Competence & training-gap matrix
Show the people doing security work are competent for it, the ISO 27001 Clause 7.2 requirement, with a per-person competence matrix, evidence, and expiry tracking.
| Person | Role | Requirement | Evidence | Status |
|---|---|---|---|---|
| A. Rivera | Security lead | ISO 27001 lead implementer | Certificate | Current |
| S. Chen | IT admin | Secure configuration | Training | Current |
| J. Okafor | Developer | Secure coding | Pending | Gap |
| M. Lin | Internal auditor | Audit competence | Certificate | Expiring |
ISO 27001 Clause 7.2 asks you to determine the competence people need for security work, ensure they have it, and keep evidence. Keel gives you the matrix for exactly that: each person and role mapped to their required competences, how each is established (education, training, experience, or certification), a status, the evidence, and an expiry on time-bound certifications.
Competence assumed, not evidenced
Teams know their people are capable, but Clause 7.2 asks them to prove it: a determined set of competences, evidence each person has them, and awareness of the gaps. Without a matrix, that’s scattered across HR files, LMS exports, and memory, and the training gaps only surface when an auditor asks.
What competence & training-gap matrix does
A per-person competence matrix
Map each person and role to the competences their security work requires, the matrix Clause 7.2 is built around, in one place instead of a spreadsheet.
Every basis Clause 7.2 recognizes
Record how each competence is established (education, training, experience, or certification), the four bases the standard names, so the record matches the requirement.
Gaps made obvious
Mark each competence met, in progress, or a gap, and see the totals at a glance, so training gaps are visible and actionable, not a surprise at audit time.
Evidence and certification expiry
Attach the evidence (certificate, course, assessment) and set an expiry on time-bound certifications. Keel flags the ones lapsing within 60 days so renewals don’t slip.
Pairs with the Training module
Competence gaps point straight to the training you assign in Keel, the awareness courses, completions, and certificates that close them, all in the same platform.
Why it matters
- Evidence ISO 27001 Clause 7.2 competence, not just assume it
- Track each person’s competences by basis, status, and evidence
- Surface training gaps and expiring certifications before an auditor does
- Close gaps with the built-in Training module in the same place
Get audit-ready, and prove it
Competence & training-gap matrix is one module of a full GRC platform: controls crosswalked across every framework, so you collect evidence once and comply everywhere. Start free, no credit card, no sales call.
Start freeFrequently asked questions
What does ISO 27001 Clause 7.2 require?
That you determine the competence needed for people whose work affects information security, ensure they’re competent (through education, training, experience, or other means), take action to close gaps, and retain evidence of competence. Keel’s matrix captures all of that.
What’s the difference between this and the Training module?
The competence matrix records what competence each person needs and whether they have it (Clause 7.2). The Training module is how you close gaps: assigning framework-mapped courses and collecting completion certificates as evidence. They’re complementary.
How does certification expiry work?
For a competence established by certification, set the expiry date. Keel highlights certifications lapsing within 60 days so you can schedule renewals before the competence record goes stale.
Who can edit the matrix?
Owners and admins in the workspace. Other members can view it, so the whole team can see where competence stands.
Related features: Security awareness training · Management reviews · Readiness reports
Works with: ISO/IEC 27001