Why it matters
Unpatched, known vulnerabilities are one of the most common root causes in real breach reports.
How a self-led small team implements it
A monthly patching cadence plus dependency-scanning in CI is proportionate; you don't need a dedicated vuln management platform yet.
What auditors expect to see
Patch logs, dependency scan reports.
Track A.8.8 in your own Statement of Applicability — mark it applicable, log your justification, and link it to the risk that drove it.
Start your ISMS