ICS
1Stage 1 of 3

Prepare

Incident command is mostly people and paperwork, and both have to exist before the incident does. The technical preparation lives in the PIVTR-D preparation playbook. This page covers what the incident organization needs in place before anyone stands it up.

People

Name at least two trained people for every seat you expect to fill, so the incident survives its first shift change. Training covers the role, the forms and the meetings. Weight it toward the incident commander, the one job nobody does day to day.

Practise in the seats. Google runs Wheel of Misfortune exercises, role-playing past incidents so less experienced on-callers build skill somewhere safe. Run tabletops the same way: replay real incidents, rotate who holds command, communications and operations, and time the first objectives and the first executive update.

Authority

Write down what the incident commander can do without asking: isolate systems, suspend accounts, take services offline, activate retainers, spend up to a set amount, engage law enforcement. Put the limits in business terms. Name who approves anything above them, and their backups.

Detection that reaches someone

The incident organization starts when someone is paged. Google's guide asks four things of an alert: it arrives in time, it covers what users depend on, it measures what users experience, and someone can act on it. For security, read that as detections that fire early enough to contain, cover the systems and identities that matter most, carry enough context to size the incident, and route to someone who can take command. The PIVTR-D identification playbook covers the detection side.

Tools that open the incident for you

Automate the first ten minutes so responders spend them thinking. One action should open the incident record from the ICS 201 template, create the command bridge and the out-of-band room, page the incident commander and on-call, start a timestamped activity log, and post the first internal notice. Google's guide points the same way: automate common tasks and the first read of impact so on-callers can work the problem.

Contracts and outside help

  • Incident response retainer: how to activate it, response times, who can sign.
  • Cyber insurance: notice deadline, panel vendors, what the insurer must approve.
  • Counsel: who to call, and when counsel directs the investigation.
  • Managed providers: which containment actions they take on their own authority.
  • Law enforcement: named contacts, agreed before you need them.

Ready to run an incident

#Item
1Two trained people named for incident commander, operations, communications and planning
2Incident commander authority written, with limits and approvers
3Incident types mapped to your severity scale and published
4Forms and the incident record template ready to copy
5Out-of-band channel and accounts provisioned outside the main identity provider
6Contact roster for internal and outside parties, kept offline and tested
7Retainer, insurer and counsel details in the roster
8One action that opens a new incident
9Shift length and relief rules agreed
10A tabletop in the last quarter, with the seats rotated
Adapted from the National Incident Management System, Third Edition (FEMA, 2017). Cyber adaptation, examples and templates by Habib Tora, licensed under CC BY 4.0. Not published by, endorsed by, or affiliated with FEMA or the Department of Homeland Security. Structure after Google's SRE Incident Management Guide. Companion to PIVTR-D.