Respond and manage
Google's incident guide says it plainly: left unmanaged, a response turns chaotic. Treat it as a project in its own right, with someone planning it, someone deciding who is involved, and a record of what was done. ICS is the structure for that project.
ICS came out of the California wildfires of the 1970s, when agencies fighting the same fire used different terms, different radios and different plans. Cyber incidents break down in the same places: nobody sure who decides, three people briefing executives with three different numbers, responders on hour thirty with no relief, and a vendor, counsel and an insurer each running their own version of the response.
Coordinate, communicate, control
Google's incident management system, IMAG, is built on ICS and organizes around three Cs. Each maps onto NIMS positions.
| C | What it means | Held by |
|---|---|---|
| Coordinate | One set of objectives and one plan, with every responder working to it | Incident Commander, Planning |
| Communicate | Every audience hears the same facts on a schedule, and incoming requests have one door | Public Information Officer, Liaison |
| Control | Clear assignments, a manageable span of control, and changes made through command | Incident Commander, Operations |
Start with three roles
Most incidents need three seats filled. Google's guide names the same three.
| Role | NIMS position | Google IMAG | Owns |
|---|---|---|---|
| Incident commander | Incident Commander | Incident Commander (IC) | The overall response: objectives, priorities, decisions, handover |
| Communications lead | Public Information Officer | Communications Lead (CL) | Regular updates to every audience, and the single contact for incoming questions |
| Operations lead | Operations Section Chief | Operations Lead (OL) | Mitigating the issue, limiting impact, resolving the problem |
Incident roles go to whoever knows the systems and the situation best. Day-job reporting lines pause until the incident closes.
The full organization
When the incident runs past one shift or one team, the rest of the structure fills in around those three.
Getting more help
NIMS describes Incident Management Teams: rostered groups of ICS-qualified people, typed by capability, who deploy to manage incidents that outgrow local capacity. Google keeps the same capability as Incident Response Teams it can activate for major incidents. In cyber, the equivalents are an internal major-incident team drawn from across the organization, the incident response firm on retainer, and an executive crisis team for decisions above the incident commander's authority. Decide in advance who activates each one, and how.
In this section
| Page | Covers |
|---|---|
| Principles | The fourteen NIMS management characteristics, in cyber terms |
| The organization | Every seat, what it owns, who fills it |
| Sizing the response | Complexity types, and when to grow or shrink |
| The planning cycle | Operational periods, the meetings, the Incident Action Plan |
| Unified command | Several parties with authority running one response |
| Above the incident | The crisis team, the executive group and the joint information system |
| Resources | Typing, qualification, the six-step resource process, mutual aid |
| Communications and information | Channels, cadence, what every update answers, the common operating picture |
| Command and handover | Taking command, transferring it, shift change |
| Demobilization | Releasing people and closing the incident organization |