DRI Incident Response and Emergency Operations 1 — Questions and Answers
Question 1: What is the PRIMARY purpose of an Incident Response Plan (IRP)?
- To assign financial liability for losses incurred during incidents
- To provide a structured framework for detecting, responding to, and recovering from incidents in a controlled and coordinated manner (Correct answer)
- To document lessons learned after incidents for regulatory reporting
- To ensure all incidents are reported to law enforcement immediately
Correct answer: To provide a structured framework for detecting, responding to, and recovering from incidents in a controlled and coordinated manner
An Incident Response Plan provides the structured framework for detecting, containing, investigating, and recovering from incidents—its primary purpose is enabling effective, coordinated response that minimizes impact and restores normal operations.
An Incident Response Plan defines the organizational framework for managing the full lifecycle of an incident: preparation (building response capabilities before incidents occur), detection and analysis (identifying and understanding incidents), containment (limiting the spread and impact), eradication (removing the threat), recovery (restoring normal operations), and post-incident activities (lessons learned and improvement). The plan designates the Incident Response Team, defines escalation criteria, establishes communication protocols, provides technical procedures for common incident types, and identifies external resources (legal, forensics, insurance, regulators). A well-designed IRP is a living document that is regularly updated based on changes in the threat landscape and lessons from exercises and actual incidents. The absence of an IRP means incident response is ad hoc—relying on individuals' judgment under stress without a coordinated framework, which consistently leads to slower response, greater damage, and avoidable mistakes.
Question 2: In the Incident Command System (ICS), what is the role of the 'Incident Commander (IC)'?
- To manage financial resources and approve all expenditures during the incident
- To have overall authority and responsibility for managing the incident response (Correct answer)
- To communicate with external media and government agencies
- To coordinate technical recovery activities for IT systems
Correct answer: To have overall authority and responsibility for managing the incident response
The Incident Commander holds overall authority and responsibility for managing the incident response, including strategic objectives, resource allocation, and approval of the Incident Action Plan—all response functions ultimately report to the IC.
The Incident Command System provides a standardized management structure for incident response adopted from emergency management and widely applied in private sector business continuity. The Incident Commander occupies the apex of the command structure with overall authority for setting incident objectives, approving strategies, and allocating resources. Directly beneath the IC are four section chiefs (Operations, Planning, Logistics, Finance/Administration) who manage their functional areas. The Command Staff (Public Information Officer, Safety Officer, Liaison Officer) reports directly to the IC. The unified command structure ensures there is a single, clear decision-making authority during incidents, preventing the coordination failures and conflicts of authority that plague unstructured responses. The IC does not manage tactical details—those are delegated to section chiefs—but rather focuses on strategic objectives, resource requests, and inter-agency coordination.
Question 3: What is an 'Emergency Operations Center (EOC)' and how is it activated?
- A permanent facility that monitors all organizational risks and is always active
- A designated command and coordination hub activated when an incident exceeds routine management capabilities and requires coordinated multi-functional response (Correct answer)
- A virtual system for remote employees to coordinate during any significant event
- An offsite location where recovery teams work after a facility loss
Correct answer: A designated command and coordination hub activated when an incident exceeds routine management capabilities and requires coordinated multi-functional response
An EOC is activated when an incident exceeds the capacity of normal operations to manage—when multiple functions must coordinate, when significant resources must be allocated, or when strategic decisions must be made—providing centralized command and coordination.
Emergency Operations Centers are incident management hubs that provide the physical or virtual space, communication infrastructure, and coordination processes needed for multi-functional incident management. EOC activation is typically tiered: Level 1 might involve only the most critical staff for a minor incident; Level 2 brings in a larger team for moderate incidents; Level 3 represents full EOC activation for major incidents requiring comprehensive coordination. Activation criteria are pre-defined in the EOC plan and might include specific event types, geographic scope, regulatory notification triggers, or operational impact thresholds. Once activated, the EOC provides: situation awareness through consolidated reporting, resource coordination, decision-making authority, communication management, and documentation. EOC effectiveness depends on pre-activation preparation: equipment maintenance, staff training, regular exercises, and current contact information and procedure documentation.
Question 4: During an incident, what is the purpose of maintaining an 'incident log'?
- To track employee attendance during the response
- To document all significant actions, decisions, communications, and resource deployments throughout the incident for accountability and after-action analysis (Correct answer)
- To record financial expenditures for insurance reimbursement claims
- To satisfy real-time regulatory reporting requirements
Correct answer: To document all significant actions, decisions, communications, and resource deployments throughout the incident for accountability and after-action analysis
The incident log provides a timestamped record of all significant actions, decisions, communications, and resource deployments—it is essential for situational awareness during the incident and for post-incident analysis, legal defensibility, and insurance claims.
Incident logging serves multiple critical functions. During the incident, the log provides situational awareness—any authorized responder can review the log to understand what actions have been taken, what decisions have been made, and what resources have been deployed, reducing redundant questions and enabling informed decision-making. Post-incident, the log is foundational for after-action reviews: it provides the factual basis for reconstructing the timeline, evaluating whether decisions were appropriate given available information, and identifying delays or failures. Legally and for insurance purposes, the log demonstrates that the organization responded appropriately and documents the basis for decisions. Regulators may request incident logs as part of post-incident reporting. In cyber incident response, the forensic timeline derived from incident logs may be essential for determining the scope of a breach, the initial access vector, and data potentially exfiltrated. Incident logs should be maintained contemporaneously, not reconstructed after the fact.
Question 5: What is the 'span of control' principle in the Incident Command System?
- The geographic area under the Incident Commander's jurisdiction
- The principle that one supervisor should manage no more than 3-7 subordinates for effective coordination (Correct answer)
- The limit on financial authority delegated to field commanders
- The maximum number of incidents that can be managed simultaneously
Correct answer: The principle that one supervisor should manage no more than 3-7 subordinates for effective coordination
Span of control refers to the number of subordinates a single supervisor can effectively manage—ICS recommends 3-7 people per supervisor (optimally 5), ensuring each supervisor has an appropriate, manageable number of people to coordinate without losing control.
The span of control principle in ICS addresses a fundamental management challenge: supervisors with too many direct reports lose situational awareness and control; supervisors with too few are an inefficient use of leadership capacity. The recommended span of 3-7 (optimally 5) reflects research on cognitive load under incident conditions. When a supervisor's direct reports exceed 7, ICS requires expanding the organizational structure by adding supervisory positions—creating intermediate supervisors who each manage groups within the span. This modular structure allows ICS to scale from small incidents managed by a single IC to massive events with hundreds of responders organized in a clear, manageable hierarchy. For business continuity professionals, span of control must be considered in EOC staffing designs and crisis team structures—assigning one coordinator 15 different recovery workstreams produces the same coordination failures that ICS span-of-control principles were designed to prevent.
Question 6: Which phase of incident response focuses on returning business operations to normal while preserving evidence for investigation?
- Containment phase
- Eradication phase
- Recovery phase (Correct answer)
- Post-incident analysis phase
Correct answer: Recovery phase
The Recovery phase focuses on restoring systems and operations to normal while maintaining the careful balance between operational restoration and evidence preservation for ongoing investigation—security forensics may require maintaining certain system states even during restoration.
The NIST SP 800-61 incident response lifecycle defines four phases: Preparation, Detection and Analysis, Containment/Eradication/Recovery (often grouped), and Post-Incident Activity. The Recovery phase begins once the threat has been eradicated and involves: rebuilding or restoring affected systems from clean backups, validating that systems are functioning correctly, monitoring for signs of reinfection or recurring attack, and progressively restoring normal operations starting with the highest-priority functions. The tension between recovery and investigation is significant: restoring systems quickly destroys forensic evidence, while preserving evidence delays restoration. Organizations must make explicit decisions about this tradeoff, often working with legal counsel and forensic experts to determine what evidence must be preserved and in what format before restoration proceeds. For cybersecurity incidents, this typically means creating forensic images of affected systems before restoration rather than restoring in place.
What is the PRIMARY purpose of an Incident Response Plan (IRP)?