Evidencing Security Team Competence
An auditor asks how you know your security team can do the work.
Most teams answer with an attendance record, which addresses a different control. Here are the references that actually ask, why time-in-seat has stopped being a usable proxy, and a response you can fill in and send.
The controls that ask, and what they ask for
The distinction that decides your answer is between the general workforce and people in specialised roles. Awareness training satisfies the first and is not evidence for the second, and the frameworks separate them explicitly.
| Reference | What it requires | What satisfies it |
|---|---|---|
| ISO 27001:2022 cl. 7.2 Competence | Determine the competence necessary, ensure people are competent, and retain documented information as evidence. | A role-to-capability definition plus per-person assessment records. The clause names retained evidence, so a training plan alone does not close it. |
| ISO 27001:2022 cl. 7.3 Awareness | People are aware of the policy and their contribution. | Awareness training. General workforce, not your engineers. |
| ISO 27001:2022 A.6.3 | Awareness, education and training appropriate to role. | Role-appropriate records. "Appropriate to role" is the operative phrase. |
| NIST CSF 2.0 PR.AT-01 | Personnel possess knowledge to perform general tasks with cybersecurity risk in mind. | Awareness programme. Again, not the security team. |
| NIST CSF 2.0 PR.AT-02 | Individuals in specialised roles possess the knowledge and skills to perform relevant tasks. | This is the one for SOC and engineering staff: role-specific, assessed, demonstrable. |
| SOC 2 / TSC CC1.4 | Commitment to attract, develop and retain competent individuals. | Development plans and assessment outcomes, not hiring criteria alone. |
Answering a PR.AT-02 or clause 7.2 question with PR.AT-01 evidence: offering annual awareness completion as proof that a detection engineer is competent. A reviewer who knows the frameworks reads that as a misunderstanding or an evasion, and it costs credibility on the rest of the response.
Define the role before you evidence competence in it
Both clause 7.2 and PR.AT-02 require competence relative to a role, so an undefined role cannot be evidenced. The NICE Workforce Framework for Cybersecurity is the standard reference: it publishes Work Roles with Task, Knowledge and Skill statements, grouped into Competency Areas, and the whole dataset is downloadable rather than something you compose yourself.
| Step | Do | Produces |
|---|---|---|
| 1 | Pick the NICE Work Role nearest each seat you employ. | A named role per person, from a published taxonomy rather than your job advert. |
| 2 | Pull that role's Task, Knowledge and Skill statements. | The competence list clause 7.2 asks you to determine. |
| 3 | Mark each statement covered by training, covered by experience, or not covered. | A gap list, and the honest answer to "what is this person trained for". |
| 4 | Attach the assessment record and artifact for each covered statement. | The retained documented information the clause requires. |
The evidence ladder
Ascending strength. Level 3 and above survives a follow-up question; levels 1 and 2 generally do not on their own.
| L | Evidence | What it proves | How it gets challenged |
|---|---|---|---|
| 1 | Attendance and completion records | Training was delivered. | "Completion of what, assessed how?" |
| 2 | Knowledge assessment | The material was read. | "Does it test recall or decisions?" |
| 3 | Scenario-based assessment | Judgment in a realistic situation. | "Could it be failed? Show the criteria." |
| 4 | Work product in production | Capability applied to your environment. | Rarely challenged. The strongest form. |
| 5 | Independently verifiable credential | A third party attests, checkable without you. | "Where do I verify it?" Have the URL ready. |
The traditional shorthand was tenure: two to four years took an analyst to senior capability, so years in post stood in for competence. That proxy is now unreliable in both directions. Automation has absorbed much of the repetitive investigation work, so analysts who spend their time on investigative reasoning reach senior capability materially faster, while an analyst who spent three years closing an automated queue may not have accumulated the judgment at all.
Which means "five years in the SOC" is weaker evidence than it was, and a level 3 or 4 artifact from last quarter is stronger. If your current answer to an auditor leans on headcount tenure, it is resting on a proxy the industry is actively abandoning.
The response template
Four elements, one per paragraph. It survives follow-up because each part points at something concrete rather than a programme name. Fill the brackets.
ROLE
[Name] holds the role of [role title], mapped to the NICE
Work Role [role ID / name]. The role requires [two or three
capabilities from that role's TKS statements].
DEVELOPMENT
Competence is developed through [named course sequence],
covering [those capabilities] across [N] modules with
hands-on work against a representative dataset.
ASSESSMENT
Each module concludes with a scenario-based assessment in
which the candidate reaches and defends a decision. Pass
criteria are [criteria]. Per-person results are retained
from [date] in [system].
VERIFICATION
Completion issues a credential verifiable at [URL].
Applied capability is evidenced by [work product, e.g.
detection rules in production authored by this person].Choosing training that produces the evidence
Competence evidence is usually thin because it is assembled in the fortnight before an audit from whatever exists, and what systems log by default is attendance. Pick training that emits level 3 and 5 evidence as a by-product and the problem disappears.
| Ask of any training | Why it decides the evidence level |
|---|---|
| Can the assessment be failed? | An assessment nobody fails is attendance with extra steps. Level 1, not 3. |
| Does it test a decision or a definition? | Recall testing caps you at level 2 however it is described. |
| Is the credential verifiable by a third party? | Without a public verification route you cannot reach level 5. |
| Does the learner produce something you keep? | Work product is level 4, the form auditors challenge least. |
| Does it map to a published role taxonomy? | Without a role mapping you cannot show competence is "appropriate to role". |
Our courses end with a scenario-based exam that turns on a decision and can be failed, issue a credential with a public verification page, and carry CPE credits. Because the work is hands-on against a realistic enterprise dataset, learners produce real artifacts, which is the level 4 evidence. Our learning paths map sequences to roles, which is the shape clause 7.2 and PR.AT-02 are both asking about.
Evidence that accumulates as the team trains
Business seats are $324 per seat per year, any number of seats, one annual invoice. Scenario-based exams, verifiable credentials and CPE credits on every course, for each named team member.
See Business pricingWeekly security engineering insights
Detection techniques, architecture patterns, and operational judgment, every Tuesday.
No spam. Unsubscribe anytime.