Why it matters
Your network is the shared surface every other system sits on — a gap here exposes everything behind it.
How a self-led small team implements it
Cloud provider security groups/firewalls, default-deny inbound, is the practical baseline most small teams already have.
What auditors expect to see
Firewall/security group configuration.
Track A.8.20 in your own Statement of Applicability — mark it applicable, log your justification, and link it to the risk that drove it.
Start your ISMS