ISO 27001:2022 Clause 7.2 Competence Explained

ISO 27001 Clause 7.2 Competence Certification Guide

In this guide you will learn how to implement ISO 27001 Clause 7.2 Competence and pass your audit from ISO 27001 Lead Auditor Stuart Barker – author of the ultimate ISO 27001 Toolkit.

Purpose and Definition

The purpose of ISO 27001 Clause 7.2 Competence is to make sure that the people you have working on the information security management system (ISMS) have the skills, knowledge and experience to do it.

The ISO 27001 standard defines ISO Clause 7.2 Competence as:

The organisation shall: a) determine the necessary competence of person(s) doing work under its control that affects its information security performance; b) ensure that these persons are competent on the basis of appropriate education, training, or experience; c) where applicable, take actions to acquire the necessary competence, and evaluate the effectiveness of the actions taken; and d) retain appropriate documented information as evidence of competence.

ISO 27001:2022 Clause 7.2 Competence
Stuart Barker - High Table - ISO27001 Director

Instant download of mandatory ISMS core policies and documentation. Verified by Lead Auditors and used by 5,000+ businesses worldwide to pass Stage 1 certification first time.

FREE ISO 27001 Clause 7.2 Training Video

What is ISO 27001 Clause 7.2?

ISO 27001 competence is ensuring you have the skills and experience to run the information security management system.

What is does it mean? It means you have people on the team when we’re running your information security management system (ISMS) that know how to run the management system.

This clause is all about people and their skills, experience and competency.

You cannot have ISO 27001 and go for certification if nobody knows any anything about ISO 27001, they’ve got no experience in ISO 27001 and they’ve got no knowledge in ISO 27001.

Requirement

The requirement for ISO 27001 Competence far out reaches just information security.

The organisation as a whole has departments that contribute to the success of the organisation that also play into an effective information security management system.

We can consider HR, legal and regulatory compliance, commercial, and Information Technology (IT) teams.

There are distinct phases in the process of ISO 27001 certification. Each of those phases potentially requires a different level of skill, knowledge and experience. It is possible that this is one person but the likelihood is you are going to get specialist help for the establishment and implementation phase. It can make sense to reduce the reliance on that specialist help when it comes to maintenance and continual improvement. Only using that knowledge and expertise for training and sense checking.

How to implement ISO 27001 Clause 7.2

Step 1: Formalise ISMS Roles and Accountability

  • Action: Define specific information security duties for every role using a granular Accountability Matrix (RASCI). Assign ownership for Clause 7.1 resources and Annex A controls.
  • Result: Ensures clear ownership of ISO 27001 controls and prevents ambiguity regarding who is responsible for critical tasks such as risk assessments or incident response.
  • Technical Requirement: Update job descriptions to include specific ISMS responsibilities and map these to your Role-Based Access Control (RBAC) definitions to ensure segregation of duties.

Step 2: Define Technical and Legal Competency Requirements

  • Action: Document the exact qualifications, experience, and skills required for each role. This includes internal technical skills (e.g., AWS security, firewall config) and external legal requirements (e.g., GDPR, Data Protection).
  • Result: Creates a measurable standard for assessing staff. It also clarifies where external support, such as outsourced legal counsel or virtual DPOs, is necessary to meet competence obligations.
  • Technical Requirement: Specify required certifications (e.g., CISSP, CISM, ISO 27001 Lead Auditor) and formalise contracts for outsourced legal competence where in-house expertise is absent.

Step 3: Conduct a Competency Gap Analysis

  • Action: Audit your current workforce’s capabilities against your defined baselines using a Competency Matrix. Identify where incumbents lack necessary certifications or documented experience.
  • Result: Generates a prioritised list of vulnerabilities where a lack of knowledge could lead to non-conformity.
  • Technical Requirement: Utilise a structured Competency Matrix to visualise data, ensuring every person affecting the ISMS has a corresponding record of skill validation.

Step 4: Execute Targeted Training and Resourcing

  • Action: Address identified gaps by implementing ISO 27001 Lead Implementer/Auditor training for internal staff or engaging specialist ISO 27001 consultants for complex phases like establishment and certification.
  • Result: Mitigates human risk by ensuring the correct resource is used at the correct lifecycle phase, balancing internal development with external expertise.
  • Technical Requirement: Create formal Training Plans within your Learning Management System (LMS) or engage High Table consultants to bridge high-risk competency gaps during the implementation phase.

Step 5: Centralise and Validate Audit Evidence

  • Action: Archive all proofs of competence, including certificates, quizzes, and induction checklists, in a retrievable format.
  • Result: Guarantees a smooth audit process by providing instant verification that competence is being actively managed and evolved.
  • Technical Requirement: Maintain a digital register of Continuing Professional Development (CPD) logs and third-party competence contracts (e.g., legal/security operations) within your HR or GRC repository.

Check Your Work?

You built it yourself. Maybe with AI. But will it pass the audit?

Don’t gamble – let an ISO 27001 Lead Auditor check your work.

Stuart Barker - High Table - ISO27001 Director

The Role of External Consultants and Outsourcing

It can be useful to rely on the competence of third parties. If you engage with third parties and consultants then this is a fast track to the evidence of competence for the areas that they cover.

ISO 27001 Clause 7.2 Templates

For ISO 27001 Clause 7.2 Competence the entire ISO 27001 toolkit is relevant but in particular the following templates directly support this ISO 27001 clause:

ISO 27001 Competency Matrix Template

The ISO 27001 competency matrix template is used to record the employees and the skills that they have, the skills they require and any training needs. It is directly supports clause 7.2 and is a key document to meeting it.

ISO 27001 Competency Matrix Template

ISO 27001 Accountability Template

The ISO 27001 accountability template records which employees are accountable and responsible for the information security management system and all of the ISO 27001 Annex A controls. It is a key document in identifying and recording who is doing what and is used along with the competency matrix to record the skills and experience they have for the areas that they have been assigned.

ISO 27001 ISMS Rasci Matrix Template

ISO 27001 Training Policy Template

The ISO 27001 training policy template is a supporting document that sets out the organisations approach to training and commitment to ensuring employees have the skills and experience that they need to perform the roles that they have been assigned to.

ISO 27001 Training and Awareness Policy Template

ISO 27001 Competency Matrix

ISO 27001 Competence Matrix Example
ISO 27001 Competence Matrix Example

How to build your own competence matrix

This particular video on How to Build a Competency Matrix has been viewed over 24,000 times and in it we show you how to build the competency matrix from scratch if you don’t want to download and use the ISO 27001 Competence Matrix Template.

How to pass the ISO 27001 Clause 7.2 audit

To pass an audit of ISO 27001 Clause 7.2 Competence you are going to

  • Understand the requirements of ISO 27001 Competence
  • Identify the roles you need
  • Allocate people to roles
  • Assess the competency of people to perform those roles
  • Address competency gaps through training or bringing in specialist help

ISO 27001 Clause 7.2 FAQ

What is ISO 27001 Clause 7.2 Competence?

ISO 27001 Clause 7.2, also known as the competence clause, requires organizations to determine the necessary competence of people doing work under their control that affects information security performance. This means the organization must identify the skills, knowledge, and experience needed for each role that impacts the Information Security Management System (ISMS), ensure that people in those roles possess them, and keep documented evidence of their competence.

What are the ISO 27001:2022 Changes to Clause 7.2?

Great news. There are no changes to ISO 27001 Clause 7.2 in the 2022 update.

What’s the difference between “competence” and “awareness” in ISO 27001?

Competence (Clause 7.2) is about having the specific knowledge, skills, and experience to perform a job effectively, especially as it relates to information security. It’s a role-specific requirement. Awareness (Clause 7.3) is about ensuring all people under the organization’s control are aware of the information security policy, their contribution to the ISMS, and the implications of not conforming. Awareness is a universal requirement for all personnel, while competence is targeted to specific roles.

How do I evidence I meet the requirement of ISO 27001 Competence?

The best way is to record the skills of your resources in a Competency Matrix.

How do you demonstrate competence to an auditor?

You can demonstrate competence by providing documented evidence such as:

  • Job descriptions that outline required skills.
  • Resumes or CVs showing relevant experience.
  • Training records, certificates, or qualifications.
  • Records of on-the-job training or mentoring programs.
  • Performance reviews that assess security-related tasks.

Auditors may also conduct interviews to verify that personnel understand their responsibilities.

Can you show me how to build an ISO 27001 competence matrix?

Yes, in this video we show you step by step how to build your own ISO 27001 competence matrix from scratch in around 15 minutes.

What is a competency matrix and is it required?

A competency matrix is a tool, usually a spreadsheet, that maps personnel roles and responsibilities to the required skills, knowledge, and experience for information security. While it’s not explicitly required by the standard, it’s considered best practice because it provides a clear, documented way to demonstrate compliance with Clause 7.2, identify skill gaps, and manage training needs.

What actions are needed to ensure competence?

If an organization identifies a competence gap, Clause 7.2 requires them to take action. This may include:

  • Providing training, such as workshops, e-learning courses, or seminars.
  • Offering mentoring or on-the-job guidance from experienced staff.
  • Encouraging professional development and obtaining certifications.
  • Reassigning roles or hiring new, competent personnel.

The organization must also evaluate the effectiveness of these actions.

Do all employees need to be information security experts?

No, the standard does not require everyone to be an information security expert. It only requires that personnel are competent for the work they do that affects the ISMS. For example, an IT administrator needs technical security skills, while a call centre agent needs training on how to handle customer data securely and validate identities.

How often should competence be assessed?

ISO 27001 doesn’t specify a frequency, but competence should be reviewed regularly to ensure it remains current with evolving threats and changes in roles or technologies. This can be done as part of annual performance reviews, during internal audits, or when new security risks are identified.

What happens if an auditor finds a non-conformity in Clause 7.2?

A non-conformity in Clause 7.2 means the organization hasn’t sufficiently demonstrated that its personnel are competent to manage information security risks. This could be due to a lack of documented evidence, skill gaps, or ineffective training. The organization would then be required to implement corrective actions to address the issue and show evidence of improvement to the auditor.

Does experience count as competence?

Yes, absolutely. The standard explicitly states that competence can be based on appropriate “education, training, or experience.” Experience is a crucial component, and organizations should document it through job descriptions, performance reviews, or other records that highlight the individual’s history and accomplishments related to information security.

Can I use external resource for ISO 27001 Clause 7.2 Competence?

Yes. Many companies seek the help of qualified, experienced third party suppliers to help with ISO 27001.

Can I train my staff to meet the requirements of ISO 27001 Clause 7.2 Competence?

Yes, there are many reputable training courses for ISO 27001 Lead Auditor and ISO 27001 Lead Implementor.

How can we make competence-building cost-effective?

To build competence without breaking the bank, consider these strategies:

  • Internal training: Have experienced employees mentor or train their colleagues.
  • Knowledge sharing: Create forums or sessions for team members to share insights on emerging threats and best practices.
  • Free resources: Encourage self-study using free online resources, articles, and government-provided security guides.
  • Cross-training: Allow employees to work on different security projects to broaden their experience.

Further Reading

About the author

Stuart Barker
🎓 MSc Security 🛡️ Lead Auditor 30+ Years Exp 🏢 Ex-GE Leader

Stuart Barker

ISO 27001 Ninja

Stuart Barker is a veteran practitioner with over 30 years of experience in systems security and risk management. Holding an MSc in Software and Systems Security, he combines academic rigor with extensive operational experience, including a decade leading Data Governance for General Electric (GE).

As a qualified ISO 27001 Lead Auditor, Stuart possesses distinct insight into the specific evidence standards required by certification bodies. His toolkits represent an auditor-verified methodology designed to minimise operational friction while guaranteeing compliance.

Shopping Basket
Scroll to Top