Why it matters
Laptops and phones leave the office constantly — this is where most physical-asset risk actually lives for a remote team.
How a self-led small team implements it
Full-disk encryption plus a remote-wipe capability on all company devices is the practical baseline here.
What auditors expect to see
Device encryption status, MDM enrollment.
Track A.7.9 in your own Statement of Applicability — mark it applicable, log your justification, and link it to the risk that drove it.
Start your ISMS