Why it matters
Where this overlaps with GDPR or similar law, gaps here create legal exposure, not just an audit finding.
How a self-led small team implements it
A short data map of what personal data you hold and why is the practical starting point — align with any existing privacy policy.
What auditors expect to see
Personal data inventory/data map.
Track A.5.34 in your own Statement of Applicability — mark it applicable, log your justification, and link it to the risk that drove it.
Start your ISMS