Skip to main content
Category: ISMS Clauses and Planning

Competence

Simply put

Competence is the ability to do something effectively, drawing on sufficient knowledge, judgment, and skill to carry out a given task. In a security compliance context, it refers to making sure the people responsible for security-related work actually have the knowledge and skills needed to perform it. Whether that competence is demonstrated through education, training, or experience typically depends on the role and the organization's own decisions.

Formal definition

In general usage, competence is the capacity or minimal ability to perform an activity effectively, encompassing knowledge, judgment, and skill. Within an ISO/IEC 27001 information security management system, competence is addressed under the ISMS requirements in clauses 4 through 10, where an organization is generally expected to determine the necessary competence of persons whose work affects information security performance, ensure those persons are competent (typically on the basis of appropriate education, training, or experience), take actions to acquire needed competence where gaps exist, and retain documented information as evidence of competence. The specific methods used to establish and evidence competence vary by scope, role, and the organization's risk assessment. Competence requirements should not be conflated with the reference controls listed in Annex A, which are selected via the Statement of Applicability; competence sits within the management-system requirements themselves. In SOC 2 examinations conducted under AICPA SSAE 18, the competence of personnel is relevant to how a service organization's controls are designed and operated but is evaluated as part of the auditor's consideration of the control environment rather than as a standalone certifiable requirement.

Why it matters

Competence sits at the foundation of any information security management system because controls do not operate themselves, people do. In an ISO/IEC 27001 context, an organization can design well-documented policies and select appropriate reference controls, but if the individuals responsible for security-related work lack the necessary knowledge, judgment, or skill, those controls are unlikely to function as intended. This is why the ISMS requirements in clauses 4 through 10 generally expect an organization to determine the competence needed for roles whose work affects information security performance, ensure that competence exists, close gaps where they are found, and retain documented evidence of it.

Competence also matters because it is a recurring focus in both certification audits and attestation examinations. Under ISO/IEC 27001, an auditor from a certification body typically reviews how the organization establishes and evidences competence as part of assessing conformity with the management-system requirements. In a SOC 2 examination conducted under AICPA SSAE 18, the competence of personnel is relevant to how a service organization's controls are designed and operated, though it is evaluated as part of the auditor's consideration of the control environment rather than as a standalone certifiable requirement.

Because the specific methods used to establish competence vary by scope, role, and risk assessment, treating competence as a checkbox rather than a substantive practice tends to create weaknesses that surface during audits. Demonstrating competence through appropriate education, training, or experience, and retaining the evidence of it, helps show that the people running the ISMS can actually perform the work the framework assigns to them.

Who it's relevant to

Compliance and GRC managers
Those responsible for maintaining an ISMS need to determine what competence each security-relevant role requires, close identified gaps, and retain documented evidence. Since the methods vary by scope and role, they typically own the process of defining, tracking, and evidencing competence across the organization.
ISO 27001 certification auditors
Auditors from certification bodies review how an organization establishes and evidences competence when assessing conformity with the ISMS requirements in clauses 4 through 10, distinct from the Annex A reference controls selected via the Statement of Applicability.
SOC 2 examiners (CPA firms)
In examinations conducted under AICPA SSAE 18, personnel competence informs how a service organization's controls are designed and operated. It is evaluated as part of the auditor's consideration of the control environment rather than as a standalone certifiable requirement.
Security engineers and operational staff
Individuals whose work affects information security performance are the subjects of competence requirements. Their education, training, or experience is what organizations typically rely on to demonstrate that security-related tasks can be carried out effectively.
HR and training functions
Because competence may be acquired through training and evidenced with documented information, teams responsible for onboarding, professional development, and records often support the actions an organization takes to establish and retain proof of competence.

Inside Competence

Clause 7.2 Requirement
Competence is addressed in Clause 7.2 of ISO/IEC 27001, part of the ISMS requirements in clauses 4 through 10. It requires the organization to determine the necessary competence of persons whose work affects the performance of the information security management system.
Determination of Necessary Competence
The organization must identify what competence is needed for roles that influence ISMS performance, based on the responsibilities assigned within the defined scope of the management system.
Basis of Competence
Competence is typically established on the basis of appropriate education, training, or experience, with the specific combination depending on the role and the organization's own criteria.
Actions to Acquire Competence
Where gaps exist, the organization is expected to take actions to acquire the necessary competence, such as providing training, mentoring, reassignment of current employees, or hiring, and to evaluate the effectiveness of those actions.
Documented Evidence
The organization is required to retain appropriate documented information as evidence of competence. The form of this evidence varies by organization and is assessed by the certification body during the audit of the ISMS.

Common questions

Answers to the questions practitioners most commonly ask about Competence.

Is competence an ISO 27001 Annex A control?
No. Competence is a requirement stated in the ISMS clauses (clauses 4 through 10) rather than an Annex A reference control. It sits among the support requirements that the organization must satisfy to establish and maintain its management system, and it applies regardless of which Annex A controls are selected through the Statement of Applicability. Treating it as an optional, risk-selected Annex A control would misstate its role, since the ISMS clause requirements are not subject to the same applicability selection process that Annex A controls are.
Does demonstrating competence in ISO 27001 mean the same thing as SOC 2's treatment of workforce capability?
Not exactly, and the two should not be conflated. ISO 27001 addresses competence as a defined ISMS clause requirement within a management system standard, while SOC 2 examines whether controls related to personnel capability are suitably designed and, in a Type II engagement, operating effectively over the review period against the applicable Trust Services Criteria. A SOC 2 examination produces a report attesting to controls over the period covered, whereas ISO 27001 leads to certification of the ISMS against the standard. Evidence gathered for one may be partially useful for the other, but satisfying competence expectations under one framework does not automatically satisfy the other.
How is competence typically evidenced during an ISO 27001 certification audit?
In most engagements, organizations retain documented information showing how the required competence was determined for roles affecting information security performance, and how it was met. This can include training records, qualifications, experience summaries, and records of actions taken to acquire needed competence. The specific evidence expected depends on the certification body, the defined ISMS scope, and the roles involved, so the form and depth of records vary rather than following a single fixed template.
Who within an organization does the competence requirement usually apply to?
It typically applies to persons performing work under the organization's control that affects information security performance, which can extend beyond dedicated security staff to include relevant management, operational, and sometimes third-party roles within the ISMS scope. The exact population depends on how the scope of the management system is defined, so organizations generally identify the affected roles as part of scoping rather than assuming a universal list.
What is the difference between establishing competence and delivering awareness activities?
Competence generally concerns the ability of specific individuals to perform their security-relevant duties, based on appropriate education, training, or experience, whereas awareness concerns ensuring that relevant persons understand the policy, their contribution to the ISMS, and the implications of not conforming. They are related but distinct expectations, and organizations typically maintain separate evidence for each, since a broad awareness program does not by itself demonstrate role-specific competence.
How can organizations address gaps when required competence is not yet met?
Where a gap is identified, organizations typically take actions to acquire the necessary competence, such as providing training, mentoring, reassigning duties, or engaging suitably qualified personnel, and then evaluate whether the action achieved the intended result. Records of these actions are usually retained as documented information. The appropriate response depends on the role, the ISMS scope, and the organization's own risk decisions, so the chosen approach varies across organizations.

Common misconceptions

Competence requirements under ISO 27001 automatically satisfy the personnel-related expectations of a SOC 2 examination.
ISO 27001 certification and a SOC 2 report are distinct outcomes from different frameworks. While competence and human-resource controls may map partially, ISO 27001 Clause 7.2 to relevant Trust Services Criteria, satisfying one does not automatically satisfy the other, and any mapping is partial and depends on scope.
Competence requires formal certifications or degrees for every person working within the ISMS.
The standard bases competence on appropriate education, training, or experience. Depending on the role and the organization's criteria, relevant experience alone may be sufficient; there is no universal rule mandating formal credentials.
Providing training is enough to demonstrate competence during a certification audit.
Clause 7.2 typically expects that, where actions such as training are taken, their effectiveness is evaluated, and that documented information is retained as evidence. Training delivery alone, without evidence of resulting competence, may not meet the requirement.

Best practices

Define the competence needed for each role that affects ISMS performance, and document the education, training, or experience criteria used to establish it.
Perform a gap analysis comparing required competence against current personnel, and plan actions, training, mentoring, reassignment, or hiring, to address any shortfalls.
Evaluate the effectiveness of actions taken to acquire competence rather than assuming that delivering training alone closes the gap.
Retain documented information as evidence of competence, in a form that can be reviewed by the certification body during the audit of the ISMS.
Review competence requirements periodically and after significant organizational or scope changes, since expectations depend on the roles and responsibilities within the defined ISMS scope.
When pursuing both ISO 27001 and a SOC 2 report, map personnel-related requirements deliberately rather than assuming equivalence, recognizing that any mapping is partial and depends on scope and applicable criteria.