2Respond and manage
Principles
NIMS names fourteen management characteristics. Together they let people who do not normally work together run one response. The right-hand column is what each looks like in a cyber incident.
| Characteristic | In NIMS | In a cyber incident |
|---|---|---|
| Common terminology | Plain language and defined terms across every organization involved | One name per system, one severity scale, one agreed meaning for contained. Publish the glossary before the incident. |
| Modular organization | The organization grows from the top down only as far as the incident needs | Start with an incident commander. Add sections when workload or span of control calls for them, and fold them back when it drops. |
| Management by objectives | Command sets objectives, the sections choose tactics to meet them | An objective names an outcome, a measure and a time, such as no attacker access to domain controllers by 18:00. Tasks sit below it in assignments. |
| Incident action planning | A plan for each operational period, written once the incident is large enough | The IAP says what this period is for, who does what, how people talk to each other, and when the next briefing is. |
| Manageable span of control | NIMS treats one supervisor to five people as optimal. ICS training uses three to seven as the working range | When a lead has more than seven people reporting, split the work into groups with their own supervisors. |
| Incident facilities and locations | Command post, staging areas, bases | The war room, physical or virtual, a clean build network, the evidence store, somewhere to sleep. |
| Comprehensive resource management | Identify, order, track and release resources | Retainers, forensic licences, loaner hardware and extra staff are ordered through Logistics and tracked until returned. |
| Integrated communications | A shared communications plan and interoperable channels | An out-of-band channel, a command bridge, a status cadence and a list of who hears what, written into the communications plan. |
| Establishment and transfer of command | Command is established at the start and transferred by briefing | The first qualified person takes command and says so. Handover happens by briefing, is announced, and is logged. |
| Unified command | Organizations with authority share command through one set of objectives | IT, security, OT, counsel and the business agree one set of objectives and one plan, each keeping authority over its own people. |
| Unity of command and chain of command | Every person reports to one supervisor, and authority runs in a clear line | Every responder has one boss for the length of the incident, whatever their day-job reporting line. |
| Accountability | Check-in, assignments, and records of who is where | Everyone working the incident is on the roster with an assignment and a relief time. |
| Dispatch and deployment | Resources join when requested and dispatched | Help from other teams arrives through the IC or Logistics with an assignment. Nobody freelances. |
| Information and intelligence management | Collect, analyze and share incident information | Forensic findings and threat intelligence flow through one situation picture, owned by Planning. |
If you adopt only three
Name one incident commander out loud, write objectives before tactics, and hand over by briefing. Most of the rest grows from those.