Incident management and response policy
This policy covers security incidents and significant service outages affecting systems operated by NorthCoast DevOps LLC (ncdLabs).
Definitions
- Security incident — unauthorized access, malware, credential exposure, data loss or disclosure, or a credible attempt with material risk.
- Availability incident / outage — sustained loss of a production service or critical customer-facing function.
Roles
- ncdLabs on-call representative — owns triage, containment decisions, customer/status communication coordination, and post-incident follow-up.
- Engineering responders — implement containment and recovery under on-call direction.
Reporting channels
- Security: security@ncdlabs.com
- Outages and service help: help@ncdlabs.com
- Privacy-related incidents also notify privacy@ncdlabs.com
Response process
- Detect — monitoring alerts, customer reports, partner notices, or internal discovery.
- Triage — confirm scope, severity, and whether customer data or credentials may be involved.
- Contain — revoke or rotate secrets, disable compromised integrations, isolate systems, or roll back as appropriate.
- Eradicate and recover — remove the cause, restore service, verify integrity of critical data paths.
- Communicate — notify affected customers when required by contract, law, or material impact; use accurate, timely updates via help@ or agreed channels.
- Learn — record timeline, root cause, and corrective actions; track follow-ups to completion.
Severity (guidance)
- SEV-1 — confirmed breach of customer confidential data, or total outage of a production product.
- SEV-2 — partial outage, degraded security control, or suspected credential exposure under investigation.
- SEV-3 — limited impact, workaround available, or non-production only.
Evidence and retention
Incident notes, relevant logs, and remediation artifacts are retained long enough for investigation and contractual or legal obligations, then disposed of under the data retention and protection policy.