6  Foreword The OSCE is the world’s largest regional security organization, encompassing 57 participating States in Europe, Asia and North America. The Organization’s cross-dimensional approach to security lent itself to efforts in disarmament and implementation of security- and confidence-building measures in a number of security areas. In cyber/ICT security, participating States quickly recognized a potential for applying confidence-building measures (CBMs) in cyberspace. The OSCE plays a pioneering role in enhancing cyber/ICT security, being the first regional organization to develop CBMs to reduce the risks of conflict stemming from the use of ICTs among its participating States. In the past decade, regional organizations have served as incubators of UN recommendations on international ICT security. This momentum was recently reinforced by landmark reports adopted by the UN Open-Ended Working Group on “developments in the field of information and telecommunications in the context of international security” and by UN Group of Governmental Experts on “Advancing responsible State behaviour in cyberspace in the context of international security”. Both reports recognize the importance of regional and sub-regional organizations in developing and implementing CBMs in their respective regions. Since 2013, OSCE participating States have adopted and continue to work on the implementation of 16 cyber/ICT CBMs, due to the fact that the CBM process is practical, voluntary and depoliticized in nature. As such, it has proven its worth as a tool to strengthen inter-State collaboration, create transparency, and foster greater preparedness. The OSCE Secretariat’s Transnational Threats Department supports participating States in the implementation of cyber/ICT security CBMs, by providing a platform to conceptualize and exchange best practices on such topics as public-private partnerships, responsible reporting of vulnerabilities and critical infrastructure protection. The foundation for this report is in CBM 15, through which participating States agreed to —on a voluntary basis—“encourage, facilitate and/or participate in regional and subregional collaboration between legally-authorized authorities responsible for securing critical infrastructures to discuss opportunities and address challenges to national as well as trans-border ICT networks, upon which such critical infrastructure relies”. One of the areas of collaboration is the adoption of voluntary national arrangements to classify ICT incidents by their scale and seriousness. The report highlights emerging practices in national classification of cyber incidents by underlining commonalities in existing approaches to cyber incident classification among OSCE participating States and identifying limitations in this process. Although experiences in developing cyber incident classification systems are diverse across participating States, the knowledge derived from these processes could be used as a capacity-building tool to promote the use of national cyber incidents classification systems within the OSCE area and beyond. Alena Kupchyna Co-ordinator of Activities to Address Transnational Threats OSCE Secretariat

Select target paragraph3