36
Cyber Incident Classification in the OSCE Region
Another identified challenge relates to the categorization and prioritization
of incidents. Even the best classification system cannot include all the
different possible incident categories. Sometimes, however, an incident
does not fit into a certain category or can fit into multiple categories,
creating obstacles for triaging an incident. Protocols for determining how
to proceed in such situations may therefore be required.
RECOMMENDATION 12
It is important to establish protocols that determine how
to proceed when challenges relevant to categorization of
incidents are encountered.
The challenge of setting meaningful thresholds for classifying incidents
in a manner that can then be interpreted by relevant stakeholders
requires specific attention. Since there are many ways of looking at an
incident and different actors generally have different information at
their disposal, it is often challenging to achieve a common picture of the
incident. A lack of specific information provided by target organizations
relevant to an incident often requires further interaction to fully leverage
the classification scheme. Furthermore, the dynamic, non-static aspect of
cyber incidents is not necessarily catered for in current approaches. In
this regard, decisions regarding the category and priority assignation of
a given incident is generally based on the information that the incident
handler has at a given moment. However, said information can change as
time passes, which may in turn change the priority level of the incident.
Terminology continues to pose challenges, since many terms in and
of themselves do not have a delimited meaning. An example of how
to overcome this challenge includes developing a list of definitions
and concepts that is then included in the relevant legal instrument or
guidance document, although this might become a challenge too, if too
narrow in scope.