Resources
NIMS resource management is how an incident gets the right people and equipment, and gives them back. It rests on three things: describing resources the same way everywhere, knowing who is qualified, and running every request through one process.
Typing
NIMS describes a resource by kind, what it is, and type, how capable it is. Typing lets a request say exactly what is needed and lets a supplier confirm it can deliver. Define your cyber resources the same way before the incident.
Example
| Resource | Kind | Type 1 | Type 2 |
|---|---|---|---|
| Incident commander | Personnel | Has commanded a Type 2 or larger incident | Has commanded a Type 3 incident |
| Forensic analyst | Personnel | Leads host and memory forensics and defends the findings | Collects and processes evidence under supervision |
| Rebuild strike team | Team | Five technicians with imaging rights and a staging area | Three technicians with imaging rights |
| Clean administration kit | Equipment | Hardened workstation, break-glass credentials, offline tools | Hardened workstation |
Qualification and credentialing
NIMS separates qualifying a person for a position, certifying that they meet the standard, and credentialing them so other organizations can trust it. FEMA's qualification system uses position task books: the tasks a person must show they can do in a role. Write a one-page task book for each seat you fill, and sign it off after an exercise or a real incident.
The resource management process
NIMS runs every incident resource through six steps. Several resources can be at different steps at once.
| Step | In a cyber incident |
|---|---|
| Identify requirements | Operations states what it needs, by kind and type, at the tactics meeting |
| Order and acquire | Logistics orders from inside the organization, the retainer or mutual aid. Finance/Admin approves the spend |
| Mobilize | Check-in, assignment, access granted, briefing |
| Track and report | The Resources unit keeps status: assigned, available, resting, released |
| Demobilize | Check-out: access revoked, evidence handed over, hardware returned |
| Reimburse and restock | Invoices paid, insurance claim filed, licences and spares replaced |
Mutual aid
Mutual aid agreements let organizations lend each other resources on terms agreed in advance. For cyber, the sources are your sector's ISAC, peer organizations, technology partners, and government support, which varies by sector and state. Agree the terms before you need them: who can ask, what is provided, who pays, and how access and confidentiality work.