Skip to content

Not-Applicable Controls

Field Value
Status designed (scoping decisions recorded)
Owner DIR
Applies to The scope-out of physical/office/data-centre controls for Partile's current remote, no-paper, no-office, cloud-only posture.
Review cadence Annual, or on any change to remote/office/hosting posture.
Mapped controls The physical-security family of ISO 27001:2022 Annex A (A.7.*) and physical aspects of A.5.14/A.5.33/A.8.10.
Evidence This document; ../registers/not-applicable-register.md (concise index).
Exception handling A control re-enters scope (and this list is updated) when its trigger condition occurs — see each row.

Purpose

Record, deliberately, which controls are not applicable today and why — because an auditor wants evidence that a control was considered and scoped out for a stated reason, not silently absent. Equally, we do not create generic filler policies for areas that do not apply; this document is the complete treatment.

Scope basis

Partile today is a small, fully-remote, cloud-only software company:

  • No office or company premises — all work is remote.
  • No paper records — everything is digital, in Git or managed cloud.
  • No owned data centre or on-premises hardware — hosting is managed cloud (Google Cloud for production); the provider owns the physical and environmental layer.
  • No removable media in any workflow — transfer is over TLS; storage is cloud + Git.
  • No real production user data yet — the GCP production environment exists, but pre-GA testing uses only mock seed data.

Not applicable today (with re-apply trigger)

Control area ISO 27001:2022 ref Why N/A Re-applies when
Clean desk / clear screen A.7.7 No shared physical workspace A physical/shared office exists
Physical entry controls / visitor management A.7.1–A.7.4 No premises to control Company premises are established
Physical security monitoring A.7.4 No premises Premises established
Paper / physical records handling A.5.33 (paper aspect) No paper produced or stored Paper records are created
Removable media management A.7.10, A.8.10 (media aspect) No removable media in workflow Removable media enters workflow
Cabling & equipment siting/protection A.7.8, A.7.12 No owned data centre / on-prem kit On-prem infrastructure is owned
Supporting utilities (power/HVAC) A.7.11 Cloud-provider responsibility Owned facility
Equipment maintenance / secure disposal A.7.13, A.7.14 No owned servers; operator devices covered by device policy Company owns disposable hardware
Physical media transfer A.5.14 (physical aspect) All transfer is over TLS Physical media transfer occurs

Controls that are N/A only in their physical aspect

Some controls have a physical aspect that is N/A but a logical aspect that very much applies — these are not scoped out, they are handled elsewhere:

  • Media/asset handling (A.8.10, A.7.10): the removable-media aspect is N/A; the logical data-handling aspect is covered by data-classification-and-handling-policy.md.
  • Secure disposal (A.7.14): physical disposal is N/A; secure deletion of data is covered by privacy-and-retention-policy.md (hard-delete spine) and backup-and-recovery-policy.md.
  • Cloud provider's physical security: inherited from Google Cloud for the production stack; tracked via the vendor diligence in vendor-and-subprocessor-policy.md, not re-implemented.

Maintenance

When any trigger condition occurs (e.g. Partile leases an office, hires staff who handle paper, or moves to owned hardware), the affected row is removed from this list, a real control is created, and the control register is updated. The concise tabular index is mirrored in ../registers/not-applicable-register.md.