44
Recommendations
Engaging relevant stakeholders and constituencies in the design and
development of the classification system can contribute to building trust
between public and private actors and within and across sectors and
services from the outset.
A standard approach to categorizing and prioritizing cyber incidents in
accordance with their severity and scale is important for diagnosing an
incident and relating the importance of the incident to its impact on a specifi c
institution, entity or sector and its urgency, relative to the timing of the
incident. Categorization speeds up the process of incident classification and
creates greater efficiency within the process flow while priority assignment
can help ensure a common lexicon when an incident is being discussed,
help determine urgency, incident response and reporting and notification
requirements, as well as recommendations for leadership engagement.
Ensuring clarity on the scope or coverage of a cyber incident classification
system, including by establishing clear criteria to determine its key
stakeholders and constituents is important, particularly for notification
and reporting purposes. The system should remain flexible enough to
accommodate an ever-changing threat landscape and include pprotocols
that determine how to proceed when challenges relevant to categorization
of incidents are encountered. Uniform and consistent procedures for
incident notification and reporting is critical to the effectiveness of cyber
incident classification systems.
Regular reviews of a NCICS are necessary to assess its scope and
effectiveness and ensure it is appropriately informing a country’s incident
response and its risk or emergency management posture. Any changes to
the incident classification system deriving from the review process should
be introduced in a manner that allows for long-term comparative analysis.
Sharing national approaches to classifying ICT incidents in terms of the scale
and seriousness of the incident with other States can contribute to building
confidence between States and help avoid potential misunderstandings
that may emerge around cyber incidents and related response measures, thus
contributing to regional and international security and stability.
People and resources
Continuous political commitment, skilled personnel, including a
dedicated incident response entity or team with sound expertise in both
general and cyber crisis management, and adequate and stable budgets