ISO 27001 guide · Clause 7
7.2 — Competence
Clause 7.2 requires you to define the skills needed for work that affects security, confirm people have them, close any gaps and keep evidence of all of it.
By Sentrix · Published 2026-07-16
Good intentions are not a control. This is the requirement that turns "our people know what they are doing" into something you can actually prove.
Mandatory requirement · Documented information required: yes
In plain language
7.2 requires you to figure out what skills someone actually needs to do work that affects information security, confirm they have those skills through education, training, or experience, close any gaps you find, and keep evidence of all of it.
Why this requirement exists
A control assigned to someone without the skill to run it properly is a control on paper only. This requirement forces organizations to connect roles to actual capability, rather than assuming that a job title implies the competence a security-relevant task demands.
Scenario: a company assigns firewall rule reviews to a junior IT support technician with no network security background, because they had spare capacity. The reviews happen on schedule, technically satisfying a process requirement, but nobody with the competence to spot a genuinely risky rule ever actually looks. 7.2 exists to catch that gap before an incident does.
What the standard expects
The standard expects the organization to determine the necessary competence of people doing work under its control that affects information security performance; ensure those people are competent on the basis of appropriate education, training, or experience; where applicable, take action to acquire the necessary competence and evaluate whether that action worked; and retain appropriate documented information as evidence of competence.
In practice
- Map security-relevant roles (ISMS owner, control operators, internal auditors) to the specific skills each one needs, rather than assuming general IT competence covers it.
- Keep a simple competence record per role: what is required, how it was demonstrated (certification, training completion, years of relevant experience), and when it was last reviewed.
- When a gap surfaces—a new hire, a new tool, an expanded scope—treat closing it as an action with a deadline, not a hope.
Evidence the auditor will ask for
- A competence matrix or role profile linking security-relevant roles to required skills.
- Certifications, training records, or documented experience for the people in those roles.
- Evidence that identified competence gaps were addressed, with an evaluation of whether the action closed the gap.
Common pitfalls
- Assuming a job title ("IT manager") automatically implies the specific competence a security task requires.
- No record of why a person was deemed competent—just an assumption with nothing kept as evidence.
- Training completed once, years ago, with no re-evaluation as tools, threats, or roles change.
Related requirements
- 7.1 Resources—competence gaps are usually closed through resources allocated here.
- 7.3 Awareness—competence is role-specific skill; awareness is the baseline everyone needs.
- Parent clause: Clause 7 Support.
Sources
Frequently asked questions
- Does competence require a formal certification?
- No. The standard accepts education, training, or experience. A certification is one way to evidence competence, but demonstrated hands-on experience with documented outcomes can be equally valid. What matters is a record of why the person was deemed competent, rather than an assumption with nothing kept as evidence.
- Who needs to be covered: only the security team?
- Anyone whose work affects information security performance, which often extends beyond the security team to IT operations, HR (for onboarding and offboarding controls), and anyone managing access or sensitive data. Map the relevant roles—ISMS owner, control operators, internal auditors—to the specific skills each one needs.
- What should happen when a competence gap surfaces?
- Treat closing it as an action with a deadline, not a hope. A gap typically surfaces with a new hire, a new tool, or an expanded scope. The standard expects the organization to take action to acquire the necessary competence, then evaluate whether that action worked, and keep that evaluation as evidence.
Related pages
ISO 27001 guide · Clause 7
Clause 7 — Support
Resources, competence, awareness, communication and documented information: clause 7 provides the scaffolding that keeps the ISMS running day to day.
ISO 27001 guide · Clause 7
7.1 — Resources
Clause 7.1 requires you to determine what the ISMS needs to be built, run and improved—people, budget, tools, time—and then to actually provide those resources.
ISO 27001 guide · Clause 7
7.3 — Awareness
Clause 7.3 requires everyone working under the organization’s control to know the security policy, their contribution to the ISMS and what nonconformity means.
Let's talk about your compliance program.
Last updated: 2026-09-17
