ICS

Incident Command

A NIMS-based guide to running incidents. Written for cybersecurity. Works for anything.

Any organization large enough to have incidents will eventually have one that outgrows the team that found it. How that incident goes depends on three things: whether someone is clearly in charge, whether everyone hears the same facts, and whether the work is planned or improvised. The National Incident Management System answers all three, and emergency services in the United States have run on it for two decades.

This guide adapts NIMS to cybersecurity. The structure, vocabulary and paperwork carry over almost unchanged. What changes is who fills each seat and what each section does. It is laid out the way Google's SRE team presents its own ICS-based process, in three stages: prepare, respond and manage, learn. Nothing here depends on the incident being cyber.

STAGE 1PreparePeople trained for each seatAuthority agreed in advancePlaybooks and forms readyChannels set up out of bandDrills that rotate the seatsSTAGE 2Respond and manageCoordinateCommunicateControlIncidentcommanderCommunicationsleadOperationsleadGrows into the full ICS organization as the incident doesSTAGE 3LearnBlameless after-action reviewActions with owners and datesTracked in the backlogTrends across incidentsFindings back into preparationWhat the review finds feeds the next round of preparation
CoordinateOne commander, one set of objectives, one plan per operational period
CommunicateEvery audience hears the same facts, on a schedule, from one voice
ControlClear assignments, a manageable span of control, nobody freelancing

Prepare

Most of what decides an incident is settled before it starts. The people for each seat are trained and have practised in it. The authority to isolate systems, suspend accounts and spend money is agreed. The channels, forms, contracts and playbooks are ready to use at two in the morning. Prepare lists what to have in place.

Respond and manage

The first qualified person takes command out loud. Three roles cover most incidents: an incident commander who coordinates, a communications lead who keeps every audience informed, and an operations lead who runs the technical work. When the incident outgrows one shift or one team, the rest of the ICS organization fills in around them: planning, logistics, finance, liaison, safety.

Each operational period gets written objectives and an Incident Action Plan. Command changes hands by briefing. Nobody joins the response without an assignment. Respond and manage covers the organization, sizing, the planning cycle, unified command, communications and handover.

Learn

The after-action review starts as soon as the incident closes, while memory is fresh. It is blameless: people acted on what they knew at the time, so findings go to systems, procedures and training. Every corrective action gets an owner and a date and is tracked to done. Across many incidents, recurring findings show where larger investment belongs. Learn has the review questions and the improvement plan.

NIMS in one picture

ICS is one part of NIMS. The rest adds a crisis team and an executive group above the incident, one joint voice to the public, and common ways to handle resources and information at every level.

COMMAND AND COORDINATIONPOLICYMultiagency Coordination GroupCyber: the executive decision group. Priorities, policy, scarce resourcespriorities, decisions, resourcessituation, requestsSUPPORTEmergency Operations CenterCyber: the crisis management team. Business impact, continuity, resourcespriorities, decisions, resourcessituation, requestsTACTICALIncident Command SystemCyber: incident commander, Command and General Staff. Runs the responseJoint InformationSystemOne set of public factsacross every partyCyber: the comms leadsof your organization,suppliers, insurer andlaw enforcementRUNNING THROUGH EVERY LEVELResource managementtyping, qualification, ordering, tracking, mutual aidCommunications and information managementinteroperable channels, common terms, common operating picture

NIMS at a glance walks through the three components and the four structures.

How it pairs with PIVTR-D

PIVTR-D covers the response lifecycle, the technical work from preparation to debrief. This guide covers the management around that work: who decides, how the team is organized, how the plan is written and handed over, and how the effort holds up past the first night.

PIVTR-D phaseWhere it sits in incident command
PreparationPrepare: people qualified for each seat, pre-agreed authority, the forms, the communications plan
IdentificationOutside the incident organization until an event of interest is raised
Verification and triageInitial response and assessment. The first qualified responder takes command and sizes the incident
Response loopThe Operations Section, working to one set of objectives per operational period, carried in the Incident Action Plan
DebriefDemobilization, then Learn

When to stand it up

Use the structure when an incident needs more than one team, will run past one shift, or will draw in executives, counsel or outside parties. An analyst closing a phishing report needs none of it beyond knowing they are in command. An enterprise ransomware event needs most of it by the end of the first day. Sizing the response sets the thresholds.

Further reading

Adapted from the National Incident Management System, Third Edition (FEMA, 2017). Cyber adaptation, examples and templates by Habib Tora, licensed under CC BY 4.0. Not published by, endorsed by, or affiliated with FEMA or the Department of Homeland Security. Structure after Google's SRE Incident Management Guide. Companion to PIVTR-D.