Why it matters
Admin-level access is what turns a routine compromise into a catastrophic one.
How a self-led small team implements it
A short list of who holds admin/root access anywhere, reviewed quarterly, is proportionate at small scale.
What auditors expect to see
Privileged access list and review log.
Track A.8.2 in your own Statement of Applicability — mark it applicable, log your justification, and link it to the risk that drove it.
Start your ISMS