8
P
P
PURPOSE
AND
OBJECTIVES
POLICY
AND LEGAL
BASES
Clarity about the purpose and objectives of the cyber incident classification system and its core stakeholders and constituents is a critical
first step in its implementation and
socialisation.
Having a sound policy and/or legal base
for cyber incident classification is critical
to ensuring its effectiveness as well as its
sustainability. Clear provisions on overall
responsibility for the system, interagency
co-operation, reporting and notification,
data-handling procedures, resource allocation and review procedures are equally
important. Furthermore, ensuring appropriate linkages with broader national
crisis/emergency management policy or
legislation is also essential.
In a national context, it is important to have clearly articulated guidance in place, which specifies:
•
The policy and legal base for what the cyber incident classification is setting out to achieve;
•
Who co-ordinates its development and implementation;
•
Who its key stakeholders/constituencies are;
•
What the process of categorizing and prioritizing an incident entails;
•
The response mechanisms for incidents;
•
What would happen to activate a specific classification; and
•
How regularly the incident classification system is reviewed and what the review
process entails.