I’ve opened assessments where an entire physical-security section was marked “Not Applicable.”

The explanation was usually straightforward: the vendor hosted its systems with a third-party data-center provider, so physical security was handled by the data center.

Some of those N/A responses were completely reasonable.

Others weren’t.

If a question was specifically about the physical protection of infrastructure where sensitive information was stored, I could understand why the vendor pointed to the data-center provider. The vendor didn’t operate that facility, and those controls were being handled somewhere else.

But the questionnaire usually didn’t stop there.

There were also questions about things like visitor access, devices in workspaces, and other physical-security responsibilities that still belonged to the vendor.

The data center wasn’t controlling who entered the vendor’s office.

It wasn’t deciding how company devices were protected in the vendor’s own work environment.

And it didn’t automatically take responsibility for every physical-security control just because the hosted infrastructure lived there.

That was where I had to separate what the provider was actually responsible for from what still belonged to the vendor.

I would go back and explain that some requirements could reasonably be handled by the data-center provider, while others still needed an answer from the vendor.

Once I broke it down that way, vendors usually understood the distinction and provided what was needed.

That experience is why I’m careful with N/A responses.

N/A isn’t just an empty response option. It’s a conclusion about applicability.

If I’m going to accept it, I want to understand why the requirement really doesn’t apply.

Sometimes the answer is that another provider performs the control.

But even then, I still need to understand what moved to that provider and what stayed with the vendor.

The same problem comes up with vendors that operate largely or entirely remotely.

A company may not have a traditional office, so questions about things like building entry or reception controls may genuinely make little sense.

That still doesn’t mean every physical-security responsibility disappears.

People may be working with company devices or protected information outside a traditional facility. The environment changed, but some of the responsibilities may still exist in a different form.

That’s why I don’t like treating an entire questionnaire section as one applicability decision.

I’d rather look at what each question is actually trying to establish and who is responsible for it in the environment I’m assessing.

The vendor may perform the control.

Another provider may perform it.

The responsibility may be shared.

Or the control may genuinely not apply.

Those are very different conclusions, even if the questionnaire gives the vendor only one box labeled N/A.

My job is figuring out which one I’m actually looking at before I accept the response.

When a vendor marks something “Not Applicable,” what tells you the underlying responsibility actually disappeared rather than simply moved somewhere else?

Reply

Avatar

or to participate