Incident Manager: coordination, recovery, and learning
Six lessons, 30 questions, and nine cases on impact, coordination, communication, mitigation, recovery, and incident learning.
Objectives and progression
A professional assessment with six modules on impact-based triage, delegation, communication under uncertainty, mitigation, evidence, shift handover, and learning. Practice fictional batch, middleware, rollback, pending-file, and international incident cases. Includes primary sources, explanations for every option, and an internal assessment of 27 decisions in 60 minutes. Uses NIST SP 800-61 Rev. 3 as a current cybersecurity reference and distinguishes Google and PagerDuty examples from local processes. Awards no external certification.
Audience: Incident managers, APS professionals, service owners, and incident coordination participants.
Prerequisites: Experience collaborating in technical teams and delivery and support fundamentals; no prior certification required.
300 estimated study minutes
- Turn scattered signals into a response proportionate to service impact.
- Organize responsibilities without creating parallel command during recovery.
- Communicate impact and upcoming decisions without unsupported recovery promises.
- Compare recovery options, limit risk, and protect useful information.
- Confirm the service outcome and preserve coordination across shift changes.
- Turn incidents into verifiable service and response improvements.
Modules
- Declaration, impact, and priority
- Command, delegation, and shared state
- Communication and uncertainty
- Mitigation decisions and evidence
- Recovery, handover, and continuity
- Postmortem, actions, and exercises
Continue learning
References and version
Google SRE incident guidance; PagerDuty contextual incident model; NIST SP 800-61 Rev. 3 April 2025; editorial review 2026-10-01
- Managing Incidents · 2026-09-30
- Incident Response · 2026-09-30
- Postmortem Culture: Learning from Failure · 2026-09-30
- Postmortem Culture · 2026-09-30
- Severity Levels · 2026-09-30
- Incident Commander · 2026-09-30
- During an Incident · 2026-09-30
- External Communication Guidelines · 2026-09-30
- Effective Troubleshooting · 2026-09-30
- Data Integrity: What You Read Is What You Wrote · 2026-09-30
- Incident Response Recommendations and Considerations for Cybersecurity Risk Management · 2026-09-30
- SP 800-61 Rev. 3 full publication · 2026-09-30
What you will explore
0 / 6Declaration, impact, and priority
Turn scattered signals into a response proportionate to service impact.
Command, delegation, and shared state
Organize responsibilities without creating parallel command during recovery.
Communication and uncertainty
Communicate impact and upcoming decisions without unsupported recovery promises.
Mitigation decisions and evidence
Compare recovery options, limit risk, and protect useful information.
Recovery, handover, and continuity
Confirm the service outcome and preserve coordination across shift changes.
Postmortem, actions, and exercises
Turn incidents into verifiable service and response improvements.