Incident Response

Owner: Security/Ops
Reviewers: Product, Engineering, DevOps
Status: Draft
Version: 0.1
Last Updated: 2026-09-16
Review Cycle: Per incident or quarterly

Severity Examples

Severity Examples
Critical Data leak across farms, credential exposure, production outage.
High Auth bypass, report data corruption, IoT command malfunction.
Medium Feature outage with workaround, delayed notifications.
Low Minor UI issue or non-critical log noise.

Response Flow

  1. Detect and classify.
  2. Assign incident commander.
  3. Contain impact.
  4. Communicate status.
  5. Remediate.
  6. Validate recovery.
  7. Write post-incident report.

Open Items

  • On-call schedule.
  • External communication owner.
  • Incident channel and escalation matrix.