ISO 27001

Competence & training-gap matrix

Show the people doing security work are competent for it, the ISO 27001 Clause 7.2 requirement, with a per-person competence matrix, evidence, and expiry tracking.

Start free See pricing
app.keelgrc.com/competence
People
Competence matrix
26
People
22
Competent
5
Gaps
3
Expiring
PersonRoleRequirementEvidenceStatus
A. RiveraSecurity leadISO 27001 lead implementerCertificateCurrent
S. ChenIT adminSecure configurationTrainingCurrent
J. OkaforDeveloperSecure codingPendingGap
M. LinInternal auditorAudit competenceCertificateExpiring

ISO 27001 Clause 7.2 asks you to determine the competence people need for security work, ensure they have it, and keep evidence. Keel gives you the matrix for exactly that: each person and role mapped to their required competences, how each is established (education, training, experience, or certification), a status, the evidence, and an expiry on time-bound certifications.

Competence assumed, not evidenced

Teams know their people are capable, but Clause 7.2 asks them to prove it: a determined set of competences, evidence each person has them, and awareness of the gaps. Without a matrix, that’s scattered across HR files, LMS exports, and memory, and the training gaps only surface when an auditor asks.

What competence & training-gap matrix does

A per-person competence matrix

Map each person and role to the competences their security work requires, the matrix Clause 7.2 is built around, in one place instead of a spreadsheet.

Every basis Clause 7.2 recognizes

Record how each competence is established (education, training, experience, or certification), the four bases the standard names, so the record matches the requirement.

Gaps made obvious

Mark each competence met, in progress, or a gap, and see the totals at a glance, so training gaps are visible and actionable, not a surprise at audit time.

Evidence and certification expiry

Attach the evidence (certificate, course, assessment) and set an expiry on time-bound certifications. Keel flags the ones lapsing within 60 days so renewals don’t slip.

Pairs with the Training module

Competence gaps point straight to the training you assign in Keel, the awareness courses, completions, and certificates that close them, all in the same platform.

Why it matters

  • Evidence ISO 27001 Clause 7.2 competence, not just assume it
  • Track each person’s competences by basis, status, and evidence
  • Surface training gaps and expiring certifications before an auditor does
  • Close gaps with the built-in Training module in the same place

Get audit-ready, and prove it

Competence & training-gap matrix is one module of a full GRC platform: controls crosswalked across every framework, so you collect evidence once and comply everywhere. Start free, no credit card, no sales call.

Start free

Frequently asked questions

What does ISO 27001 Clause 7.2 require?

That you determine the competence needed for people whose work affects information security, ensure they’re competent (through education, training, experience, or other means), take action to close gaps, and retain evidence of competence. Keel’s matrix captures all of that.

What’s the difference between this and the Training module?

The competence matrix records what competence each person needs and whether they have it (Clause 7.2). The Training module is how you close gaps: assigning framework-mapped courses and collecting completion certificates as evidence. They’re complementary.

How does certification expiry work?

For a competence established by certification, set the expiry date. Keel highlights certifications lapsing within 60 days so you can schedule renewals before the competence record goes stale.

Who can edit the matrix?

Owners and admins in the workspace. Other members can view it, so the whole team can see where competence stands.