----------------
📚 Frameworks
===================
A field guide by Habib Tora (v1.0, September 2026) adapts NIMS, the National Incident Management System that US emergency services have run on for two decades, to cybersecurity incidents. The premise is plain: the structure, vocabulary and paperwork carry over almost unchanged. The adaptation changes who fills each seat and what each section does. It follows the three stages of Google's ICS-based incident guide: prepare, respond and manage, and learn.
Core principles
• Coordinate: one commander, one set of objectives, one plan per operational period
• Communicate: every audience hears the same facts, on a schedule, from one voice
• Control: clear assignments, a manageable span of control, nobody freelancing
Prepare
People for each seat are trained and have practiced in it. Authority to isolate systems, suspend accounts and spend money is agreed in advance. Channels, forms, contracts and playbooks are ready to use at two in the morning. The preparation chapter also covers the severity scale, commander rotation, update schedules and metrics.
Respond and manage
The first qualified person takes command out loud. Three roles cover most incidents: Incident Commander (coordinates), Communications Lead (keeps every audience informed), Operations Lead (runs the technical work). When an incident outgrows one team or one shift, planning, logistics, finance, liaison and safety sections fill in. Each operational period gets written objectives and an Incident Action Plan. Command changes hands by briefing. Nobody joins the response without an assignment. Unified command covers incidents that cross organizations.
Learn
The after-action review starts as soon as the incident closes, while memory is fresh, and it is blameless: people acted on what they knew at the time, so findings go to systems, procedures and training. Every corrective action gets an owner and a date and is tracked to done. Recurring findings across incidents point to where larger investment belongs.
PIVTR-D pairing
The guide maps its structure phase by phase onto PIVTR-D, which covers the technical response lifecycle. Preparation aligns with qualified seats and pre-agreed authority. Identification sits outside the incident organization until an event of interest is raised. Verification and triage is the initial response, where the first qualified responder takes command and sizes the incident. The response loop sits in the Operations Section, working to one set of objectives per operational period. Debrief lands in demobilization and learn.
Worth noting
Nothing here depends on the incident being cyber; the data center flood tabletop runs the same structure with no attacker in it. ICS is also only one part of NIMS: the rest adds a crisis team and an executive group above the incident, one joint voice to the public, and common resource and information handling at every level.
Limitations
This is guidance, not field data. The trigger conditions are stated, more than one team, past one shift, executive involvement, but no metrics from real incidents are published. Validating the planning cycle in a tabletop before relying on it is the reasonable first step.
🔹 NIMS #IncidentCommand #IncidentResponse #ICS #frameworks
🔗 Source: https://im.htora.dev/