Free Template

Evidencing Security Team Competence

An auditor asks how you know your security team can do the work.

Most teams answer with an attendance record, which addresses a different control. Here are the references that actually ask, why time-in-seat has stopped being a usable proxy, and a response you can fill in and send.

The controls that ask, and what they ask for

The distinction that decides your answer is between the general workforce and people in specialised roles. Awareness training satisfies the first and is not evidence for the second, and the frameworks separate them explicitly.

ReferenceWhat it requiresWhat satisfies it
ISO 27001:2022 cl. 7.2
Competence
Determine the competence necessary, ensure people are competent, and retain documented information as evidence.A role-to-capability definition plus per-person assessment records. The clause names retained evidence, so a training plan alone does not close it.
ISO 27001:2022 cl. 7.3
Awareness
People are aware of the policy and their contribution.Awareness training. General workforce, not your engineers.
ISO 27001:2022 A.6.3Awareness, education and training appropriate to role.Role-appropriate records. "Appropriate to role" is the operative phrase.
NIST CSF 2.0 PR.AT-01Personnel possess knowledge to perform general tasks with cybersecurity risk in mind.Awareness programme. Again, not the security team.
NIST CSF 2.0 PR.AT-02Individuals in specialised roles possess the knowledge and skills to perform relevant tasks.This is the one for SOC and engineering staff: role-specific, assessed, demonstrable.
SOC 2 / TSC CC1.4Commitment to attract, develop and retain competent individuals.Development plans and assessment outcomes, not hiring criteria alone.
The most common finding

Answering a PR.AT-02 or clause 7.2 question with PR.AT-01 evidence: offering annual awareness completion as proof that a detection engineer is competent. A reviewer who knows the frameworks reads that as a misunderstanding or an evasion, and it costs credibility on the rest of the response.

Define the role before you evidence competence in it

Both clause 7.2 and PR.AT-02 require competence relative to a role, so an undefined role cannot be evidenced. The NICE Workforce Framework for Cybersecurity is the standard reference: it publishes Work Roles with Task, Knowledge and Skill statements, grouped into Competency Areas, and the whole dataset is downloadable rather than something you compose yourself.

StepDoProduces
1Pick the NICE Work Role nearest each seat you employ.A named role per person, from a published taxonomy rather than your job advert.
2Pull that role's Task, Knowledge and Skill statements.The competence list clause 7.2 asks you to determine.
3Mark each statement covered by training, covered by experience, or not covered.A gap list, and the honest answer to "what is this person trained for".
4Attach the assessment record and artifact for each covered statement.The retained documented information the clause requires.
Do this once and it serves three purposes: the audit answer, the onboarding gap list, and the development plan. Most teams build all three separately from different sources and then cannot reconcile them in a review.

The evidence ladder

Ascending strength. Level 3 and above survives a follow-up question; levels 1 and 2 generally do not on their own.

LEvidenceWhat it provesHow it gets challenged
1Attendance and completion recordsTraining was delivered."Completion of what, assessed how?"
2Knowledge assessmentThe material was read."Does it test recall or decisions?"
3Scenario-based assessmentJudgment in a realistic situation."Could it be failed? Show the criteria."
4Work product in productionCapability applied to your environment.Rarely challenged. The strongest form.
5Independently verifiable credentialA third party attests, checkable without you."Where do I verify it?" Have the URL ready.
Worked example, why time-in-seat has stopped working as evidence

The traditional shorthand was tenure: two to four years took an analyst to senior capability, so years in post stood in for competence. That proxy is now unreliable in both directions. Automation has absorbed much of the repetitive investigation work, so analysts who spend their time on investigative reasoning reach senior capability materially faster, while an analyst who spent three years closing an automated queue may not have accumulated the judgment at all.

Which means "five years in the SOC" is weaker evidence than it was, and a level 3 or 4 artifact from last quarter is stronger. If your current answer to an auditor leans on headcount tenure, it is resting on a proxy the industry is actively abandoning.

The response template

Four elements, one per paragraph. It survives follow-up because each part points at something concrete rather than a programme name. Fill the brackets.

ROLE [Name] holds the role of [role title], mapped to the NICE Work Role [role ID / name]. The role requires [two or three capabilities from that role's TKS statements]. DEVELOPMENT Competence is developed through [named course sequence], covering [those capabilities] across [N] modules with hands-on work against a representative dataset. ASSESSMENT Each module concludes with a scenario-based assessment in which the candidate reaches and defends a decision. Pass criteria are [criteria]. Per-person results are retained from [date] in [system]. VERIFICATION Completion issues a credential verifiable at [URL]. Applied capability is evidenced by [work product, e.g. detection rules in production authored by this person].
Keep the retention date and system in the answer. Clause 7.2 asks for retained documented information, so "results retained from March 2026 in [system]" closes the control in a way "we assess competence" does not.

Choosing training that produces the evidence

Competence evidence is usually thin because it is assembled in the fortnight before an audit from whatever exists, and what systems log by default is attendance. Pick training that emits level 3 and 5 evidence as a by-product and the problem disappears.

Ask of any trainingWhy it decides the evidence level
Can the assessment be failed?An assessment nobody fails is attendance with extra steps. Level 1, not 3.
Does it test a decision or a definition?Recall testing caps you at level 2 however it is described.
Is the credential verifiable by a third party?Without a public verification route you cannot reach level 5.
Does the learner produce something you keep?Work product is level 4, the form auditors challenge least.
Does it map to a published role taxonomy?Without a role mapping you cannot show competence is "appropriate to role".

Our courses end with a scenario-based exam that turns on a decision and can be failed, issue a credential with a public verification page, and carry CPE credits. Because the work is hands-on against a realistic enterprise dataset, learners produce real artifacts, which is the level 4 evidence. Our learning paths map sequences to roles, which is the shape clause 7.2 and PR.AT-02 are both asking about.

Evidence that accumulates as the team trains

Business seats are $324 per seat per year, any number of seats, one annual invoice. Scenario-based exams, verifiable credentials and CPE credits on every course, for each named team member.

See Business pricing

Weekly security engineering insights

Detection techniques, architecture patterns, and operational judgment, every Tuesday.

No spam. Unsubscribe anytime.