Why it matters
Laptops and phones are the most common entry point into your systems for both attackers and accidental loss.
How a self-led small team implements it
MDM enforcing encryption, screen-lock, and remote wipe on every company device is the practical baseline.
What auditors expect to see
MDM enrollment report, device configuration policy.
Track A.8.1 in your own Statement of Applicability — mark it applicable, log your justification, and link it to the risk that drove it.
Start your ISMS