Not-Applicable Controls Register¶
A deliberate record of controls that are not applicable to Partile's current scope, with the reason and the trigger that would make them apply. Marking a control N/A is an auditable decision, not an omission — an auditor wants to see that we considered it and scoped it out for a stated reason.
Scope today: a small, fully-remote, no-office, no-paper software company
with a GCP production environment, no owned data centre, and no real
production user data.
The fuller policy-side rationale lives in
policies/not-applicable-controls.md; this register is the concise index.
Status: designed (scoping decisions recorded). Owner: DIR. Review: annually or
on any change to remote/office/hosting posture.
| Control area | ISO 27001:2022 ref | Why N/A today | Re-applies when |
|---|---|---|---|
| Clean desk / clear screen | A.7.7 | No physical office; no shared physical workspace | Any shared/physical office is established |
| Physical entry / visitor access | A.7.1–A.7.4 | No company premises to control entry to | Company leases/operates premises |
| Physical security monitoring | A.7.4 | No premises | Premises established |
| Paper / physical records handling | A.5.33 (paper aspect) | No paper records produced or stored | Any paper records are created |
| Removable media / storage media management | A.7.10, A.8.10 (media aspect) | No removable media in workflow; cloud + Git only | Removable media enters any workflow |
| Cabling / equipment siting & protection | A.7.8, A.7.12 | No owned data-centre or on-prem infrastructure | On-prem infrastructure is owned |
| Supporting utilities (power/HVAC) | A.7.11 | Cloud-provider responsibility (Google Cloud for production); no owned facility | Owned facility |
| Equipment maintenance / secure disposal of equipment | A.7.13, A.7.14 | No company-owned servers; managed cloud; operator devices covered by device policy | Company owns disposable hardware/servers |
| Physical media transfer | A.5.14 (physical aspect) | No physical media transfer; all transfer is over TLS | Physical media transfer occurs |
Controls that are physical-aspect-only N/A (e.g. media, asset disposal) remain
applicable in their logical/cloud form and are covered by the relevant
policy: see policies/data-classification-and-handling-policy.md,
policies/cryptography-and-secrets-policy.md, and
policies/acceptable-use-and-device-policy.md.
We do not create filler policies for the N/A areas above; this register and
policies/not-applicable-controls.md are the complete treatment.