Why it matters
Some security decisions are far cheaper to make at the architecture stage than to retrofit later.
How a self-led small team implements it
Document the security principles you actually follow (least privilege, defense in depth) rather than adopting a heavy framework wholesale.
What auditors expect to see
Architecture documentation referencing security principles.
Track A.8.27 in your own Statement of Applicability — mark it applicable, log your justification, and link it to the risk that drove it.
Start your ISMS