I am going to show you what ISO 27001 Clause 7.2 Competence is, what’s new, give you ISO 27001 templates, an ISO 27001 toolkit, show you examples, do a walkthrough and show you how to implement it.
I am Stuart Barker the ISO 27001 Ninja and using over two decades of experience on hundreds of ISO 27001 audits and ISO 27001 certifications I show you exactly what changed in the ISO 27001:2022 update and exactly what you need to do for ISO 27001 certification.
What is ISO27001 Clause 7.2 Competence?
The ISO27001 standard requires an organisation to have people that are competent to do the work for information security.
This clause is all about people and their skills, experience and competency.
There are distinct phases in the process of ISO27001 certification. Each of those phases potentially requires a different level of skill, knowledge and experience. It is possible that this is one person but the likelihood is you are going to get specialist help for the establishment and implementation phase. It can make sense to reduce the reliance on that specialist help when it comes to maintenance and continual improvement. Only using that knowledge and expertise for training and sense checking.
Definition
The requirement for ISO27001 Competence far out reaches just information security. The organisation as a whole has departments that contribute to the success of the organisation that also play into an effective information security management system. We can consider HR, legal and regulatory compliance, commercial, and Information Technology (IT) teams.
The ISO27001 Standard defines clause 7.2 as:
The organisation shall:
a) determine the necessary competence of person(s) doing work under its control that affects its information security performance; b) ensure that these persons are competent on the basis of appropriate education, training, or experience; c) where applicable, take actions to acquire the necessary competence, and evaluate the effectiveness of the actions taken; and d) retain appropriate documented information as evidence of competence.
ISO27001 Clause 7.2 Competence
What are the ISO27001:2022 Changes to Clause 7.2?
Great news. There are no changes to ISO27001 Clause 7.2 in the 2022 update.
How To Comply
Our guide would be
ISO27001 Establishment: use specialist resource
ISO27001 Implementation: use specialist resource
ISO27001 Certification: use specialist resource in combination with your own staff
ISO27001 Maintenance: use your own staff with training and sense checking by specialist resource
ISO27001 Continual Improvement: use your own staff with training and sense checking by specialist resource
Of course you can do ALL of it with the ISO27001 Toolkit which includes all of the resources, step by step guides and video walkthroughs you will need with the ability to by specialist help by the hour.
Time needed: 1 day
How to comply with ISO27001 Clause 7.2 Competence
Engage with trained ISO27001 resources
Whether you look to engage a professional such as a High Table ISO27001 Consultant, hire someone full-time or train up internal staff on ISO27001 lead auditor or ISO27001 lead implementor courses you need to engage with trained and experienced resource for your ISO27001 certification.
Complete an accountability matrix
For each of the ISO27001 clauses AND the ISO27001 Annex A / ISO27002 clauses you need to allocate and record who is responsible for that clause and control.
Complete a competency matrix
For each person involved in the operation of the Information Security Management System be sure to record them in them in the competency matrix. The competency matrix allows you to identify and demonstrate that you have the required competencies to run the information security management system. It also identifies gaps that you can plan to address.
Implement training and awareness
Implement and effective process of training and awareness that directly meets the needs of the organisation and the risk the organisation faces.
Implementation Guide
ISO27001 training can help you gain the skills and experience in house and is an option to consider.
ISO27001 lead auditor training, ISO27001 lead implementor training and associated courses are readily available to choose from. For book knowledge to the standard these are an ideal starting point. It can be problematic when it comes to actually applying the learnings though as they tend to focus heavily on the semantics of the standard rather than real world implementation and they will not cover your particular implementation.
Will they tick the box when it comes to the ISO27001 certification? If you haven’t got specialist outside help then yes, they most definitely will.
There is no set level to what level of competence that you require. It is dependant on the needs of the business. You can easily argue what ever level you decide based on the fact that you have risk assessed it and determined it based on risk and business need.
Of course the simplest way is to demonstrate training and certifications for staff.
If this is cost prohibitive then the use of outsourced third parties can also be an answer.
Depending on the size of the business it is unlikely you will have in house legal counsel. So how do you demonstrate that you have competence? Well you probably outsource your legal requirements to a third party law firm. As long as you have a contract and can evidence it then you can demonstrate your competence compliance by simply outsourcing the function. GDPR and Data Protection outside of your grasp for a full time employee? Of course it is. So outsource it and engage a third party company, have a contract in place and record that in your competency matrix.
It isn’t complicated or hard and it doesn’t have to be costly.
ISO27001 templates are a great way to implement your information security management system. Whilst an ISO27001 Toolkit can save you up to 30x in consulting fees and allow you to deliver up to 10x faster these individual templates help meet the specific requirements of ISO27001 clause 7.2