# Fictional ExampleCo Gap Register — Demonstration Only

This is not a real company's security posture.

| Gap ID | Domain | Missing evidence or control | Type | Impact | Priority | Proposed owner | Safe current answer | Next action |
|---|---|---|---|---|---|---|---|---|
| GAP-001 | Incident response | No completed tabletop/exercise record | Evidence and possibly execution | Buyer cannot verify plan effectiveness | High | CEO + CTO | “Plan exists; no completed test evidence supplied.” | Schedule a scoped exercise and retain date, participants, scenario, findings, and follow-up evidence. |
| GAP-002 | Resilience | Backups configured but restoration not evidenced | Evidence and execution | Recovery claim is unsupported | High | CTO | “Backups are configured; recurring restore testing is not yet evidenced.” | Run an authorized non-production restoration and record success criteria/results. |
| GAP-003 | Vulnerability management | No public disclosure channel | Control | Researchers lack a lawful reporting route | Medium | CTO | “No formal public VDP is currently published.” | Draft security contact, scope, safe-harbor language, triage owner, and response targets; obtain appropriate review before publishing. |
| GAP-004 | Access control | Quarterly target not consistently evidenced | Evidence/execution | Practice may diverge from policy | Medium | CTO | “Policy calls for quarterly review; one annual record was supplied.” | Complete review and add a recurring owner-controlled reminder. |
