Showing posts with label Critical Incident Response. Show all posts
Showing posts with label Critical Incident Response. Show all posts

Incident Management Plan Alert States and Trigger Response Plans

It is important for incident managers to be provided with simple guidance as to how to sensibly and effectively escalate a risk management posture to reflect threat indicators, or increasing levels of threat. It is also important to define the difference between a problem and a crisis, so that managers do not ignore a real crisis event, or conversely do not mobilize resources that far exceed a requirement, as this will quickly fatigue the crisis management responses. Frequently the determination between a problem and a crisis is a subjective one; however, some simple guidelines will assist those less experienced in identifying and managing crisis events.

The Business Continuity Management Plan will typically contain detailed alert states and trigger plans to meet a range of possible crisis scenarios; however, a simplified version can be useful within the IMP itself. Threat levels are often the key indicators of alert states, but threat levels can be extremely volatile and do not necessarily reflect actual risks to personnel, facilities, resources, or activities. Assessing alert states in terms of the threat and vulnerability will provide a more tailored and local alert state. This should be a continuous process of assessing the risk environment in which the company is operating, at local, regional, and national levels—rather than being purely associated with IMP requirements. Sound judgment forms the basis of a decision; however, the development of agreed alert states provides a common vocabulary, context, and structure for assessing and reacting to the threats that confront the company's people or project. In essence, these alert states provide a simple and effective way of conveying the severity of a situation to local, national, and corporate management in order to facilitate their decision‐making process, as well as evidence and justify a response need. They also bring important consistency to the risk management approach. Alert states can also be used to trigger internal risk and security measures, increasing awareness, initiating contingency measures, and mobilizing resources to be positioned to enable the company to respond at appropriate levels to a particular need.

Alert states can be influenced by internal assessments, or may be influenced or guided by government, military, or civil assessments. There may be differences in what a government considers just reason to evacuate, and what commercial organizations see as the final trigger for a withdrawal. Businesses will bear the brunt of financial or project losses, whereas diplomatic warnings are more advisory and often not audience specific. Alert state risk assessments can also be tied directly to actions required and policies implemented. This will assist in a semi‐automated process following the risk assessment. Alert states may vary from negligible to low, medium, high, or extreme. In each instance, an explanation of what drives the classification should be provided to avoid personal perspective or ambiguity, as well as what actions are required in association with alert states to reflect a change to risk levels. Tables may be complex or simple, depending on the complexity of the company requirement—although the IMP version should be as clear and focused as possible to reflect the user audience's knowledge, capabilities, and experiences. Exhibit 2.16 illustrates a simple table that might be used to guide first responders and incident managers through a simple and directed decision‐making process connected to certain levels of risk probability. Numerical alerts can be used to guide managers to where they need to start taking action; alternatively, color coding is an option to making interpretation of risk levels easier for users.


Exhibit 1: Incident Management Plan Alert State Trigger Plan

Generic and macro‐level trigger natures are illustrated in Exhibit 1; however, more specific triggers or trip wires may be defined by companies so as to provide granular‐level guidance to staff. Organizations such as the U.S. Overseas Security Advisory Council (OSAC) advocate trip‐wire planning for commercial organizations operating abroad. The OSAC advocates determining points at which certain risks—principally natural disasters, civil disorder and political unrest, terrorism, health and environmental threats, infrastructure weakness, and other facility or employee concerns—mobilize an organization into predetermined response measures (OSAC, “Tripwire Approach to Emergency Planning,” May 11, 2008). Establishing trip wires or trigger points enables local managers, as well as corporate officers, to have clearly defined and unambiguous points at which decisions or actions are taken, whether they be major earthquakes, large‐scale riots, pandemic alerts, fuel shortages, or water contamination threats. These specific trigger points or trip wires can include:


  • Demonstrations that indicate growing social unrest, whether peaceful or violent in nature, especially if aimed at foreign workers, facilities, or other associated company activities.
  • The media, host nation government, religious groups or leadership, or militia leaders preaching or actively spreading inflammatory propaganda or directives that could adversely affect the company, its personnel, or its facilities.
  • A rapidly diminishing ability to gain accurate and timely information from local government organizations, foreign missions, and media agencies on local or regional events that could present threats to the company.
  • Increasing levels of opportunistic criminal activity, especially if directed at specific ethnic or religious groups, genders, or business activities, locations, or facilities.
  • Focused attention by organized crime on the company and its employees, activities, or facilities, or unwanted attention toward associated or similar commercial groups.
  • Rising levels of insurgent, terrorist, or activist targeting, especially if directed toward the company or toward associated or parallel groups.

  • Host nation, embassy, media, or other public announcements indicating an increase in specific threat types or pending crisis events.
  • Sustained disruptions to basic infrastructure or utilities preventing the supply of clean water, gas, electricity, food, fuel, or other life‐support essentials.
  • Reliable reports of an imminent natural disaster—hurricane, typhoon, tsunami, wildfire, volcanic eruption, or flooding.
  • Reports of a pending or occurring industrial or environmental disaster that could present toxic or physical hazards to personnel, as well as contaminate facilities, food or water supplies, or critical materials.
  • An outbreak of contagious diseases that the local government or responding agencies do not have the resources, expertise, or medicines to treat.
  • Rapid economic decline brought about by sanctions, civil unrest, coups, assassinations, or the turnover in host nation leadership, which might lead to local authorities being unable to maintain law and order.
  • Political instability and loss of governance resulting from the abrupt replacement, detention, or arrest of key government officials, military leaders, political opponents, religious leaders, or other prominent figures.
  • Similar organizations increasing security profiles, ceasing operations, closing facilities, rapidly evacuating personnel, or demobilizing activities.
  • Foreign embassies and aid agencies declaring heightened risk alerts or withdrawing their presence from the area, region, or nation.
  • The inability, lack of resources, or unwillingness for local or national security and law enforcement agencies to provide adequate protection to foreign workers and the company's interests.
  • Rising levels of corruption, extortion, and legal liability risks presented by corrupt political leadership, which could result in detentions or imprisonment.
  • Rapidly declining transportation capacities for road, rail, air, or maritime facilities, which could adversely affect the ability of company employees to evacuate the country.


Each company, and indeed project, should provide definitions and responses that are appropriate to its unique requirements and operating environment. The risk assessment conducted during the contingency planning aspect of the Business Continuity Management Plan's development should define what postulated threats are posed against a company or particular activity, and thus what should be included within the risk type category. The guidelines should be considered as such, guidelines, with common sense playing a critical role in how managers respond.

Collecting Evidence

Collecting Evidence

Before the information age, when investigators wanted to collect documentary evidence, by consent, search warrant, or some other legal means, they searched a suspect's wallet, pocketbook, office file cabinet, or trash containers. In today's business environment, many of these areas are still valid places for evidence; however, they pale when compared to the amount of evidence that can be found in the workstation, PDA, laptop, or other mobile device.

What Is Evidence?

The simplest way to define evidence is information, of probative value, confirming or dispelling an assertion. In more common language, evidence either supports allegations or it does not. This is a good reference for electronic evidence, found at the U.S. Department of Justice Web site available at www.usdoj.gov/criminal/cyber-crime/s&smanual2002.htm.

At this point, it may be a good idea to examine the role of computers, networks, and systems and their role as evidence:

  • Computers may be used as instruments to commit unlawful acts. For example, if a person launched a denial-of-service attack directed to your E-commerce Web site, the computer used to launch this attack would be considered an instrument of the unlawful act.

  • Computers may be used to store evidence of an unlawful act. For example, if an employee downloads pornography on his office workstation, storing it on the hard drive as well as removable media, the workstation and related media have the same role as a file cabinet holding the evidence.

  • Organizations and their related systems can be victims of unlawful acts. For example, if an attacker gained access to a server and modified sensitive data, in this instance the organization is a victim of the unlawful act.

  • Computers may be physically stolen and thereafter are considered fruits of an unlawful act. For example, a truck loaded with PDAs is hijacked. The handheld computers would be considered fruits of the crime.

In seizing, examining, and analyzing information technology, there are many relevant legal decisions impacting investigative acts. If law enforcement agents want to seize computer systems that form part of a network, unless done correctly, the resulting damaged evidence presents prosecutors with substantial barriers. So formidable are these issues, the prosecutor might decide judges and juries cannot be convinced of the case's merits. Consequently, the prosecution declines to take legal action.

For more information regarding computers and electronic evidence search and seizure, there is substantial information available at www.usdoj.gov/criminal/cyber-crime/searching.html.

Examining the contents of target hard drives and other related media must be driven by the needs of the investigation. In short, this is another one of those "bang for the buck" priority matters. With the average workstation having more than 60 Gb of storage capacity, it is virtually impossible to completely examine every file and byte of stored or deleted information from a practical standpoint.

Data stored centrally on a network server may contain incriminating e-mail, but it also stores irrelevant e-mail of innocent third parties that have a reasonable expectation of privacy. Investigators sifting through messages considered private or privileged might find themselves the object of civil suits and depending on the circumstances criminally prosecuted. Seizing electronic evidence where communications are considered privileged, as e-mail exchanges between clergy and their parishioners, medical doctors and their patients, attorneys and their clients, and husbands and wives, can also result in the materials being excluded from legal actions. At times, determining if media contain privileged communications is an issue decided by the presiding judge; consequently, it is a matter for judicial hearings listening to arguments and evidence from opposing sides.

Evidence Prioritization

In relative terms, 24 Gb of printed data would amount to a stack of paper roughly 500 feet high. Obviously, it would require a large team of investigators to catalog and understand such a large amount of information. Computer forensic examiners must follow standards of evidence collection and analysis in the pursuit of their cases.

Despite the fact examiners may have a legal right to examine and search every file in the system, time constraints or legal limitations may not permit it. Therefore, the examination of files is practically limited to those identified as being case-relevant having evidentiary value. However, there is a voice in opposition to merely looking at the case-relevant files ignoring other evidence in the examination process. For example, an investigator viewing files containing stolen intellectual property should not ignore the files where the subject stored financial information about laundering the financial proceeds of that stolen property. Investigators must prioritize their efforts looking for relevant case-related information and perform sufficient examinations so they are convinced that all files do not contain anything of further evidentiary value.

Examining Computer Evidence

In physical terms, computer evidence generally consists of central processing units, storage media, monitors, printers, routers, firewalls, switches, logs, and software. Evidence stored on physical items is considered latent and needs to be essentially "lifted" to another medium for collection, examination, and preservation. Collection, examination, and analysis are performed on this recovered media and must remain unchanged if going to be considered of evidentiary value.

Often senior managers ask why copied media must remain unaltered if it is going to be used in legal proceedings. The answer is not simple. In the most basic terms, opposing legal sides routinely challenge the media's authenticity and if it is discovered the content has been changed, it feeds arguments that the evidence was intentionally or accidentally altered rendering it useless. Judges and juries have been convinced that although the content was slightly altered by the collection or examination process, the argument was sufficiently enlarged by opposing lawyers that they chose to exclude the digital evidence from their deliberations. Consequently, if digital evidence is to have full evidentiary impact, it must remain unaltered.

To further support this concept, review the following quote from the Federal Rules of Evidence for year 2002:

  • Rule 1001. Definitions

    • The following definitions are applicable:

      1. Writings and recordings. — ''Writings'' and ''recordings'' consist of letters, words, or numbers, or their equivalent, set down by handwriting, typewriting, printing, photocopying, photographing, magnetic impulse, mechanical or electronic recording, or other form of data compilation.

      2. Photographs. — ''Photographs'' include still photographs, x-ray films, video tapes, and motion pictures.

      3. Original. — An ''original'' of a writing or recording is the writing or recording itself or any counterpart intended to have the same effect by a person executing or issuing it. An ''original'' of a photograph includes the negative or any print therefrom.

        If data are stored in a computer or similar device, any printout or other output readable by sight, shown to reflect the data accurately, is an "original''.

      4. Duplicate. — A "duplicate'' is a counterpart produced by the same impression as the original, or from the same matrix, or by means of photography, including enlargements and miniatures, or by mechanical or electronic re-recording, or by chemical reproduction, or by other equivalent techniques which accurately reproduces the original.

  • Rule 1002. Requirement of Original

    • To prove the content of a writing, recording, or photograph, the original writing, recording, or photograph is required, except as otherwise provided in these rules or by Act of Congress.

  • Rule 1003. Admissibility of Duplicates

    • A duplicate is admissible to the same extent as an original unless

      1. A genuine question is raised as to the authenticity of the original or

      2. In the circumstances it would be unfair to admit the duplicate in lieu of the original.

These rules permit investigators to use forensic software and other tools to reconstruct an accurate representation of the original data stored on the system. This means the data copied from the target computer may be introduced if it can be proven that this data is a fair and accurate representation of the original.

Of course, opposing sides are going to attack the integrity of the collected evidence; for this reason, it is imperative that when collecting evidence, no one exceeds her expertise, as it could render evidence useless.

Policies and Procedures

Policies and procedures provide instructions and structures and apply to the examination of computers and related media. Their adherence ensures quality and good practices by investigators making sure their efforts are planned, performed, monitored, and recorded. Formalized procedures ensure the integrity and quality of the work performed. Policies should require electronic examinations to be performed on forensically sound copies of the original evidence. This principle is based on the fact that bit-by-bit copies can be made of original digital evidence resulting in exact and true copies of the original.

Policies and procedures must dictate that investigative methods used recovering digital information from computers are valid and reliable. These methods must be technologically and legally acceptable ensuring all relevant information is recovered and preserved. Duplication methods must be legally defensible so nothing in the original was altered when it was forensically copied and that forensic copy is an exact duplicate of the original down to the last bit.

Common Mistakes when Handling Evidence

These are some common mistakes when collecting and preserving evidence:

  • Altering the MAC (modify, access, and create) times

  • Updating or patching affected systems before responders arrive at the scene

  • Using tools that alter the content of the original media

  • Writing over evidence by installing software on the target media

  • Performing collection and analysis exceeding training and expertise

  • Failing to initiate and maintain accurate documentation including chain of custody schedules, commands on the target system, tools to recover digital evidence, and history of actions taken by the responders

Critical Incident Response and CIRT Development

Critical Incident Management

In modern organizations, the combination of easily available data, poorly administered safeguards, and malicious individuals make systems vulnerable and attractive to attacks. Almost daily, we hear of businesses being robbed of critical information assets or suffering outages through virus infections or denial-of-service attacks. Computer networks are still relatively new, having their birth only 30 years ago. It sometimes seems hard to put in perspective, but the vaunted Information Highway was just getting its feet of the ground in the early 1980s. And, as information became an extremely valuable commodity, the exploitation of vulnerabilities seemed to keep pace with the growth of network systems.

Illustrating this point is one of the most famous misdeeds, the 1988 "Morris Worm" incident resulted in a significantly large percentage of the network systems with Internet connections being corrupted and removed from service. This was the catalyst that caused Internet users to have postmortem meetings where they decided that preventative, detective, and corrective steps had to be made active parts of their business practice.

For the past seven years, the Computer Crime and Security survey has been conducted jointly by the Computer Security Institute (www.gocsi.com) and the Federal Bureau of Investigation's San Francisco, California, office. The purpose of this survey is to raise levels of computer system awareness while measuring the magnitude and frequency of computer crimes. The 2002 survey results are based on 503 responses from computer security professionals practicing in U.S. business and government agencies. Responses to this survey confirm that computer systems threats continue to spiral upwardly with corresponding financial losses following.

Here are a few highlights from the most recent survey:

  • 90 percent of the survey respondents detected computer security breaches in the last twelve months.

  • 80 percent acknowledged financial losses attributable to the computer security breaches.

  • Of the 503 respondents, 44 percent estimated their financial losses at more than $455 million.

  • The most serious financial losses occurred through the theft of proprietary information with 26 respondents reporting more than $170 million and 25 respondents reporting more than $115 mission in financial fraud.

  • Of the respondents, 74 percent reported their Internet connection as the more-frequent point of attack than their internal system.

  • In 1996, only 16 percent acknowledged reporting intrusions to law enforcement, but in 2002, 34 percent reported their intrusions to law enforcement authorities.

  • 40 percent detected systems' penetration from outside the organization.

  • 78 percent detected employee abuse of Internet access privileges or inappropriate use of e-mail.

  • 38 percent suffered unauthorized access or misuse of their Web sites in the last 12 months, while 21 percent reported they did not know if there had been unauthorized access or misuse.

Patrice Rapalus, CSI Director, remarked that the Computer Crime and Security Survey has served as a reality check for industry and government:

Over its 7 year life span, the survey has told a compelling story. It has underscored some of the verities of the information security profession; for example, that technology alone cannot thwart cyber attacks and that there is a need for greater cooperation between the private sector and the government. It has also challenged some of the profession's 'conventional wisdom;' for example, that the 'threat from inside the organization is far greater than the threat from outside the organization and that most hack attacks are perpetrated by juveniles on joy rides in cyberspace. Over the 7 year life span of the survey, a sense of the facts on the ground has emerged. There is much more illegal and unauthorized activity in cyberspace than corporations will admit to their clients, stockholders, and business partners or report to law enforcement. Incidents are widespread, costly, and commonplace. Since September 11, 2001, there seems to be a greater appreciation for how much information security means not only to each individual enterprise but also to the economy itself and to society as a whole. Hopefully, this greater appreciation will translate into increased staffing levels, more investment in training, and enhanced organizational clout for those responsible for information security.


Experience Note

The most frequent system attacks originate outside the business organization, but the most successful attacks are those committed by insiders.

Critical Incident Response

The best response to critical incidents is characterized by the "ounce of prevention is worth a pound of cure" philosophy. It is much more financially prudent to implement a sound risk management program characterized by written policies, procedures, and standards, with compliance ensured by comprehensive and unannounced audits, than it is to deal with financially devastating events after they happen.

But there are times when "bad things happen to good people" and a response must be made to a critical incident occurring despite your best efforts. It is virtually impossible to predict when someone is going to attack your system and steal your critical information except to say it is not a matter of if as much as it is a matter of when.

Firefighter Response Model

Responding to a critical incident is similar to responding to a fire. Fire departments work tirelessly to educate us about the best means to prevent fires. Safety training starts with simple programs when we are young by talking about fire-related hazards at home and school. Television and radio public service announcements tell us of the safety measures we can take to safeguard our lives at home. We see fire-safety slogans telling us "only you can prevent forest fires" and similar signs as we enter campgrounds and picnic areas. Sometimes we are visited by Fire Marshals inspecting our facilities, making certain there are marked exits and equipment to extinguish fires and save lives.

When the worst happens, a company of firefighters responds to an emergency:

  • Respond to emergency contact numbers

  • Trained to handle wide-ranging emergency situations

  • Organized in the deployment of their tactics and equipment

  • Frequently cross-trained as Emergency Medical Technicians

  • Confirm that an emergency exists and the nature of it

  • Take all appropriate steps to control the emergency

  • Take all appropriate steps to prevent the fire from destroying priority order:

    • Lives

    • Surrounding property

    • Property where the fire is presently burning

  • Take every possible step to collect and preserve evidence of criminal behavior but not at the risk of life and property

  • Testify at judicial proceedings about their actions and findings

  • Conduct reviews and critique improving their performance

Critical Incident Response Strategy

No one would argue that responding to critical system incidents is a complex area that is not as easy as taking a pill and waking up feeling better in the morning. Critical Incident response methodology closely follows that of the firefighters:

  • Precritical incident preparation. Designated and specially trained response personnel, contact methods, equipment, and tool availability and response posture.

  • Detection of critical incidents.

  • Initial response evaluation. This is a preliminary step in which an initial investigation is performed and an evaluation is made quickly to determine which type of response is appropriate.

  • Response. This is the step where necessary resources are deployed responding to the critical incident. The response goals are very similar to those of the firefighters: contain the damage, prevent it from further spreading, dedicate efforts in a priority manner, and pursue resumption of normal operations.

  • Response posture strategy. This step is where the preliminary facts are ascertained and a "best response" plan is proposed. At this time, the proposed plan is passed to senior managers for their review and approval. It is imperative that this step be accomplished within the framework of response demands and priorities. Time is of the essence, dawdling is not acceptable here. Depending on the nature of the emergency, there will be times that an immediate hammer-to-nail response is made and there will be times when the matter may be handled the next business day.


    Experience Note

    Be careful of "crying wolf" too frequently; if every case is declared an emergency, there are no emergencies.

  • Law enforcement notification. Having previously established a relationship with law enforcement authorities, responders know whether they should collect the evidence first, or secure the crime scene and wait for officers to respond.

  • Legal determination. Responders must include their legal counsel in the decision process surrounding response strategy. On receiving the responder's observations and recommendations, legal counsel should be prepared to render an opinion whether the responders should collect evidence for future legal proceedings, notify law officers so they can collect relevant evidence or take immediate steps to correct damage and restore operations possibly destroying evidence. It is possible that in destroying evidence that responders are violating laws or regulations by not preserving evidence and not coordinating their efforts with law enforcement authorities. For this reason, senior managers and legal counsel must be part of the decision process.

  • Evidence collection. This step collects key evidence with interviews, photographs, sketches, and physical evidence.

  • Forensic duplications. This step provides bit-by-bit, forensically sound, duplications of critical media.

  • Recovery. Responders take appropriate steps to isolate, contain, recover from the incident, and resume business operations.

  • Reporting. Take appropriate steps to draft accurate and timely reports to stakeholders and law enforcement authorities, where applicable.

  • Postmortem. This is the after-action critique and report of the actions taken during the critical incident response.

Critical Incident Planning

  • If you do not plan, you're planning to fail.

Writing and implementing a critical incident plan ensures that emergencies are addressed carefully, thoroughly, and in conformity with risk management programs. As part of the response plan, draft checklists where common incidents are addressed minimizing the required time for response actions. For example, having a response checklist addressing a workstation virus will be significantly different from an employee who is discovered stealing intellectual property and e-mailing it to a competitor.

Here are some recommended elements for a critical incident response plan:

  • Obtain and follow the organization's risk management plans. If your organization does not have one, today is an excellent time to start one. This plan should provide details relative to the priority of critical assets, their restoration, and the steps to be taken for resuming profitable operations.

  • The critical incident response plan should outline the means of detecting emergencies, collecting preliminary information, assessing the gravity of the system attack, systems affected, spread of damage, steps necessary to stop damage, and protect personnel, data, and facilities. The recommended plan structure is simple, direct, and understandable.

  • The critical incident response plan should provide a means to easily contact all relevant employees and outside resources.

  • The critical incident response plan should provide specific instructions about policies, procedures, and legal requirements.

  • The critical incident response plan should provide templates for any documents required during the emergency. For example, the plan should include a template for logging responder's actions and significant events during the response.

Many critical incident response plans fail because they do not include a response-owner and a senior management correspondent as part of the process. A response-owner is the employee responsible in most cases for the response the emergency receives including relevant actions from start to completion. The senior manager correspondent is the employee who will deliver information to stakeholders.

Command Post Operations

This is a sensitive topic relative to the initiation, staffing, and operation of a command post. Do not think that CPs are intended only for military or government operations because all agencies, while addressing emergency situations, should consider this response strategy. Basically, a CP is a temporary business unit assembled to address one of more crises and will remain in operation until all emergencies are stable and settled. CPs work very closely with regular business operations but have the executive "horsepower" to function independently in decision making, assigning resources, taking action, and following up.

CPs are staffed with specialists assigned particular tasks with dedicated resources at their disposal. In their most common configuration, CPs are housed in segregated facilities located within the business' headquarters. If this is not possible, plans should include relocating the CP to a secondary and equipped facility. They should be equipped with dedicated facilities such as office space, electrical generation, high-speed satellite-linked Internet connections, telephones having multiple direct lines separate from other business units, satellite-linked television for news reception, and a LAN connecting CP workstations to the business LAN and the Internet.

CP reporting structure is funnel-shaped. Information flows from telephone calls, radio, news broadcasts, and e-mail to those designated for information processing. Telephone callers may be employees, specialized response teams, members of the press, stakeholders, or the general public. Carefully trained employees are tasked to interview outside callers and collect information. They are trained relative to the information they may disclose because any comments will be attributed to the organization.

Individuals collecting information for the CP should complete a simple contact report form synopsizing the information from their call, news broadcast, or e-mail. This form may be paper-based or electronic with one copy being passed to the function-point (the single point where all collected information flows), another copy is passed to the data input unit, and the last copy is retained and archived as "work papers." If it is significant, she immediately briefs the function-point and follows the briefing with the written contact report form.

The function-point unit is the person or unit that screens incoming information and makes a determination of where the information should be routed, its priority and processing action. The function-point is a critical position requiring decisions to be based on sound business sense. The data input unit is responsible for routing the information to the unit or employee assigned to the task by the function-point. Another unit must be responsible for collecting the work papers and organizing them for future review and retrieval.

Within the CP are several critical business unit representatives. Depending on the nature of the emergency, these are suggested units that should have representatives in the CP:

  • Legal

  • Human Resources

  • Public/Media Relations

  • Senior Management

  • Operations Staff

  • Maintenance Staff

  • Supply/Logistics Staff

  • Communications Staff

  • Data Input Staff

  • Function-Point staff

At least in the initial stages, it will probably be required that the CP is open and staffed for 24 hours.


Experience Note

CP staff will have stages of burnout. Replace all staff members at the end of their 8-hour shifts. At the end of shifts, there should be a briefing by the outgoing shift of the events so the oncoming shift knows what has happened during the past eight hours.

There is a good reason to maintain an events log — so the oncoming employees can review it for reference purposes. Activity logs and other work papers could be made part of legal actions, so care in this area is advised. Employees should be trained that documenting facts is acceptable, while documenting opinions or editorializing are not.


Experience Note

While working in a CP, an employee made a note that was later maintained as a work paper about an event that was only hypothetical and not actual. However, when legal action was sought, the plaintiff introduced the note was as if the event actually happened. Despite the defendant's protestations and objections, the note was accepted as evidence causing significant damage to the defendant's case.

Once the emergency begins to abate, staff, duty-hours, and activities can be reduced. It is a common practice having CP unit leaders meet every half-hour during the first few hours of CP operations. At this time, they should bring important events to briefings along with any concerns. Meetings should last not more than a few minutes and are driven by the nature and treatment of the emergency.

CP employees should understand that press inquiries can have grave consequences for the organization. They should be trained to handle press calls in an appropriate manner. For example, in the face of a disaster, the CP receives a telephone inquiry from a noted news organization; the employee handling the call accepts the information and documents the inquiry by completing the contact report form. Once completed, the form is passed to the function-point where it is screened again and passed to the public relations unit at the CP for handling. One copy of the intake report is passed to the data-input unit that is creating a chronology database of events, and while making an assignment to the public relations unit with a request, they respond when the assignment is completed. In this fashion, assignments can be tracked whether they have been completed or not. Frequently, the input unit will list all uncompleted assignments and pass them to the function-point that will screen them again deciding if they need to be completed in light of the most recent events. Once the public relations unit receives the assignment from the function-point, they contact the news organization and provide appropriate information.

Popular Posts