Why it matters
Still one of the most common ways attackers gain a foothold, especially via endpoints.
How a self-led small team implements it
Modern OS-native protection (e.g. built-in endpoint defense) plus MDM enforcement is sufficient for most small teams.
What auditors expect to see
Endpoint protection status report.
Track A.8.7 in your own Statement of Applicability — mark it applicable, log your justification, and link it to the risk that drove it.
Start your ISMS