Not-Applicable Controls¶
| Field | Value |
|---|---|
| Status | designed (scoping decisions recorded) |
| Owner | DIR |
| Applies to | The scope-out of physical/office/data-centre controls for Partile's current remote, no-paper, no-office, cloud-only posture. |
| Review cadence | Annual, or on any change to remote/office/hosting posture. |
| Mapped controls | The physical-security family of ISO 27001:2022 Annex A (A.7.*) and physical aspects of A.5.14/A.5.33/A.8.10. |
| Evidence | This document; ../registers/not-applicable-register.md (concise index). |
| Exception handling | A control re-enters scope (and this list is updated) when its trigger condition occurs — see each row. |
Purpose¶
Record, deliberately, which controls are not applicable today and why — because an auditor wants evidence that a control was considered and scoped out for a stated reason, not silently absent. Equally, we do not create generic filler policies for areas that do not apply; this document is the complete treatment.
Scope basis¶
Partile today is a small, fully-remote, cloud-only software company:
- No office or company premises — all work is remote.
- No paper records — everything is digital, in Git or managed cloud.
- No owned data centre or on-premises hardware — hosting is managed cloud (Google Cloud for production); the provider owns the physical and environmental layer.
- No removable media in any workflow — transfer is over TLS; storage is cloud + Git.
- No real production user data yet — the GCP production environment exists, but pre-GA testing uses only mock seed data.
Not applicable today (with re-apply trigger)¶
| Control area | ISO 27001:2022 ref | Why N/A | Re-applies when |
|---|---|---|---|
| Clean desk / clear screen | A.7.7 | No shared physical workspace | A physical/shared office exists |
| Physical entry controls / visitor management | A.7.1–A.7.4 | No premises to control | Company premises are established |
| Physical security monitoring | A.7.4 | No premises | Premises established |
| Paper / physical records handling | A.5.33 (paper aspect) | No paper produced or stored | Paper records are created |
| Removable media management | A.7.10, A.8.10 (media aspect) | No removable media in workflow | Removable media enters workflow |
| Cabling & equipment siting/protection | A.7.8, A.7.12 | No owned data centre / on-prem kit | On-prem infrastructure is owned |
| Supporting utilities (power/HVAC) | A.7.11 | Cloud-provider responsibility | Owned facility |
| Equipment maintenance / secure disposal | A.7.13, A.7.14 | No owned servers; operator devices covered by device policy | Company owns disposable hardware |
| Physical media transfer | A.5.14 (physical aspect) | All transfer is over TLS | Physical media transfer occurs |
Controls that are N/A only in their physical aspect¶
Some controls have a physical aspect that is N/A but a logical aspect that very much applies — these are not scoped out, they are handled elsewhere:
- Media/asset handling (A.8.10, A.7.10): the removable-media aspect is N/A;
the logical data-handling aspect is covered by
data-classification-and-handling-policy.md. - Secure disposal (A.7.14): physical disposal is N/A; secure deletion of
data is covered by
privacy-and-retention-policy.md(hard-delete spine) andbackup-and-recovery-policy.md. - Cloud provider's physical security: inherited from Google Cloud for the
production stack; tracked via the vendor diligence in
vendor-and-subprocessor-policy.md, not re-implemented.
Maintenance¶
When any trigger condition occurs (e.g. Partile leases an office, hires staff who
handle paper, or moves to owned hardware), the affected row is removed from this
list, a real control is created, and the control register is updated. The concise
tabular index is mirrored in ../registers/not-applicable-register.md.