Sorry, I guess everyone is out on vacation.
We are implementing ISMS too. To plan ISMS, you do not need much. Basically, there is the stuff that helps you and the remaining stuff that is just to formalize it. Everything starts with risk assesment/analysis - you get
external consultants who perform a thorought audit and tell you where your problems are (relative to data and information security). You react upon it by furnishing sort of an action plan which ends up in a Statement of Applicability which is a formal document for your stakeholders/management. From that point forward, you take measures to mitigate those risks, and the special thing about ISMS is that you do it in a PDCA cycle way (you plan your measures, then implement them, check feedback/results, take more measures). Hope that helps.
Before you answer your consultants questions, have them sigh confidentiality agreement. In case you are really really concerned about information loss, give them what they ask for, but tell them they can use it while in your office only, no taking it home, no photocopies, no pictures.