Begin with scope and business context
Define which services, locations, teams and information are inside the information security management system. A clear scope prevents an uncontrolled project while still addressing important interfaces and suppliers.
Use the risk process to make decisions
The risk assessment should explain why controls are needed, who owns treatment and how leadership accepts remaining risk. Avoid copying a generic risk register that does not match the organisation.
Make evidence part of work
Access reviews, supplier reviews, incidents, training, changes and management decisions should produce usable records as part of normal operation. That is more sustainable than reconstructing evidence before an audit.
Keep certification independent
Implementation consultants can help build the ISMS. Certification is performed by an independent certification body, ideally accredited by the relevant national accreditation body.