Why it matters
Uncontrolled changes are a leading cause of both outages and accidentally-introduced security gaps.
How a self-led small team implements it
Pull request review plus a deployment log is legitimate change management evidence — you don't need a formal CAB process.
What auditors expect to see
PR review history, deployment logs.
Track A.8.32 in your own Statement of Applicability — mark it applicable, log your justification, and link it to the risk that drove it.
Start your ISMS