Why it matters
Encryption is what makes stolen data useless to whoever stole it.
How a self-led small team implements it
Encryption at rest and in transit enabled by default on your cloud provider covers most of this — document what's on.
What auditors expect to see
Encryption configuration for data at rest and in transit.
Track A.8.24 in your own Statement of Applicability — mark it applicable, log your justification, and link it to the risk that drove it.
Start your ISMS