Why it matters
Prevents a compromise in one part of your network (e.g. a guest network) from reaching production systems.
How a self-led small team implements it
Separate VPCs/subnets for production vs. everything else is a proportionate implementation for a cloud-native team.
What auditors expect to see
Network segmentation diagram or VPC configuration.
Track A.8.22 in your own Statement of Applicability — mark it applicable, log your justification, and link it to the risk that drove it.
Start your ISMS