Policies Internal operating policies

Incident Response Policy

How Map.ca classifies, responds to, and communicates about security and operational incidents.

Version
0.1.0
Effective
May 20, 2026
Last reviewed
May 20, 2026
Review cycle
every 3 months
Master Policy Index entry
§4 #63

Policy text

Incidents happen. The Incident Response Policy defines what counts as an incident, the severity classification (Sev-1 through Sev-4), the response SLAs by severity, the assembly of an incident response team, the communications discipline (internal first, regulators next, users on the timelines required by law and the timelines Map.ca commits to itself), and the post-incident review that becomes the input to subsequent policy revisions. The Privacy Breach Policy governs the breach-specific path; this policy governs the general incident path.

It applies to Map.ca security, engineering, operations, communications, leadership, and any vendor whose systems are involved in an incident. Three-month review cycle, deliberately short.

Principles this policy enforces

  • Consent must be meaningful
  • Collect less, protect more
  • Public data and personal data are not the same thing
  • Community benefit must survive scale

What it requires

  • Classify incident severity within the documented SLA.
  • Assemble an incident response team within the documented SLA.
  • Notify affected users within the timelines required by law and by Map.ca’s own commitments.
  • Conduct and publish a post-incident review.

What it forbids

  • Do not close an incident silently.
  • Do not delay user notification beyond regulatory or self-imposed timelines.
  • Do not triage without documentation.
  • Do not omit affected users from notification to avoid embarrassment.

How it applies

References