Why it matters
Weak authentication undermines every other access control you've documented.
How a self-led small team implements it
MFA everywhere it's supported, especially on admin and cloud provider accounts, is the single highest-leverage fix here.
What auditors expect to see
MFA enforcement configuration/screenshots.
Track A.8.5 in your own Statement of Applicability — mark it applicable, log your justification, and link it to the risk that drove it.
Start your ISMS