Technical controls enforce encryption in transit across all channels
Switching off legacy unencrypted protocols on every service and remote-access path is the technical enforcement A.5.14 needs behind an encryption requirement written on paper.
Enforcing encrypted protocols everywhere and disabling legacy unencrypted options protects information as it travels across the network, a core objective of A.8.20.
The technical facet configures every service and remote-access path to enforce encrypted protocols and switch off legacy unencrypted fallbacks.