Cyber Incident Classification 35 • Regularly exercising the system to build resilience to incidents and test its effectiveness and the preparedness of relevant stakeholders. • Regular generation of statistics and reports. • Regular analysis of statistics to understand anomalies in the system (e.g., if too many incidents are registered under ‘Other’, said incident may require a new classification). • Continuous interpretation and communication of results to the target audience in a timely, consistent and clear manner. • Comparative analysis of classification standards and systems across countries and regions. CHALLENGES IN DEVELOPING AND IMPLEMENTING NATIONAL CYBER INCIDENT CLASSIFICATION SYSTEMS It would be presumptuous to assume that cyber incident classification systems come without challenges. The challenges that OSCE participating States have identified vary significantly, reflecting in part the level of maturity of each country’s classification system. Challenges include: • Developing a taxonomy that is meaningful and can be used across different entities and sectors; • Maintaining objectivity in the design of the system; • Sustaining the iterative process of categorizing and prioritizing incidents; • An absence of regulation or relevant requirements to ensure that incidents are reported or notified to the relevant body; • Setting reporting/notification thresholds and implementing related requirements; • A limited number of qualified and experienced personnel to maintain the system; and • A lack of awareness of the system or understanding of how it works.

Select target paragraph3