All information security incidents MUST be classified by one or more threat categories.NOTE See Glossary entry in Appendix A for Threat Categories.5.2.2 All information security incidents MUST have an associated severity rating.NOTE 1. This severity rating may change during the course of an incident.NOTE 2. See Glossary entry in Appendix A for Severity Ratings.5.2.3 All information security incidents MUST be assessed for impact materiality in accordance with the