Why it matters
Security bolted on after a project ships is far more expensive than security designed in from the start.
How a self-led small team implements it
Add one security checklist item to whatever project template you already use — don't build a parallel process.
What auditors expect to see
Project templates or checklists showing a security review step.
Track A.5.8 in your own Statement of Applicability — mark it applicable, log your justification, and link it to the risk that drove it.
Start your ISMS