Why it matters
Confirms the specific services running on your network (VPN, DNS, etc.) are themselves configured securely.
How a self-led small team implements it
Document the security configuration of whichever network services you actually run — most small teams run few.
What auditors expect to see
Network service configuration documentation.
Track A.8.21 in your own Statement of Applicability — mark it applicable, log your justification, and link it to the risk that drove it.
Start your ISMS