CBM 11: Incident severity schemas
Organization of American States
Measure
CBM 11 (2022): Develop national cyber incident severity schemas and share information about them.
Background: This CBM encourages member states to develop and share national cyber incident severity schemas – frameworks that classify incidents by impact, scope, and urgency that enable authorities to assess and respond to incidents consistently and proportionately while helping prioritise resources. Sharing them across states fosters common understanding and interoperability, supporting faster, more coordinated cross-border responses and reducing the risk of misinterpretation or escalation caused by differing threat perceptions. In addition, it promotes transparency and facilitates information sharing and cooperation, which is particularly critical when incidents have transnational effects.
Practice: Unlike many other CBMs, this measure has a clear and verifiable objective. At the fourth Working Group meeting, the United States presented its cyber incident severity scoring system, which is now being explored as a potential model for regional adoption. While the original plan envisioned each state developing its own schema and sharing it through the web portal, discussions have shifted toward creating a common, standardised system to enhance interoperability and streamline information sharing. Following this, by the end of 2025 the Dominican Republic has submitted a non-paper as a non-binding reference tool to assist OAS Member States in developing their own classification systems to advance the implementation of this CBM.
So far, efforts have not yet begun, so there is no implementation, but the CSIRTs Americas Network is expected to play a central role in moving this effort forward.
Key Implementation Activities and Resources
OAS member states have begun discussing approaches to cyber incident severity classification, including presentations of existing national models and proposals for a common regional framework to improve interoperability.
Preparatory resources include the United States' cyber incident severity scoring system and a non-paper developed by the Dominican Republic to support national implementation efforts.