Use as many levels as the organization can apply consistently. The labels below are illustrative, not ISO-defined. A usable row ties observable conditions to an initial owner, escalation path, decision authority, communication route, response objective, and reassessment rule. Avoid vague labels such as 'major impact' unless the row explains what qualifies.
A single factor can set a minimum level or force escalation. For example, a safety concern, confirmed compromise of a critical service, evidence at risk, or a potential legal-reporting duty may require immediate specialist or management involvement even while the overall impact is uncertain. Write that override into the matrix instead of relying on memory.
Test the rows with source-supported incident types rather than abstract labels alone. A blocked malicious-email attachment with no execution or affected account may remain a low-impact event after validation. Repeated password attacks against an exposed account can rise when evidence shows compromise or spread. A denial-of-service attack against a critical public service, theft of an unencrypted device holding sensitive data, or a supply-chain backdoor can force higher escalation because service, data, third parties, recovery, and reporting analyses are involved. The final rating still depends on the organization's actual or projected consequences.