Why it matters
Most application vulnerabilities trace back to coding practices, not infrastructure.
How a self-led small team implements it
Static analysis or linting in CI, even a basic ruleset, is legitimate evidence of secure coding practice.
What auditors expect to see
CI configuration showing static analysis/linting.
Track A.8.28 in your own Statement of Applicability — mark it applicable, log your justification, and link it to the risk that drove it.
Start your ISMS