cyber incident classification systems
55