Too many ISO 27001 programs are optimized for the audit, not the organization. The result is a binder of policies nobody reads and controls nobody enforces.
Anchor scope in business reality. The statement of applicability should reflect what your engineers actually operate — not an aspirational architecture diagram.
Then automate evidence. Manual screenshot collection at audit time is a signal that the ISMS is decoupled from the production environment. Wire control evidence directly to the systems they govern.