GAP-001 · High priority
No completed tabletop/exercise record
- Safe current answer
- Plan exists; no completed test evidence supplied.
- Next action
- Schedule a scoped exercise and retain date, participants, scenario, findings, and follow-up evidence.
Demonstration only
The sample demonstrates the delivery format and the discipline of separating verified facts, partial evidence, gaps, and non-applicable questions.
Artifact 1
Positive claims require evidence references. A partial answer preserves its limitation rather than silently upgrading it.
| Control | Domain | Question | Safe answer | Status | Evidence |
|---|---|---|---|---|---|
| SEC-001 | Access control | Is multifactor authentication required for production administrative access? | Fictional ExampleCo requires SSO and multifactor authentication for production administrative roles. | VERIFIED | EV-001 |
| SEC-002 | Access control | How often are privileged access rights reviewed? | Fictional ExampleCo has a written quarterly review target but supplied evidence confirms only one review in the last year. | PARTIAL | EV-002;EV-003 |
| SEC-003 | Data protection | Is customer data encrypted in transit? | Fictional ExampleCo's public application endpoint enforces modern TLS through its fictional managed hosting provider; internal service paths were not evidenced. | PARTIAL | EV-004 |
| SEC-004 | Data protection | Is customer data encrypted at rest? | The supplied fictional provider configuration states managed database storage encryption is enabled for the production database. | VERIFIED | EV-005 |
| SEC-005 | Incident response | Has the incident response plan been tested in the last 12 months? | No completed exercise record was supplied; Fictional ExampleCo cannot currently claim the plan was tested. | GAP | — |
| SEC-006 | Resilience | Are backups restored in a recurring test? | Backups are configured but no successful restoration record was supplied. | PARTIAL | EV-006 |
| SEC-007 | Application security | Are code changes independently reviewed before production? | The fictional protected-branch configuration requires one approving review for the production branch. | VERIFIED | EV-007 |
| SEC-008 | Vulnerability management | Does the company have a documented vulnerability disclosure channel? | No public security contact or disclosure policy was supplied. | GAP | — |
| SEC-009 | Subprocessors | Is a current list of subprocessors available to customers? | Fictional ExampleCo maintains a dated customer-facing subprocessor list covering the providers in the supplied architecture note. | VERIFIED | EV-008;EV-009 |
| SEC-010 | AI governance | Is customer content used to train third-party models? | The supplied fictional model-provider agreement states API inputs are not used for model training by default; Fictional ExampleCo must separately confirm it does not opt in or reuse content itself. | PARTIAL | EV-010 |
| SEC-011 | Physical security | Does the vendor operate its own data center? | Fictional ExampleCo does not operate a data center; its application uses a managed cloud provider. Provider physical controls are addressed through the provider's assurance material. | NOT APPLICABLE | EV-009 |
| SEC-012 | Assurance | Is Fictional ExampleCo SOC 2 certified? | No. Fictional ExampleCo has not supplied a SOC 2 report and must not claim certification. | GAP | — |
Artifact 2
The pack records evidence metadata and customer-approved references. This public sample contains descriptions only—never real artifacts.
| ID | Evidence description | Scope | Effective date | Classification |
|---|---|---|---|---|
| EV-001 | Fictional identity-provider administrative policy export | Production admin group | 2026-07-15 | CONFIDENTIAL METADATA ONLY |
| EV-002 | Fictional access review policy | All workforce access | 2026-01-10 | INTERNAL |
| EV-003 | Fictional completed access review record | Production roles | 2025-11-30 | CONFIDENTIAL METADATA ONLY |
| EV-004 | Fictional managed-host TLS configuration export | Public application endpoint | 2026-07-20 | INTERNAL |
| EV-005 | Fictional database encryption settings export | Production managed database | 2026-07-20 | CONFIDENTIAL METADATA ONLY |
| EV-006 | Fictional backup settings export | Production managed database | 2026-07-20 | INTERNAL |
| EV-007 | Fictional protected-branch settings export | Production branch | 2026-07-18 | INTERNAL |
| EV-008 | Fictional subprocessor list | Customer-facing providers | 2026-07-01 | PUBLIC |
| EV-009 | Fictional architecture and data-flow note | Production SaaS | 2026-07-01 | CONFIDENTIAL METADATA ONLY |
| EV-010 | Fictional model-provider data-use terms excerpt | API service default terms | 2026-06-01 | PUBLIC |
Artifact 3
A useful gap record states what is missing, why it matters, what can safely be said now, and the next owner-controlled action.
GAP-001 · High priority
GAP-002 · High priority
GAP-003 · Medium priority
GAP-004 · Medium priority
The pilot uses only customer-authorized source material and leaves unsupported claims visible.
Check pilot fit