Policies Internal operating policies
Incident Response Policy
How Map.ca classifies, responds to, and communicates about security and operational incidents.
- Version
- 0.1.0
- Effective
- May 20, 2026
- Last reviewed
- May 20, 2026
- Review cycle
- every 3 months
- Master Policy Index entry
- §4 #63
Policy text
Incidents happen. The Incident Response Policy defines what counts as an incident, the severity classification (Sev-1 through Sev-4), the response SLAs by severity, the assembly of an incident response team, the communications discipline (internal first, regulators next, users on the timelines required by law and the timelines Map.ca commits to itself), and the post-incident review that becomes the input to subsequent policy revisions. The Privacy Breach Policy governs the breach-specific path; this policy governs the general incident path.
It applies to Map.ca security, engineering, operations, communications, leadership, and any vendor whose systems are involved in an incident. Three-month review cycle, deliberately short.
Principles this policy enforces
- Consent must be meaningful
- Collect less, protect more
- Public data and personal data are not the same thing
- Community benefit must survive scale
What it requires
- Classify incident severity within the documented SLA.
- Assemble an incident response team within the documented SLA.
- Notify affected users within the timelines required by law and by Map.ca’s own commitments.
- Conduct and publish a post-incident review.
What it forbids
- Do not close an incident silently.
- Do not delay user notification beyond regulatory or self-imposed timelines.
- Do not triage without documentation.
- Do not omit affected users from notification to avoid embarrassment.
How it applies
- Map.ca security
- Engineering and operations
- Communications and leadership
- Vendors involved in an incident
References
- PIPEDA — Breach of security safeguards reporting
- Office of the Privacy Commissioner of Canada — Breach notification guidance
Related policies
Privacy Breach Policy
How Map.ca detects, contains, reports, and learns from privacy breaches — aligned with PIPEDA's breach reporting framework.
Security Policy
How Map.ca protects accounts, infrastructure, secrets, and operational data day to day.
Audit Logging Policy
What Map.ca logs for audit purposes, how those logs are protected, retained, and used.
Public Accountability Policy
Allows communities to see civic activity without exposing private complainants or creating unfair pressure campaigns.