Skip to content

Not-Applicable Controls Register

A deliberate record of controls that are not applicable to Partile's current scope, with the reason and the trigger that would make them apply. Marking a control N/A is an auditable decision, not an omission — an auditor wants to see that we considered it and scoped it out for a stated reason.

Scope today: a small, fully-remote, no-office, no-paper software company with a GCP production environment, no owned data centre, and no real production user data. The fuller policy-side rationale lives in policies/not-applicable-controls.md; this register is the concise index.

Status: designed (scoping decisions recorded). Owner: DIR. Review: annually or on any change to remote/office/hosting posture.

Control area ISO 27001:2022 ref Why N/A today Re-applies when
Clean desk / clear screen A.7.7 No physical office; no shared physical workspace Any shared/physical office is established
Physical entry / visitor access A.7.1–A.7.4 No company premises to control entry to Company leases/operates premises
Physical security monitoring A.7.4 No premises Premises established
Paper / physical records handling A.5.33 (paper aspect) No paper records produced or stored Any paper records are created
Removable media / storage media management A.7.10, A.8.10 (media aspect) No removable media in workflow; cloud + Git only Removable media enters any workflow
Cabling / equipment siting & protection A.7.8, A.7.12 No owned data-centre or on-prem infrastructure On-prem infrastructure is owned
Supporting utilities (power/HVAC) A.7.11 Cloud-provider responsibility (Google Cloud for production); no owned facility Owned facility
Equipment maintenance / secure disposal of equipment A.7.13, A.7.14 No company-owned servers; managed cloud; operator devices covered by device policy Company owns disposable hardware/servers
Physical media transfer A.5.14 (physical aspect) No physical media transfer; all transfer is over TLS Physical media transfer occurs

Controls that are physical-aspect-only N/A (e.g. media, asset disposal) remain applicable in their logical/cloud form and are covered by the relevant policy: see policies/data-classification-and-handling-policy.md, policies/cryptography-and-secrets-policy.md, and policies/acceptable-use-and-device-policy.md.

We do not create filler policies for the N/A areas above; this register and policies/not-applicable-controls.md are the complete treatment.