ICS
2Stage 2 of 3

Respond and manage

Google's incident guide says it plainly: left unmanaged, a response turns chaotic. Treat it as a project in its own right, with someone planning it, someone deciding who is involved, and a record of what was done. ICS is the structure for that project.

ICS came out of the California wildfires of the 1970s, when agencies fighting the same fire used different terms, different radios and different plans. Cyber incidents break down in the same places: nobody sure who decides, three people briefing executives with three different numbers, responders on hour thirty with no relief, and a vendor, counsel and an insurer each running their own version of the response.

Coordinate, communicate, control

Google's incident management system, IMAG, is built on ICS and organizes around three Cs. Each maps onto NIMS positions.

CWhat it meansHeld by
CoordinateOne set of objectives and one plan, with every responder working to itIncident Commander, Planning
CommunicateEvery audience hears the same facts on a schedule, and incoming requests have one doorPublic Information Officer, Liaison
ControlClear assignments, a manageable span of control, and changes made through commandIncident Commander, Operations

Start with three roles

Most incidents need three seats filled. Google's guide names the same three.

RoleNIMS positionGoogle IMAGOwns
Incident commanderIncident CommanderIncident Commander (IC)The overall response: objectives, priorities, decisions, handover
Communications leadPublic Information OfficerCommunications Lead (CL)Regular updates to every audience, and the single contact for incoming questions
Operations leadOperations Section ChiefOperations Lead (OL)Mitigating the issue, limiting impact, resolving the problem

Incident roles go to whoever knows the systems and the situation best. Day-job reporting lines pause until the incident closes.

The full organization

When the incident runs past one shift or one team, the rest of the structure fills in around those three.

CommandSets objectives, approves the plan, speaks for the incident
OperationsDoes the response work
PlanningKnows the situation, writes the plan, keeps the record
LogisticsGets responders what they need
Finance/AdminTracks time, cost, contracts and claims

Getting more help

NIMS describes Incident Management Teams: rostered groups of ICS-qualified people, typed by capability, who deploy to manage incidents that outgrow local capacity. Google keeps the same capability as Incident Response Teams it can activate for major incidents. In cyber, the equivalents are an internal major-incident team drawn from across the organization, the incident response firm on retainer, and an executive crisis team for decisions above the incident commander's authority. Decide in advance who activates each one, and how.

In this section

PageCovers
PrinciplesThe fourteen NIMS management characteristics, in cyber terms
The organizationEvery seat, what it owns, who fills it
Sizing the responseComplexity types, and when to grow or shrink
The planning cycleOperational periods, the meetings, the Incident Action Plan
Unified commandSeveral parties with authority running one response
Above the incidentThe crisis team, the executive group and the joint information system
ResourcesTyping, qualification, the six-step resource process, mutual aid
Communications and informationChannels, cadence, what every update answers, the common operating picture
Command and handoverTaking command, transferring it, shift change
DemobilizationReleasing people and closing the incident organization
Adapted from the National Incident Management System, Third Edition (FEMA, 2017). Cyber adaptation, examples and templates by Habib Tora, licensed under CC BY 4.0. Not published by, endorsed by, or affiliated with FEMA or the Department of Homeland Security. Structure after Google's SRE Incident Management Guide. Companion to PIVTR-D.