Cyber Incident Classification 39 2.3 International Co-operation This section of the report explores potential co-operative measures around national cyber incident classification systems, including openness to sharing the national approach— or elements thereof—to incident classification. It presents views on the existence and value of capacity building in this area, as well as the views on voluntarily participating in dedicated exchanges, including crisis management exercises relevant to cyber incident classification. EXCHANGES ON NATIONAL APPROACHES TO CYBER INCIDENT CLASSIFICATION Beyond establishing common and transparent processes and procedures for classifying cyber incidents at the national level, it is broadly accepted that voluntarily sharing national approaches to classifying ICT incidents in terms of the scale and seriousness of the incident with other States can contribute to building confidence between States and help avoid potential misunderstandings that may emerge around cyber incidents and related response measures. RECOMMENDATION 13 Sharing national approaches to classifying ICT incidents in terms of the scale and seriousness of the incident with other States can contribute to building confidence between States and help avoid potential misunderstandings that may emerge around cyber incidents and related response measures, thus contributing to regional and international security and stability. Exchanging experiences and sharing information with other states can also be a valuable contribution to the development, testing and maturing of cyber incident classification systems. It can enhance incident management and response, ensure a more common understanding of existing and evolving threats, while also contributing to the broader goal of trust and confidence building.

Select target paragraph3