46 Concluding Remarks Chapter 4 Concluding Remarks Experiences in designing these systems vary significantly across OSCE participating States, yet the study clearly demonstrates that common baselines are critical to effective cyber incident management at the national level, and for engaging on cyber incidents regionally and internationally. Some participating States have had incident classification systems in place for quite some time and have developed sound legal and/or policy bases to ensure their effective co-ordination and management as well as adequate resource allocation. For some participating States also members of other organizations such as the EU, existing regulation (e.g., the NIS Directive) has accelerated the establishment of incident classification systems, many of which are now coming into their own. Other participating States are undertaking the first steps toward establishing an incident classification system, while yet others are planning to establish one within the next two years. It is clear from the experiences discussed that a common classification taxonomy is key to ensuring the effectiveness of any cyber incident classification system. It needs to be clearly communicated to all intended constituencies on a regular and timely basis. Furthermore, establishing and nurturing interagency co-operation and information sharing adds to the effectiveness. Equally important is ensuring regular reviews of the system and allowing enough flexibility to adapt it to shifting circumstances. Regardless of the stage of development and implementation of their NCICS, the study presents some important emerging practices and lessons across the four categories of purpose, policy, processes and people.

Select target paragraph3