ISO 27001 Clause 7.2 Certification Guide | Competence
In this article we lay bare ISO 27001 Clause 7.2 Competence. Exposing the insider trade secrets, giving you the templates that will save you hours of your life and showing you exactly what you need to do to satisfy it for ISO 27001 certification.
I show you exactly what changed in the ISO27001:2022 update.
There are distinct phases in the process of ISO 27001 certification. Each of those phases potentially requires a different level of skill, knowledge and experience. It is possible that this is one person but the likelihood is you are going to get specialist help for the establishment and implementation phase. It can make sense to reduce the reliance on that specialist help when it comes to maintenance and continual improvement. Only using that knowledge and expertise for training and sense checking.
What are the ISO27001:2022 Changes to Clause 7.2?
Great news. There are no changes to ISO 27001 Clause 7.2 in the 2022 update.
ISO 27001 Clause 7.2 Definition
The requirement for ISO 27001 Competence far out reaches just information security. The organisation as a whole has departments that contribute to the success of the organisation that also play into an effective information security management system. We can consider HR, legal and regulatory compliance, commercial, and Information Technology (IT) teams.
The ISO 27001 Standard defines clause 7.2 as:
The organisation shall:
a) determine the necessary competence of person(s) doing work under its control that affects its information security performance; b) ensure that these persons are competent on the basis of appropriate education, training, or experience; c) where applicable, take actions to acquire the necessary competence, and evaluate the effectiveness of the actions taken; and d) retain appropriate documented information as evidence of competence.
ISO 27001 Clause 7.2 Competence
How To comply with ISO 27001 Clause 7.2
Our guide would be
ISO 27001 Establishment: use specialist resource
ISO 27001 Implementation: use specialist resource
ISO 27001 Certification: use specialist resource in combination with your own staff
ISO 27001 Maintenance: use your own staff with training and sense checking by specialist resource
ISO 27001 Continual Improvement: use your own staff with training and sense checking by specialist resource
Of course you can do ALL of it with the ISO 27001 toolkit which includes all of the resources, step by step guides and video walkthroughs you will need with the ability to by specialist help by the hour.
Time needed: 1 day.
How to comply with ISO 27001 Clause 7.2 Competence
Engage with trained ISO 27001 resources
Whether you look to engage a professional such as a High Table ISO 27001 Consultant, hire someone full-time or train up internal staff on ISO 27001 lead auditor or ISO 27001 lead implementor courses you need to engage with trained and experienced resource for your ISO 27001 certification.
Complete an accountability matrix
For each of the ISO 27001 clauses AND the ISO 27001 Annex A / ISO 27002 clauses you need to allocate and record who is responsible for that clause and control.
Complete a competency matrix
For each person involved in the operation of the Information Security Management System be sure to record them in them in the competency matrix. The competency matrix allows you to identify and demonstrate that you have the required competencies to run the information security management system. It also identifies gaps that you can plan to address.
Implement training and awareness
Implement and effective process of training and awareness that directly meets the needs of the organisation and the risk the organisation faces.
ISO 27001 Clause 7.2 Implementation Guide
ISO 27001 training can help you gain the skills and experience in house and is an option to consider.
ISO 27001 lead auditor training, ISO 27001 lead implementor training and associated courses are readily available to choose from. For book knowledge to the standard these are an ideal starting point. It can be problematic when it comes to actually applying the learnings though as they tend to focus heavily on the semantics of the standard rather than real world implementation and they will not cover your particular implementation.
Will they tick the box when it comes to the ISO 27001 certification? If you haven’t got specialist outside help then yes, they most definitely will.
There is no set level to what level of competence that you require. It is dependant on the needs of the business. You can easily argue what ever level you decide based on the fact that you have risk assessed it and determined it based on risk and business need.
Of course the simplest way is to demonstrate training and certifications for staff.
If this is cost prohibitive then the use of outsourced third parties can also be an answer.
Depending on the size of the business it is unlikely you will have in house legal counsel. So how do you demonstrate that you have competence? Well you probably outsource your legal requirements to a third party law firm. As long as you have a contract and can evidence it then you can demonstrate your competence compliance by simply outsourcing the function. GDPR and Data Protection outside of your grasp for a full time employee? Of course it is. So outsource it and engage a third party company, have a contract in place and record that in your competency matrix.
It isn’t complicated or hard and it doesn’t have to be costly.
ISO 27001 templates are a great way to implement your information security management system. Whilst an ISO 27001 toolkit can save you up to 30x in consulting fees and allow you to deliver up to 10x faster these individual templates help meet the specific requirements of ISO 27001 clause 7.2
ISO 27001 Clause 7.2 FAQ
What is ISO 27001 Clause 7.2 Competence ?
The ISO 27001 standard requires an organisation to have people that are competent to do the work for information security. Simple.
How do I evidence I meet the requirement of ISO 27001 Clause 7.2?