Why it matters
Confirms access is actually limited to what a role needs, not just theoretically documented.
How a self-led small team implements it
Spot-check a few systems against your access policy rather than trying to prove every permission across every tool.
What auditors expect to see
Access restriction configuration, spot-check results.
Track A.8.3 in your own Statement of Applicability — mark it applicable, log your justification, and link it to the risk that drove it.
Start your ISMS