Competence
Competence is the ability to do something effectively, drawing on sufficient knowledge, judgment, and skill to carry out a given task. In a security compliance context, it refers to making sure the people responsible for security-related work actually have the knowledge and skills needed to perform it. Whether that competence is demonstrated through education, training, or experience typically depends on the role and the organization's own decisions.
In general usage, competence is the capacity or minimal ability to perform an activity effectively, encompassing knowledge, judgment, and skill. Within an ISO/IEC 27001 information security management system, competence is addressed under the ISMS requirements in clauses 4 through 10, where an organization is generally expected to determine the necessary competence of persons whose work affects information security performance, ensure those persons are competent (typically on the basis of appropriate education, training, or experience), take actions to acquire needed competence where gaps exist, and retain documented information as evidence of competence. The specific methods used to establish and evidence competence vary by scope, role, and the organization's risk assessment. Competence requirements should not be conflated with the reference controls listed in Annex A, which are selected via the Statement of Applicability; competence sits within the management-system requirements themselves. In SOC 2 examinations conducted under AICPA SSAE 18, the competence of personnel is relevant to how a service organization's controls are designed and operated but is evaluated as part of the auditor's consideration of the control environment rather than as a standalone certifiable requirement.
Why it matters
Competence sits at the foundation of any information security management system because controls do not operate themselves, people do. In an ISO/IEC 27001 context, an organization can design well-documented policies and select appropriate reference controls, but if the individuals responsible for security-related work lack the necessary knowledge, judgment, or skill, those controls are unlikely to function as intended. This is why the ISMS requirements in clauses 4 through 10 generally expect an organization to determine the competence needed for roles whose work affects information security performance, ensure that competence exists, close gaps where they are found, and retain documented evidence of it.
Competence also matters because it is a recurring focus in both certification audits and attestation examinations. Under ISO/IEC 27001, an auditor from a certification body typically reviews how the organization establishes and evidences competence as part of assessing conformity with the management-system requirements. In a SOC 2 examination conducted under AICPA SSAE 18, the competence of personnel is relevant to how a service organization's controls are designed and operated, though it is evaluated as part of the auditor's consideration of the control environment rather than as a standalone certifiable requirement.
Because the specific methods used to establish competence vary by scope, role, and risk assessment, treating competence as a checkbox rather than a substantive practice tends to create weaknesses that surface during audits. Demonstrating competence through appropriate education, training, or experience, and retaining the evidence of it, helps show that the people running the ISMS can actually perform the work the framework assigns to them.
Who it's relevant to
Inside Competence
Common questions
Answers to the questions practitioners most commonly ask about Competence.