Why it matters
Audit and penetration testing activity can itself disrupt production if not planned carefully.
How a self-led small team implements it
A short pre-agreed scope and window for any testing against production systems is enough at small scale.
What auditors expect to see
Audit/testing scope and scheduling documentation.
Track A.8.34 in your own Statement of Applicability — mark it applicable, log your justification, and link it to the risk that drove it.
Start your ISMS