ICS
2Respond and manage

Resources

NIMS resource management is how an incident gets the right people and equipment, and gives them back. It rests on three things: describing resources the same way everywhere, knowing who is qualified, and running every request through one process.

Typing

NIMS describes a resource by kind, what it is, and type, how capable it is. Typing lets a request say exactly what is needed and lets a supplier confirm it can deliver. Define your cyber resources the same way before the incident.

Example

ResourceKindType 1Type 2
Incident commanderPersonnelHas commanded a Type 2 or larger incidentHas commanded a Type 3 incident
Forensic analystPersonnelLeads host and memory forensics and defends the findingsCollects and processes evidence under supervision
Rebuild strike teamTeamFive technicians with imaging rights and a staging areaThree technicians with imaging rights
Clean administration kitEquipmentHardened workstation, break-glass credentials, offline toolsHardened workstation

Qualification and credentialing

NIMS separates qualifying a person for a position, certifying that they meet the standard, and credentialing them so other organizations can trust it. FEMA's qualification system uses position task books: the tasks a person must show they can do in a role. Write a one-page task book for each seat you fill, and sign it off after an exercise or a real incident.

The resource management process

NIMS runs every incident resource through six steps. Several resources can be at different steps at once.

StepIn a cyber incident
Identify requirementsOperations states what it needs, by kind and type, at the tactics meeting
Order and acquireLogistics orders from inside the organization, the retainer or mutual aid. Finance/Admin approves the spend
MobilizeCheck-in, assignment, access granted, briefing
Track and reportThe Resources unit keeps status: assigned, available, resting, released
DemobilizeCheck-out: access revoked, evidence handed over, hardware returned
Reimburse and restockInvoices paid, insurance claim filed, licences and spares replaced

Mutual aid

Mutual aid agreements let organizations lend each other resources on terms agreed in advance. For cyber, the sources are your sector's ISAC, peer organizations, technology partners, and government support, which varies by sector and state. Agree the terms before you need them: who can ask, what is provided, who pays, and how access and confidentiality work.

Adapted from the National Incident Management System, Third Edition (FEMA, 2017). Cyber adaptation, examples and templates by Habib Tora, licensed under CC BY 4.0. Not published by, endorsed by, or affiliated with FEMA or the Department of Homeland Security. Structure after Google's SRE Incident Management Guide. Companion to PIVTR-D.