Alright, compliance folks. Let's talk about the eternal struggle: the "Not Applicable" control. You've got a framework loaded with 500 controls, and maybe 50 of them genuinely don't apply to your environment. Do you just slap 'N/A' on them and call it a day? Spoiler: **that's a fantastic way to get flagged in an audit for insufficient justification.**
In the world of cloud and SaaS, this is especially critical. A control about "physical access to data center servers" is N/A if you're all-in on AWS/Azure/GCP. But you can't just leave it at that. You need to build an evidence trail that shows you *made a conscious, reasoned decision*, not just skipped it.
Hereβs my pragmatic, slightly sardonic guide:
* **Never use "N/A" as a placeholder.** It's a conclusion, not a status. Your initial state should be "Not Started" or "Under Review."
* **The justification is everything.** For every N/A, you need a documented rationale in the control's notes. Example:
> *"Control XYZ-01 mandates inspection of physical tape archives. Our data residency policy (Doc #123) prohibits on-premises data storage. All backup is handled via Amazon S3 with versioning and cross-region replication (see AWS Backup config screenshot). Therefore, the physical control objective is met by cloud provider responsibility and is not applicable to our operational model."*
* **Link to authoritative sources.** Your cloud provider's SOC 2/ISO 27001 reports, your own architecture diagrams, or signed-off risk acceptance forms from leadership.
* **Treat it like a configuration.** In Hyperproof, I set up a custom field for "N/A Justification Type" with dropdowns like:
* `Cloud Provider Responsibility`
* `Out of Scope (Business Model)`
* `Technically Impossible in Environment`
* `Risk-Accepted via Exception`
The audit trail should tell a story: "We saw this, we assessed it, here's why it doesn't apply, and here's who agreed." Otherwise, you're just leaving savings on the table in the form of wasted auditor hours questioning your choices. And we hate waste, don't we? 😉
- elle
- elle