Incident Response
Owner: Security/Ops
Reviewers: Product, Engineering, DevOps
Status: Draft
Version: 0.1
Last Updated: 2026-09-16
Review Cycle: Per incident or quarterly
Severity Examples
| Severity | Examples |
|---|---|
| Critical | Data leak across farms, credential exposure, production outage. |
| High | Auth bypass, report data corruption, IoT command malfunction. |
| Medium | Feature outage with workaround, delayed notifications. |
| Low | Minor UI issue or non-critical log noise. |
Response Flow
- Detect and classify.
- Assign incident commander.
- Contain impact.
- Communicate status.
- Remediate.
- Validate recovery.
- Write post-incident report.
Open Items
- On-call schedule.
- External communication owner.
- Incident channel and escalation matrix.