Why it matters
Confirms security requirements are defined before code is written, not discovered afterward.
How a self-led small team implements it
A short security checklist in your feature/requirements template (auth, input validation, data handling) is enough at small scale.
What auditors expect to see
Requirements template including security items.
Track A.8.26 in your own Statement of Applicability — mark it applicable, log your justification, and link it to the risk that drove it.
Start your ISMS